Re: One real life secure random generator

New Message Reply About this list Date view Thread view Subject view Author view

Ben Laurie (ben@algroup.co.uk)
Wed, 15 Jul 1998 10:56:39 +0100


Carl Ellison wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
>
> At 11:27 PM 7/14/98 +0100, Ben Laurie wrote:
> >My idea was to poll the mouse once every second or so, rather than 20
> >times a second. This would reduce the loss of entropy because of
> >predictable mouse positions without severe overhead. Even better would
> >be to do it during idle processing (if you are in no hurry to get the
> >entropy).
>
> Ben,
>
> the last time I analyzed pointing data, the real entropy source came from
> high frequency components (of the mouse track, sampled frequently). If you
> sample only once a second, you lose those high frequencies.

I think we've suffered a bit of context loss here: my point was that
sampling at regular intervals seemed to me to be better than sampling at
mouse down/up events. The counterpoint was that sampling 20 times/second
kills the machine, so I opined that once per second was still better
than on mouse up/down events.

> BTW, I also found that if you ask the user to do something non-mouse (e.g.,
> sign his name or sign "John Handcock"), then the high frequency noise is
> even greater -- over 1 bit per mouse sample.

I've noticed that some mice will sometimes do a 1-pixel jitter when you
aren't even touching them. Presumably this looks like useful input but
is actually nearly completely entropy-free.

Cheers,

Ben.

-- 
Ben Laurie            |Phone: +44 (181) 735 0686| Apache Group member
Freelance Consultant  |Fax:   +44 (181) 735 0689|http://www.apache.org/
and Technical Director|Email: ben@algroup.co.uk |
A.L. Digital Ltd,     |Apache-SSL author     http://www.apache-ssl.org/
London, England.      |"Apache: TDG" http://www.ora.com/catalog/apache/

WE'RE RECRUITING! http://www.aldigital.co.uk/recruit/


New Message Reply About this list Date view Thread view Subject view Author view

 
All trademarks and copyrights are the property of their respective owners.

Other Directory Sites: SeekWonder | Directory Owners Forum

The following archive was created by hippie-mail 7.98617-22 on Fri Aug 21 1998 - 17:20:24 ADT