LINUX.IE, website of the Irish Linux Users' Group
Tux rules!

   
Home
New Users
Articles
Download
Projects
Community
Vendors

  Print Version
Email to...
 
Archives:


planetILUG

Recent News

News Archive


Join the
ILUG
on FaceBook


Join the
ILUG
on LinkedIn


Join the
ILUG SETI
Group



















 
 :: Mailing Lists

[ILUG] serious Debian/Ubuntu security hole found

[ILUG] serious Debian/Ubuntu security hole found

Timothy Murphy gayleard at eircom.net
Sat May 17 11:06:09 IST 2008


On Friday 16 May 2008 05:52:33 pm Michael Watterson wrote:

> You don't need to know anything about quantum mechanics to make a USB
> key with zener and ADC in it. You can read it for the next 10,000,0000
> years (at 1G samples / sec) and never see a pattern nor predict what the
> next number will be. Does it matter how often you read it? Think of a
> dice thrown continuously.  It  doesn't  make any difference when you
> look or how often you look, it has no memory. The odds of a six on any
> one throw are 1/6th. But you can never know what a previous or later
> throw is without actually viewing the event.

But how do you know?
Are you an expert on Zener diodes, or are you taking the word
of someone who is?
How do you know there is no pattern?

The point is, if you use a standard mathematical
pseudo random number generator
you can be sure it has been studied by hundreds if not thousands
of highly qualified people, who have tried and failed to find a pattern
in the output of the algorithm.

If you use some physical device such as you are speaking about
you are basically taking the word of one or two people
who have almost certainly never tested the device to see if
there is some obvious non-randomness in the output.





-- 
Timothy Murphy  
e-mail: gayleard /at/ eircom.net
tel: +353-86-2336090, +353-1-2842366
s-mail: School of Mathematics, Trinity College, Dublin 2, Ireland



More information about the ILUG mailing list
Read this without the formatting.
                                                                                                    

 

Hosted by HEAnet


Maintained by the ILUG website team. The aim of Linux.ie is to support and help commercial and private users of Linux in Ireland. You can display ILUG news in your own webpages, read backend information to find out how. Networking services kindly provided by HEAnet, server kindly donated by Dell. Linux is a trademark of Linus Torvalds, used with permission. No penguins were harmed in the production or maintenance of this highly praised website. Looking for the Indian Linux Users' Group? Try here. If you've read all this and aren't a lawyer: you should be!
RSS Version
Powered by Dell