HN user

lordmax

684 karma
Posts194
Comments43
View on HN
kilderov.com 4y ago

Ukranian artist uses captured Russian BTRs as street style canvas

lordmax
5pts0
skibinsky.com 4y ago

“The Matrix Resurrections” is an excellent movie

lordmax
34pts59
www.wsj.com 5y ago

Covid-19 Vaccine: Should Lawmakers Get Priority?

lordmax
3pts2
www.wsj.com 5y ago

The Hunter Biden Business

lordmax
10pts1
www.spiegel.de 5y ago

Norwegian Boy Fends Off Wolf Pack with Heavy Metal

lordmax
1pts1
www.realclearscience.com 5y ago

Painting 'Zebra Stripes' on Cows Wards Off Biting Flies

lordmax
2pts0
stke.sciencemag.org 5y ago

A novel TNFR2 agonist antibody expands highly potent regulatory T cells

lordmax
1pts0
www.washingtonexaminer.com 5y ago

Trump spy chief seeks SEC scrutiny of Chinese dominance in cryptocurrency

lordmax
3pts0
massivesci.com 5y ago

Despite a flashy design, Elon Musk's Neuralink has little substance

lordmax
2pts1
www.technologyreview.com 5y ago

The problems AI has today go back centuries

lordmax
1pts0
www.technologyreview.com 5y ago

Too many AI researchers think real-world problems are not relevant

lordmax
14pts2
medium.com 5y ago

The Third Wave

lordmax
2pts0
www.theatlantic.com 6y ago

John Lewis Was an American Founder

lordmax
29pts0
www.technologyreview.com 6y ago

Will astronauts ever visit gas giants like Jupiter?

lordmax
6pts0
www.cnbc.com 6y ago

The cold war between U.S. and China just got a lot hotter

lordmax
6pts2
puzzlewocky.com 6y ago

Banana Optical Illusion

lordmax
3pts0
waitbutwhy.com 6y ago

The AI Revolution: The Road to Superintelligence

lordmax
5pts0
www.quantamagazine.org 6y ago

Wormholes Reveal a Way to Manipulate Black Hole Information in the Lab

lordmax
1pts0
nav.al 6y ago

Naval and Matt Ridley: How Innovation Works, Part 2

lordmax
3pts0
nav.al 6y ago

Naval and Matt Ridley: How Innovation Works, Part 1

lordmax
3pts0
www.discovermagazine.com 6y ago

Why Quantum Mechanics Still Stumps Physicists

lordmax
5pts0
physicsworld.com 6y ago

Did a black-hole merger create a flash in a distant quasar?

lordmax
1pts0
www.technologyreview.com 6y ago

Astronomers found a giant intergalactic “wall” of galaxies hiding in plain sight

lordmax
5pts0
news.ycombinator.com 6y ago

Show HN: Math Puzzle

lordmax
1pts0
www.sciencemag.org 6y ago

Blood vessel attack could trigger coronavirus’ fatal ‘second phase’ – Science

lordmax
11pts0
www.technologyreview.com 6y ago

Police across the US are training crime-predicting AIs on falsified data

lordmax
2pts0
daringfireball.net 6y ago

‘What Time Is It in London?’

lordmax
2pts0
www.wsj.com 6y ago

The Germs That Transformed History (Jared Diamond)

lordmax
2pts0
www.wsj.com 6y ago

When Will Big Concerts Finally Return After Covid?

lordmax
1pts0
www.technologyreview.com 6y ago

Why simply waiting for herd immunity to Covid-19 isn’t an option

lordmax
2pts0

Far better solution IMHO built after industry discussion of "lava wall" years ago: https://bit.ly/3naYEBP Of course, by now we got hardware rng RPi, TrueRNG, security enclave rng - largely a solved problem on most of practical systems. just setup right, seed right and use `/dev/urandom`

[dead] 6 years ago

best of twitter so far: "This simulation is getting so wild"

Here is the problem: most of these stats are not what they pretend to be (unless exact circuit / spec is published). Look at low level details of building say avalanche noise source: http://holdenc.altervista.org/avalanche/ - bandwidth is mostly bound by voltage/frequency/sampling resolution - how often you can trigger entropy event and how many of them in parallel? True result for one AN circuit: 2000 bits/sec.

What a lot of these vendors do is have some physical phenomena on the chip that feeds hardware "whitener" (endless hashing) that responds without blocking to all requests. That's practically hardware version of “/dev/urandom" that is bound only by chip IO - but its completely disconnected from bandwidth of actual “true” entropy phenomena underneath. of course it is still good CSRNG, but its not “true” source. btw nice exception: TrueRNG team are pretty honest providing direct schema - hence the real entropy speed of 40kb/sec.

