‹ BackHN Continuity

Thread

AMD's random number generator can't generate a 0?

288 points · 220 comments · BruceEel

  1. jstanley · · focus · HN ↗
    This is not the first RNG bug on Zen 2, I recall after I first got mine that some application or other would quit immediately at startup because rdrand always returned -1, i.e. all 1s. It was fixed with a microcode update.

    Do we now learn that they fixed "always generate all 1s" with "never generate all 0s"??

    EDIT: I've been unable to reproduce the problem on my CPU, FWIW. It's a Ryzen 5 3600.

    EDIT2: OK, update, I can reproduce it with rdrand16, rdrand32 is fine but rdrand16 can never generate all 0s. So my CPU does have this problem!

    1. jamesponddotco · · focus · HN ↗
      If I remember correctly, we had a setting in every Linux server we owned to remove CPU as a RNG seeder for the kernel because of those bugs with AMD CPUs.

      I.e., we had `random.trust_cpu=off nordrand` in `GRUB_CMDLINE_LINUX`.

      1. knorker · · focus · HN ↗
        Adding bad randomness can't degrade good randomness, can it?

        I thought the kernel would not replace anything just because it adds a potentially bad source.

        E.g. if you have rand source A, and xor it with rand source B, then you get, at worst, the best of A and B,

        1. jamesponddotco · · focus · HN ↗
          As far as I know that is correct; the kernel was written in a way such that one bad source doesn’t poison the pool. Still, if you know one source is bad, might as well take it out.
          1. knorker · · focus · HN ↗
            > if you know one source is bad, might as well take it out.

            Yes and no. Mostly no.

            In a simplified model, it's only useless if it adds zero bits of entropy. But if a source that's supposed to add 128 bits of entropy only adds 16, well, it's still 16.

            I would never trust RDRAND on its own. If nothing else because it's always subject to a microcode backdoor. But if I already have something I'm happy with the entropy of, sure, I'd XOR it with RDRAND output. It cannot make it worse.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.