NODE 89ddd91aRe: Mousepad RNG's?
"James A. Donald" <jamesd@echeque.com>Sun, 29 Sep 1996 02:15:25 +0800
At 08:14 PM 9/27/96 +0200, Anonymous wrote:
> I just downloaded a copy of the beta version of Datafellows
> Windows 3.1 SSH and it asked to move the mouse around to
> generate some randomness. In reading Applied Crypto, it
> mentioned that there is no such thing as generating
> randomness from a personal computer unless something like
> a Geiger counter is used. Is there any way to create a
> fairly random sample from the mouse? Should one use lots
> of jerky movements, or take ones time with it?
In this case the entropy is the negative of the logarithm of
the probability that you or someone else could exactly
duplicate those mouse movements. I would guess that you
get at least three bits a second just doodling around, so
half a minute of doodles (a pretty long time) should be unbreakable.
Some time ago, at a cypherpunks conference, people were making
all sorts of ridiculous proposals for being really, really,
really, sure that you had real entropy, and a prominent
cypherpunk, possibly Tim May, said, "This is ridiculous:
Nobody ever broke good crypto through weakness in the
source of truly random numbers". Sometime after that
Netscape was broken through weakness in the source of
truly random numbers.
---------------------------------------------------------------------
|
We have the right to defend ourselves | http://www.jim.com/jamesd/
and our property, because of the kind |
of animals that we are. True law | James A. Donald
derives from this right, not from the |
arbitrary power of the state. | jamesd@echeque.com
NODE 7da8b363Re: Mousepad RNG's?
"Timothy C. May" <tcmay@got.net>Sun, 29 Sep 1996 03:30:43 +0800
At 8:13 PM -0700 9/27/96, James A. Donald wrote:
>Some time ago, at a cypherpunks conference, people were making
>all sorts of ridiculous proposals for being really, really,
>really, sure that you had real entropy, and a prominent
>cypherpunk, possibly Tim May, said, "This is ridiculous:
>Nobody ever broke good crypto through weakness in the
>source of truly random numbers". Sometime after that
>Netscape was broken through weakness in the source of
>truly random numbers.
This somewhat misrepresents what I said, back at that Cypherpunks meeting
in 1993-4.
The Netscape "random number generator" that was the basis of the Goldberg
and Wagner attack was not even remotely a _physical_ random number
generator, as it relied on various Unix clock readings and not on any
physical sources of entropy (such as mouse tracks, Johnson noise,
radioactivity, etc.). It was a classic case of living in a state of sin.
--Tim May
We got computers, we're tapping phone lines, I know that that ain't allowed.
---------:---------:---------:---------:---------:---------:---------:----
Timothy C. May | Crypto Anarchy: encryption, digital money,
tcmay@got.net 408-728-0152 | anonymous networks, digital pseudonyms, zero
W.A.S.T.E.: Corralitos, CA | knowledge, reputations, information markets,
Higher Power: 2^1,257,787-1 | black markets, collapse of governments.
"National borders aren't even speed bumps on the information superhighway."