In short every single entry on that list should be independent inspected down to specs and schema of whitener. If they are not publishing chip spec with exact details I highly highly doubt the bandwidth of “true” entropy events are really approaching GBps - this is the speed of whitener, not of actual generator.

The key property for crypto randomness here is that these high energy particle events (be that cosmic rays, background radiation, etc) are not just random, but independent from thermal noise. They are few and far between but they affect each sample somewhere. One way or another all that entropy will get hashed, and having even few bits that are contributed by independent phenomena makes final hash extremely hard to attack.

Considering all sources that contribute noise to sensors (thermal, light photons count, high energy particles, shot/RTS noise, and i'm probably missing a few), all with unique distributions and characteristics makes each sample readout very hard to predict.

DJB retort on this is now stuff of crypto hall of fame: https://gist.github.com/tarcieri/6347417#file-gistfile1-txt

--- Cryptographers are certainly not responsible for this superstitious nonsense. Think about this for a moment: whoever wrote the /dev/random manual page seems to simultaneously believe that

   (1) we can't figure out how to deterministically expand one 256-bit
       /dev/random output into an endless stream of unpredictable keys
       (this is what we need from urandom), but

   (2) we _can_ figure out how to use a single key to safely encrypt
       many messages (this is what we need from SSL, PGP, etc.).
For a cryptographer this doesn't even pass the laugh test. --- <

worth mentioning (that sort of main premise of the article that gets a little bit unnoticed in all the methodology discussion): all existing HWRNG are relatively low bandwidth - because they are bound by physical process, rather then endless spinning up of /dev/urandom. They all have to wait for physics to produce each bit, and existing chips don't have that much "physics" in them.

The main novelty factor of "camera noise HRNG" is that we effectively leveraging 12M micro HRNGs in parallel - thats where that firehose of entropy is coming from.

I checked on that a while back as well. As far as i can find out SE HRNG is not exposed to user at all. It used internally in quite complicated process of secure booting and unlocking iOS device (there is an interesting presentation floating around with all details of reverse engineering of that process, and amount of security designed by Apple into their own hardware-to-hardware protocols is on very respectable level of insane). I think its likely SE HRNG is included in seeding /dev/urandom on iOS, so it is one of the most secure CSPRNGs around.

you are completely correct - as I mentioned in the end this would be easier extractor: "Want to relax IID assumptions and avoid careful setup of a non-correlated quantizer? Easy — use any good universal hash function. The only new requirement is that the universal hash will require a one-time seed. We can make an easy assumption that the iPhone local state of /dev/urandom is totally independent from thermal noise camera is seeing, and simply pick that seed from everybody's favorite CSPRNG."

The main reason we went with VN instead of SHA or universal hash is just was more fun thing to build/experiment with. SHA is like flamethrower that will deal with anything you throw at it. VN is far more brittle and you see all mistakes in scenery or generation. Of course then you hash the output anyway before use!

you are quite correct about this - "lens closed" mode has least amount of entropy by our measure. However its clearly proportional to intensity of light hitting the sensor (and beside natural photon variance of light itself, the shot noise in sensor increases with more light). So in what we call "optimal" conditions - enough light to generate noise, not enough to oversaturated there is plenty of natural entropy coming from the sensor.

Matthew, there is my personal collection of entropy sources for your reference. That stuff is addictive!

- True quantum source: http://whitewoodsecurity.com/products/entropy-engine/

- Atmospheric noise: https://www.random.org/randomness/

- Avalanche Effect Generators http://holdenc.altervista.org/avalanche/ http://ubld.it/truerng_v3

- Great deck about overall entropy engineering https://www.blackhat.com/docs/us-15/materials/us-15-Potter-U...

And of course "lave wall" we mentioned just takes the cake: https://sploid.gizmodo.com/one-of-the-secrets-guarding-the-s...

No Russian, part 2 12 years ago

the article was mostly shared by Russian's themselves. I think they wanted for somebody to get this message out for them in light of recent events.

No Russian 12 years ago

There is a massive amount of secondary evidence, all of which points in the same direction. Here is few research resources, unfortunately they are all in russian; perhaps google translate will recover enough meaning for it to be useful:

http://www.solonin.org/article_sbityiy-boing-medlenno-i-po http://www.echo.msk.ru/programs/code/1362312-echo/ http://gordonua.com/publications/Belkovskiy-Vse-plany-Putina... http://www.youtube.com/watch?v=MiZ43EunqvM http://www.youtube.com/watch?v=ludDRApl7nU

3 hours is upper bound and extremely friendly one to allow for all but hopelessly incompetent candidates. I did the test in less than 90 min. First 27 questions should take a competent hacker less than 20 min; rest of the time is for last 3 coding assignments.