logoalt Hacker News

strenholmeyesterday at 2:15 PM2 repliesview on HN

There are theoretical issues where a malicious source of entropy could control the PRNG output, but it’s not a very practical attack.

https://blog.cr.yp.to/20140205-entropy.html

Intel could much more easily compromise and attack systems than make an implementation of RdRand which is malicious in this manner.


Replies

tptacekyesterday at 5:13 PM

If a deliberate covert channel is the best thing you can come up with from a vulnerability, you usually don't have much of a vulnerability.

apiyesterday at 2:20 PM

Oh yeah, if your hardware is malicious you are pretty much F'd.

show 1 reply