Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.misc > #5459 > unrolled thread

OneRNG: Open Hardware Random Number Generator

Started byRich <rich@example.invalid>
First post2014-10-28 10:15 +0000
Last post2014-11-01 01:52 +0000
Articles 14 — 9 participants

Back to article view | Back to comp.misc


Contents

  OneRNG: Open Hardware Random Number Generator Rich <rich@example.invalid> - 2014-10-28 10:15 +0000
    Re: OneRNG: Open Hardware Random Number Generator Oregonian Haruspex <bob_davis_retired@yahoo.com> - 2014-10-28 15:17 -0700
      Re: OneRNG: Open Hardware Random Number Generator Tonton Th <tTh@nowhere.invalid> - 2014-10-28 22:34 +0000
        Re: OneRNG: Open Hardware Random Number Generator Michael Black <et472@ncf.ca> - 2014-10-28 19:15 -0400
          Re: OneRNG: Open Hardware Random Number Generator Oregonian Haruspex <bob_davis_retired@yahoo.com> - 2014-10-28 18:43 -0700
        Re: OneRNG: Open Hardware Random Number Generator Christian Neukirchen <chneukirchen@gmail.com> - 2014-10-29 15:41 +0100
          Re: OneRNG: Open Hardware Random Number Generator scott@alfter.diespammersdie.us (Scott Alfter) - 2014-10-29 18:11 +0000
          Re: OneRNG: Open Hardware Random Number Generator Michael Black <et472@ncf.ca> - 2014-10-29 16:06 -0400
            Re: OneRNG: Open Hardware Random Number Generator scott@alfter.diespammersdie.us (Scott Alfter) - 2014-10-30 17:38 +0000
              Re: OneRNG: Open Hardware Random Number Generator Marko Rauhamaa <marko@pacujo.net> - 2014-10-30 20:39 +0200
                Re: OneRNG: Open Hardware Random Number Generator scott@alfter.diespammersdie.us (Scott Alfter) - 2014-11-03 20:08 +0000
                  Re: OneRNG: Open Hardware Random Number Generator Marko Rauhamaa <marko@pacujo.net> - 2014-11-03 22:12 +0200
    Re: OneRNG: Open Hardware Random Number Generator Sylvia Else <sylvia@not.at.this.address> - 2014-10-31 16:52 +1100
      Re: OneRNG: Open Hardware Random Number Generator nobody@nowhere.invalid (natp) - 2014-11-01 01:52 +0000

#5459 — OneRNG: Open Hardware Random Number Generator

FromRich <rich@example.invalid>
Date2014-10-28 10:15 +0000
SubjectOneRNG: Open Hardware Random Number Generator
Message-ID<CDQMAMXHXef8qCbpaJtDabMN@dont-email.me>
http://onerng.info/

   The OneRNG is an Open Hardware, Open Source, simple and verifiable
   USB-connected source of entropy; we do not ask you to "trust" us, we
   give you the ability to verify for yourself that the OneRNG does what we
   claim, and that it does nothing else.

   OneRNG collects entropy from an avalanche diode circuit, and from a
   channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
   interference - you can remove the hat in order to visually verify the
   components being used.

   You rely on a high-quality source of random numbers to maintain your
   privacy and security in computer communication; but computers have too
   few sources of truly random data for the demands we place upon them.
   Increasingly we have been distrusting the solutions given to us by
   others, as they are shown to be weak in so many ways - because of faults
   in implementation, in design, or due to subversion by attackers who
   simply do not care about the consequences of their actions (I'm looking
   at you, NSA).

   ...

