How do we know our PRNGs work properly? (33c3)
- Title:
- How do we know our PRNGs work properly? (33c3)
- Description:
-
more » « less
https://media.ccc.de/v/33c3-8099-how_do_we_know_our_prngs_work_properly
Pseudo-random number generators (PRNGs) are critical pieces of security
infrastructure. Yet, PRNGs are surprisingly difficult to design,
implement, and debug. The PRNG vulnerability that we recently found in
GnuPG/Libgcrypt (CVE-2016-6313) survived 18 years of service and several
expert audits. In this presentation, we not only describe the details of
the flaw but, based on our research, explain why the current state of
PRNG implementation and quality assurance downright provokes incidents.
We also present a PRNG analysis method that we developed and give
specific recommendations to implementors of software producing or
consuming pseudo-random numbers to ensure correctness.Vladimir Klebanov Felix Dörre
- Video Language:
- English
- Duration:
- 58:36
![]() |
C3Subtitles edited English subtitles for How do we know our PRNGs work properly? (33c3) | |
![]() |
C3Subtitles added new URL for How do we know our PRNGs work properly? (33c3) | |
![]() |
C3Subtitles added a video: How do we know our PRNGs work properly? (33c3) |