Gentoo Archives: gentoo-hardened

From: RB <aoz.syn@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Bought an "entropy-key" - very happy
Date: Thu, 25 Mar 2010 21:03:00
Message-Id: 4255c2571003251341i2d00bd03l9ab27ea1f8079193@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Bought an "entropy-key" - very happy by Ed W
1 On Thu, Mar 25, 2010 at 14:34, Ed W <lists@××××××××××.com> wrote:
2 > I noticed a munin script in the ekeyd download - haven't tried it, but the
3 > quantity of variables you can monitor from the device seemed quite
4 > impressive.  Who would have thought you would have wanted to graph the
5 > temperature of your random number generator, but for those who do, you are
6 > in luck...
7
8 Thermal and power fluctuations are common approaches to subverting the
9 entropy available in an RNG. Thermal noise based entropy generators
10 are particularly sensitive to this - reduce the temperature, reduce
11 the entropy. IIRC, the VIA RNG is based on a pair of thermal sensors,
12 but since they're on-die it's regarded more as difficult to subvert
13 than an external set.