[toc] | [next] | [standalone]


#5463

FromOregonian Haruspex <bob_davis_retired@yahoo.com>
Date2014-10-28 15:17 -0700
Message-ID<m2p4l7$l38$1@dont-email.me>
In reply to#5459
On 2014-10-28 10:15:16 +0000, Rich said:

> http://onerng.info/
> 
>    The OneRNG is an Open Hardware, Open Source, simple and verifiable
>    USB-connected source of entropy; we do not ask you to "trust" us, we
>    give you the ability to verify for yourself that the OneRNG does what we
>    claim, and that it does nothing else.
> 
>    OneRNG collects entropy from an avalanche diode circuit, and from a
>    channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
>    interference - you can remove the hat in order to visually verify the
>    components being used.
> 
>    You rely on a high-quality source of random numbers to maintain your
>    privacy and security in computer communication; but computers have too
>    few sources of truly random data for the demands we place upon them.
>    Increasingly we have been distrusting the solutions given to us by
>    others, as they are shown to be weak in so many ways - because of faults
>    in implementation, in design, or due to subversion by attackers who
>    simply do not care about the consequences of their actions (I'm looking
>    at you, NSA).
> 
>    ...

Seems neat but there are already many ways to gather entropy from sound 
cards and other parts of the system, which satisfy randomness.  If 
one's enciphered messages are being broken I would look more at the OS 
and subsystems like OpenSSL (AHEM!) these days.

[toc] | [prev] | [next] | [standalone]


#5464

FromTonton Th <tTh@nowhere.invalid>
Date2014-10-28 22:34 +0000
Message-ID<slrnm506fs.3aj.tTh@hangartistique.cispeo.fr>
In reply to#5463
On 2014-10-28, Oregonian Haruspex <bob_davis_retired@yahoo.com> wrote:
>
>> http://onerng.info/
>> 
>>    OneRNG collects entropy from an avalanche diode circuit, and from a
>>    channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
>>    interference - you can remove the hat in order to visually verify the
>>    components being used.
>
> Seems neat but there are already many ways to gather entropy from sound 
> cards and other parts of the system, which satisfy randomness.  If 

   No audio input on a RasPi.

-- 
   \_/°< coin      http://weblog.mixart-myrys.org/?post/2014/10/Picz-THSF-2014

[toc] | [prev] | [next] | [standalone]


#5465

FromMichael Black <et472@ncf.ca>
Date2014-10-28 19:15 -0400
Message-ID<alpine.LNX.2.02.1410281911350.2761@darkstar.example.org>
In reply to#5464
On Tue, 28 Oct 2014, Tonton Th wrote:

> On 2014-10-28, Oregonian Haruspex <bob_davis_retired@yahoo.com> wrote:
>>
>>> http://onerng.info/
>>>
>>>    OneRNG collects entropy from an avalanche diode circuit, and from a
>>>    channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
>>>    interference - you can remove the hat in order to visually verify the
>>>    components being used.
>>
>> Seems neat but there are already many ways to gather entropy from sound
>> cards and other parts of the system, which satisfy randomness.  If
>
>   No audio input on a RasPi.
>
But there is bare I/O, and isn't some of it A/D?

I remember one electronic music project to get a random voltage used a 
reverse biased diode (which generates white noise), and then you sample 
it,  the voltage being different each time.  I can't remember what it was 
clocked with, but since the white noise was random, it should be fine.

Random is random, so long as you start with something that is random 
(white noise from some "natural" source like that diode or on a radio 
frequency with no manmade signal, it will be random.  This contrasts with 
the pseudo-random source often seen in computers, a long shift register 
with appropriate feedback, so it can seem like random, except at some 
point it repeats. LOng enough, and it's often good enough for many 
purposes, but not high security.

   Michael

[toc] | [prev] | [next] | [standalone]


#5466

FromOregonian Haruspex <bob_davis_retired@yahoo.com>
Date2014-10-28 18:43 -0700
Message-ID<m2pgn9$pp5$1@dont-email.me>
In reply to#5465
On 2014-10-28 23:15:34 +0000, Michael Black said:

