Transterrestrial Musings  


Amazon Honor System Click Here to Pay

Space
Alan Boyle (MSNBC)
Space Politics (Jeff Foust)
Space Transport News (Clark Lindsey)
NASA Watch
NASA Space Flight
Hobby Space
A Voyage To Arcturus (Jay Manifold)
Dispatches From The Final Frontier (Michael Belfiore)
Personal Spaceflight (Jeff Foust)
Mars Blog
The Flame Trench (Florida Today)
Space Cynic
Rocket Forge (Michael Mealing)
COTS Watch (Michael Mealing)
Curmudgeon's Corner (Mark Whittington)
Selenian Boondocks
Tales of the Heliosphere
Out Of The Cradle
Space For Commerce (Brian Dunbar)
True Anomaly
Kevin Parkin
The Speculist (Phil Bowermaster)
Spacecraft (Chris Hall)
Space Pragmatism (Dan Schrimpsher)
Eternal Golden Braid (Fred Kiesche)
Carried Away (Dan Schmelzer)
Laughing Wolf (C. Blake Powers)
Chair Force Engineer (Air Force Procurement)
Spacearium
Saturn Follies
JesusPhreaks (Scott Bell)
Journoblogs
The Ombudsgod
Cut On The Bias (Susanna Cornett)
Joanne Jacobs


Site designed by


Powered by
Movable Type
Biting Commentary about Infinity, and Beyond!

« An Interesting COTS Discussion | Main | "Tell The Christians To Come Home" »

NIST/NSA "Have Some Explaining To Do"

Bruce Schneier wonders if there is a back door in a NIST/NSA-approved random number generator. This seems like a good market opportunity for Jeff Manber.

Posted by Rand Simberg at November 16, 2007 06:38 AM
TrackBack URL for this entry:
http://www.transterrestrial.com/mt-diagnostics.cgi/8510

Listed below are links to weblogs that reference this post from Transterrestrial Musings.
Comments

I'm well aware of who Bruce Schneier is but this is sort of a non-story, on second thought I think he intended it as such too. Entertaining and funny but more of a curiosity than anything else. Or perhaps not: it could simply be the US government needs to improve its ability to snoop on itself.

Windows? Linux? The OS is unimportant in this regard (not that I would use either for something truly secret or critical) because of the big and important distinction between inherently poor random number generators (usually called PRNGs, P for Pseudo) and high quality randomness sources (usually called "true RNGs"). If you have a good random source hooked up to your computer then you don't need a generator as such since a generator merely tries to simulate a good source (and never ever by definition truly manages).

By the way this is not an opportunity for Yuzoz. Buying randomness from someone else defeats the purpose for anything truly secret rather than merely "obfuscated".

Posted by Habitat Hermit at November 16, 2007 06:33 PM

By the way this is not an opportunity for Yuzoz. Buying randomness from someone else defeats the purpose for anything truly secret rather than merely "obfuscated".

Good point. ;-)

Posted by Rand Simberg at November 16, 2007 06:45 PM


Post a comment
Name:


Email Address:


URL:


Comments: