[61212] in cryptography@c2.net mail archive
Re: Can you keep a secret? This encrypted drive can...
daemon@ATHENA.MIT.EDU (Alexander Klimov)
Fri Nov 10 13:12:33 2006
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Thu, 9 Nov 2006 10:33:44 +0200 (IST)
From: Alexander Klimov <alserkli@inbox.ru>
To: "Travis H." <travis@nexus.subspacefield.org>
Cc: cryptography@metzdowd.com
In-Reply-To: <20061108234014.GA5600@nexus.subspacefield.org>
On Wed, 8 Nov 2006, Travis H. wrote:
> On Wed, Nov 08, 2006 at 05:58:41PM -0500, Leichter, Jerry wrote:
> > Sorry, that doesn't make any sense. If your HWRNG leaks 64 bits,
> > you might as well assume it leaks 256. When it comes to leaks of
> > this sort, the only interesting numbers are "0" and "all".
>
> I can cite numerous examples of such happening in real life. [...]
> Not having to rely on perfectly unpredictable numbers coming from
> your RNG is a valid design principle.
Looks like you are doing a common mistake of using ``entropy source''
(or, probably, even``source of entropy input'') as output of your
generator (see NIST SP 800-90 for details). With such attitude, the
next step is to use identity mapping as a block cipher :-)
--
Regards,
ASK
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com