> On Tue, 28 Oct 2014, Tonton Th wrote:
> 
>> On 2014-10-28, Oregonian Haruspex <bob_davis_retired@yahoo.com> wrote:
>>> 
>>>> http://onerng.info/
>>>> 
>>>> OneRNG collects entropy from an avalanche diode circuit, and from a
>>>> channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
>>>> interference - you can remove the hat in order to visually verify the
>>>> components being used.
>>> 
>>> Seems neat but there are already many ways to gather entropy from sound
>>> cards and other parts of the system, which satisfy randomness.  If
>> 
>> No audio input on a RasPi.
>> 
> But there is bare I/O, and isn't some of it A/D?
> 
> I remember one electronic music project to get a random voltage used a 
> reverse biased diode (which generates white noise), and then you sample 
> it,  the voltage being different each time.  I can't remember what it 
> was clocked with, but since the white noise was random, it should be 
> fine.
> 
> Random is random, so long as you start with something that is random 
> (white noise from some "natural" source like that diode or on a radio 
> frequency with no manmade signal, it will be random.  This contrasts 
> with the pseudo-random source often seen in computers, a long shift 
> register with appropriate feedback, so it can seem like random, except 
> at some point it repeats. LOng enough, and it's often good enough for 
> many purposes, but not high security.
> 
>    Michael

Good post.  I might add that my above paranoia even applies to the Pi - 
we don't know that it doesn't contain a hardware backdoor akin to 
Intel's iAMT, making any attempt at cryptographic security pointless 
before the horse leaves the gate so to speak.

If you don't know about iAMT look it up.  Scary stuff.

[toc] | [prev] | [next] | [standalone]


#5468

FromChristian Neukirchen <chneukirchen@gmail.com>
Date2014-10-29 15:41 +0100
Message-ID<87a94f0wgu.fsf@gmail.com>
In reply to#5464
Tonton Th <tTh@nowhere.invalid> writes:

> On 2014-10-28, Oregonian Haruspex <bob_davis_retired@yahoo.com> wrote:
>>
>>> http://onerng.info/
>>> 
>>>    OneRNG collects entropy from an avalanche diode circuit, and from a
>>>    channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
>>>    interference - you can remove the hat in order to visually verify the
>>>    components being used.
>>
>> Seems neat but there are already many ways to gather entropy from sound 
>> cards and other parts of the system, which satisfy randomness.  If 
>
>    No audio input on a RasPi.

But a native RNG:
http://scruss.com/blog/2013/06/07/well-that-was-unexpected-the-raspberry-pis-hardware-random-number-generator/

-- 
Christian Neukirchen  <chneukirchen@gmail.com>  http://chneukirchen.org

[toc] | [prev] | [next] | [standalone]


#5470

Fromscott@alfter.diespammersdie.us (Scott Alfter)
Date2014-10-29 18:11 +0000
Message-ID<m2rakb$fbf$1@dont-email.me>
In reply to#5468
In article <87a94f0wgu.fsf@gmail.com>,
Christian Neukirchen  <chneukirchen@gmail.com> wrote:
>Tonton Th <tTh@nowhere.invalid> writes:
>
>> On 2014-10-28, Oregonian Haruspex <bob_davis_retired@yahoo.com> wrote:
>>>
>>>> http://onerng.info/
>>>> 
>>>>    OneRNG collects entropy from an avalanche diode circuit, and from a
>>>>    channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
>>>>    interference - you can remove the hat in order to visually verify the
>>>>    components being used.
>>>
>>> Seems neat but there are already many ways to gather entropy from sound 
>>> cards and other parts of the system, which satisfy randomness.  If 
>>
>>    No audio input on a RasPi.
>
>But a native RNG:
>http://scruss.com/blog/2013/06/07/well-that-was-unexpected-the-raspberry-pis-hardware-random-number-generator/

Cool...just enabled that on a couple of mine.  It looks like it produces
~50K/s.

  _/_
 / v \ Scott Alfter (remove the obvious to send mail)
(IIGS( http://alfter.us/            Top-posting!
 \_^_/                              >What's the most annoying thing on Usenet?

