| ▲ | sltkr an hour ago | |
If you cannot trust the platform you're running on, all bets are off. There is a reason so much effort is put in TPM and remote attestation and so on. A compromised kernel doesn't even have to fake any data. It can just read the generated seed directly from user space without the program ever knowing about it. > Sure an infected system may as well fake time values, but that is much more difficult clock_gettime() just reads a value that the kernel has set, so that's not particularly difficult to fake. If you're thinking of using RDTSC instructions directly, that's of course not portable, and at that point you might as well call RDRAND directly, which is at least designed to provide random data. > it's possible to detect from a userspace program. There is no detection that is guaranteed to work on a compromised system. And whatever detection you have in mind to make the algorithm resistant to tampering was _not_ part of the original for-loop. You cannot claim the for-loop is superior to just calling getentropy() because it "can detect" clock tampering, while handwaving away the actual code to detect this clock tampering. > it's an implementation that is used in a lot of security software (including GPG, not as the sole source of course but as one of many). It's fine if you use it as a strictly additional source of entropy, but then the whole argument that it is superior because it avoids syscalls goes out of the window, because you're doing strictly _more_ work. | ||
| ▲ | Taek an hour ago | parent [-] | |
The strength in this method is that it has the littlest possible surface area for upstream bugs to compromise your final entropy. Because, in the applied world, upstream bugs in "secure" system RNGs have been the cause of stolen crypto and other critical security compromises on numerous occasions. And, I agree that if the system is compromised to the level that the attacker can control the output of the timer, it's probably compromised to the level that the attacker can just read your generated entropy straight from memory. The point here is not to be fast, it's to be protected against implementation bugs on systems that weren't designed by security professionals. | ||