Wheel of Fortune (33c3)

Title:
Wheel of Fortune (33c3)
Description:

https://media.ccc.de/v/33c3-7949-wheel_of_fortune

Analyzing Embedded OS Random Number Generators

Secure random number generators play a crucial role in the wider security ecosystem. In the absence of a dedicated hardware True Random Number Generator (TRNG), computer systems have to resort to a software (cryptographically secure) Pseudo-Random Number Generator (CSPRNG). Since the (secure) design of a CSPRNG is an involved and complicated effort and since randomness is such a security-critical resource, many operating systems provide a CSPRNG as a core system service and many popular security software products assume their presence. The constraints imposed by the embedded world, however, pose a variety of unique challenges to proper OS (CS)PRNG design and implementation which have historically resulted in security failures. In this talk we will discuss these challenges, how they affect the quality of (CS)PRNGs in embedded operating systems and illustrate our arguments by means of the first public analysis of the OS random number generators of several popular embedded operating systems.

['Jos Wetzels', 'Ali Abbasi']

more » « less
Video Language:
English
Duration:
36:49
C3Subtitles edited English subtitles for Wheel of Fortune (33c3)
C3Subtitles added new URL for Wheel of Fortune (33c3)
C3Subtitles added a video: Wheel of Fortune (33c3)
http://www.youtube.com/watch?v=brYdF-iks0Q
Format: Youtube
Primary
Original
Added   by C3Subtitles
Format: Youtube
Primary
Original
http://www.youtube.com/watch?v=2EPMsIRfVsw
Format: Youtube
Added   by C3Subtitles
Format: Youtube
This video is part of Amara Public.

Subtitles download

Incomplete subtitles (1)