[toc] | [prev] | [next] | [standalone]


#5471

FromMichael Black <et472@ncf.ca>
Date2014-10-29 16:06 -0400
Message-ID<alpine.LNX.2.02.1410291605340.4171@darkstar.example.org>
In reply to#5468
On Wed, 29 Oct 2014, Christian Neukirchen wrote:

> Tonton Th <tTh@nowhere.invalid> writes:
>
>> On 2014-10-28, Oregonian Haruspex <bob_davis_retired@yahoo.com> wrote:
>>>
>>>> http://onerng.info/
>>>>
>>>>    OneRNG collects entropy from an avalanche diode circuit, and from a
>>>>    channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
>>>>    interference - you can remove the hat in order to visually verify the
>>>>    components being used.
>>>
>>> Seems neat but there are already many ways to gather entropy from sound
>>> cards and other parts of the system, which satisfy randomness.  If
>>
>>    No audio input on a RasPi.
>
> But a native RNG:
> http://scruss.com/blog/2013/06/07/well-that-was-unexpected-the-raspberry-pis-hardware-random-number-generator/
>
That's interesting.  I know I've seen references to "urandom" as Linux is 
booting, some reference to a random source that isn't in all hardware.

   Michael

[toc] | [prev] | [next] | [standalone]


#5474

Fromscott@alfter.diespammersdie.us (Scott Alfter)
Date2014-10-30 17:38 +0000
Message-ID<m2tt1s$hc8$1@dont-email.me>
In reply to#5471
In article <alpine.LNX.2.02.1410291605340.4171@darkstar.example.org>,
Michael Black  <et472@ncf.ca> wrote:
>On Wed, 29 Oct 2014, Christian Neukirchen wrote:
>
>> Tonton Th <tTh@nowhere.invalid> writes:
>>
>>> On 2014-10-28, Oregonian Haruspex <bob_davis_retired@yahoo.com> wrote:
>>>>
>>>>> http://onerng.info/
>>>>>
>>>>>    OneRNG collects entropy from an avalanche diode circuit, and from a
>>>>>    channel-hopping RF receiver. It even has a "tinfoil hat" to prevent RF
>>>>>    interference - you can remove the hat in order to visually verify the
>>>>>    components being used.
>>>>
>>>> Seems neat but there are already many ways to gather entropy from sound
>>>> cards and other parts of the system, which satisfy randomness.  If
>>>
>>>    No audio input on a RasPi.
>>
>> But a native RNG:
>>
>http://scruss.com/blog/2013/06/07/well-that-was-unexpected-the-raspberry-pis-hardware-random-number-generator/
>>
>That's interesting.  I know I've seen references to "urandom" as Linux is 
>booting, some reference to a random source that isn't in all hardware.

/dev/random isn't necessarily a hardware source.  The difference between
/dev/random and /dev/urandom is that /dev/random blocks when available
entropy runs out.  /dev/urandom doesn't; if demand exceeds supply, it'll
keep producing pseudorandomness, but with less entropy.

If /dev/random isn't backed by hardware, other entropy sources are
considered: time between keystrokes, mouse movement, disk interrupts, etc. 
Note that this can be somewhat troublesome for servers, which frequently
don't have input devices attached.

If a hardware RNG is available, rngd is used to top up /dev/random as
needed.

  _/_
 / v \ Scott Alfter (remove the obvious to send mail)
(IIGS( http://alfter.us/            Top-posting!
 \_^_/                              >What's the most annoying thing on Usenet?

[toc] | [prev] | [next] | [standalone]


#5475

FromMarko Rauhamaa <marko@pacujo.net>
Date2014-10-30 20:39 +0200
Message-ID<87y4rx4d1w.fsf@elektro.pacujo.net>
In reply to#5474
scott@alfter.diespammersdie.us (Scott Alfter):

> The difference between /dev/random and /dev/urandom is that
> /dev/random blocks when available entropy runs out. /dev/urandom
> doesn't; if demand exceeds supply, it'll keep producing
> pseudorandomness, but with less entropy.

/dev/random is a scarce resource. It's too bad /dev/urandom can easily
deplete all entropy. It would be nice to be able to reserve a level of
entropy for /dev/random regardless of how /dev/urandom is used.

