‹ BackHN Continuity

Thread

AMD's random number generator can't generate a 0?

288 points · 220 comments · BruceEel

  1. throwawayffffas · · focus · HN ↗
    So what? The point is to be non predictable not to pick all the numbers in the range with exactly the same probability. Would it be a problem if it never generated 16542?
    1. gnfargbl · · focus · HN ↗
      Consider an 8-bit RNG.

      By your argument, it would not be a problem if the RNG never generated 0. So, it must follow that it would also not be a problem if it never generated {1, 2, 3, ..., 253}.

      That means that our RNG now only generates the values 254 and 255. Which of the values is generated is unpredictable on any given call. However, 7 of the 8 output bits are now always fixed and so completely predictable. Can you imagine how an attacker could exploit that?

      Failing to generate only the number 0 is a weaker version of the same class of flaw.

      1. throwawayffffas · · focus · HN ↗
        The value space goes from 2^16, 2^32, 2^64 to 2^16 - 1, 2^32 - 1, and 2^64 - 1 respectively.

        The bug has zero practical impact.

        1. gnfargbl · · focus · HN ↗
          It is absolutely untrue that a biased RNG has "zero practical impact." Modern cryptography has plenty of examples of relatively small biases leading to breaks. Check out Bleichenbacher's attack, for instance.

          You could be correct that the very small bias here is not enough to be exploitable. But, given the history around this, it would be wrong to handwave it away as trivial.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.