‹ BackHN Continuity

Thread

AMD's random number generator can't generate a 0?

288 points · 220 comments · BruceEel

  1. ZiiS · · focus · HN ↗
    It is just possible they decided crypto code that uses it was safer to skip zeros. (Whist mathematically it should be no more likely; it is vastly more likely someone will actually try that key).

    It is also possible that their code was generating too many zeros and the easiest fix was to discard them all.

    1. dark-star · · focus · HN ↗
      this is not how crypto works
    2. jstanley · · focus · HN ↗
      Can you clarify what you mean by "it is vastly more likely someone will actually try that key"?

      I'm guessing you don't think there are people calling rdrand in a loop and throwing away the output with high probability except when it is 0, but I can't see how else you imagine people would be vastly more likely to use the output when it is 0?

      1. ZiiS · · focus · HN ↗
        In lots of scenarios I know the software used to generate the key; the only unknown is the random numbers used. If I am searching for weaknesses it is highly likely I would try keys with different seeds; zero, one, are going to me much more likely choices here then hoping I can guess the right values.
        1. jstanley · · focus · HN ↗
          If the keys are selected uniformly at random why are 0 and 1 more likely than other values?
          1. ZiiS · · focus · HN ↗
            Because I don't want my test keys to be random/none reproducable, instead I will just used fixed seeds to see if any timing etc leeks.
            1. jstanley · · focus · HN ↗
              So what has that got to do with rdrand? I literally don't understand what you would get from preventing 0 as output?
        2. necovek · · focus · HN ↗
          If someone was using RDRAND16 to seed a PRNG, choosing to omit one single value (a zero) from the return value would not significantly improve the generated values, if at all.
          1. ZiiS · · focus · HN ↗
            Looked at another way; leaving out the zero also dosn't significantly hurt. If the is any risk if it breaking the PRNG why take the risk.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.