> If /dev/random isn't backed by hardware, other entropy sources are
> considered: time between keystrokes, mouse movement, disk interrupts,
> etc.

That sounds like hardware to me.

Anyway, a standard, high-yield, high-quality entropy source would be a
great asset.


Marko

[toc] | [prev] | [next] | [standalone]


#5527

Fromscott@alfter.diespammersdie.us (Scott Alfter)
Date2014-11-03 20:08 +0000
Message-ID<m38nbl$krk$1@dont-email.me>
In reply to#5475
In article <87y4rx4d1w.fsf@elektro.pacujo.net>,
Marko Rauhamaa  <marko@pacujo.net> wrote:
>scott@alfter.diespammersdie.us (Scott Alfter):
>> If /dev/random isn't backed by hardware, other entropy sources are
>> considered: time between keystrokes, mouse movement, disk interrupts,
>> etc.
>
>That sounds like hardware to me.

Perhaps a better way of putting it would've been to distinguish a
purpose-built entropy source (such as a hardware RNG) from a device (such as
a keyboard) whose normal operating characteristics can be exploited to serve
as an entropy source.

  _/_
 / v \ Scott Alfter (remove the obvious to send mail)
(IIGS( http://alfter.us/            Top-posting!
 \_^_/                              >What's the most annoying thing on Usenet?

[toc] | [prev] | [next] | [standalone]


#5528

FromMarko Rauhamaa <marko@pacujo.net>
Date2014-11-03 22:12 +0200
Message-ID<87bnooyrf6.fsf@elektro.pacujo.net>
In reply to#5527
scott@alfter.diespammersdie.us (Scott Alfter):

> In article <87y4rx4d1w.fsf@elektro.pacujo.net>,
> Marko Rauhamaa  <marko@pacujo.net> wrote:
>>scott@alfter.diespammersdie.us (Scott Alfter):
>>> If /dev/random isn't backed by hardware, other entropy sources are
>>> considered: time between keystrokes, mouse movement, disk interrupts,
>>> etc.
>>
>>That sounds like hardware to me.
>
> Perhaps a better way of putting it would've been to distinguish a
> purpose-built entropy source (such as a hardware RNG) from a device (such as
> a keyboard) whose normal operating characteristics can be exploited to serve
> as an entropy source.

A coworker today was trying to generate a GPG key. He had to do quite a
bit of exercise with the mouse to produce the needed entropy. It seemed
to me he had to work several seconds for each random byte, and the total
amount of was hundreds of bytes.


Marko

[toc] | [prev] | [next] | [standalone]


#5476

FromSylvia Else <sylvia@not.at.this.address>
Date2014-10-31 16:52 +1100
Message-ID<cbgmd5Fu4lrU2@mid.individual.net>
In reply to#5459
On 28/10/2014 9:15 PM, Rich wrote:
> http://onerng.info/


"You can ask it to dump the current firmware to you, you can see all the 
components on the board."

Um, no. That's a newbie mistake. It involves trusting the firmware to 
tell the truth about its contents.

Sylvia.

[toc] | [prev] | [next] | [standalone]


#5484

Fromnobody@nowhere.invalid (natp)
Date2014-11-01 01:52 +0000
Message-ID<54543c74.39168176@nntp.aioe.org>
In reply to#5476
Sylvia Else <sylvia@not.at.this.address> wrote:

>On 28/10/2014 9:15 PM, Rich wrote:
>> http://onerng.info/
>
>
>"You can ask it to dump the current firmware to you, you can see all the 
>components on the board."
>
>Um, no. That's a newbie mistake. It involves trusting the firmware to 
>tell the truth about its contents.
>
>Sylvia.

You need a much simpler circuit that you can trust, such as this:
http://web.jfet.org/hw-rng.html

Hard to envision the NSA putting a back door in a 2N3904 transistor.

[toc] | [prev] | [standalone]


Back to top | Article view | comp.misc


csiph-web