The maintainers of the security-conscious FreeBSD operating system have declared that they will no longer rely on the random number generators in Intel and Via's chips, on the grounds that the NSA likely has weakened these opaque hardware systems in order to ease surveillance. The decision is tied to the revelations of the BULLRUN/EDGEHILL programs, wherein the NSA and GCHQ spend $250M/year sabotaging security in standards, operating systems, software, and networks.
"For 10, we are going to backtrack and remove RDRAND and Padlock backends and feed them into Yarrow instead of delivering their output directly to /dev/random," FreeBSD developers said. "It will still be possible to access hardware random number generators, that is, RDRAND, Padlock etc., directly by inline assembly or by using OpenSSL from userland, if required, but we cannot trust them any more."
In separate meeting minutes, developers specifically invoked Snowden's name when discussing the change.
"Edward Snowdon [sic] -- v. high probability of backdoors in some (HW) RNGs," the notes read, referring to hardware RNGs. Then, alluding to the Dual EC_DRBG RNG forged by the National Institute of Standards and Technology and said to contain an NSA-engineered backdoor, the notes read: "Including elliptic curve generator included in NIST. rdrand in ivbridge not implemented by Intel... Cannot trust HW RNGs to provide good entropy directly. (rdrand implemented in microcode. Intel will add opcode to go directly to HW.) This means partial revert of some work on rdrand and padlock."
“We cannot trust” Intel and Via’s chip-based crypto, FreeBSD developers say [Dan Goodin/Ars Technica]
The US Department of Homeland Security has published a new proposed rule that would make people ineligible for US citizenship if their credit-scores were poor.
A recent Pew poll challenged subjects to distinguish between factual statements and statements of opinion in news articles; it found that there is a large gap in accuracy between 18- to 49-year-olds (32% of whom correctly labeled 100% of the facts, and 44% of whom correct labeled 100% of the opinions) and those aged 50 […]
The Pew Center reports that there's been virtually no growth in US adoption of broadband, computers, mobile devices, or smart home devices for two years, and not just because of saturation: the top culprit is substandard, unavailable and/or overpriced broadband; also prominent is older peoples' fear of their own technological illiteracy. (via /.)
Take a scroll through any app marketplace and you’ll see that the doors are wide open for any game these days – and any game developer. Like any creation, virtual or analog, it all starts with an idea. And if you’ve got one of those, the Complete Unity Game Developer Bundle can walk you the […]
At the rate the world is shrinking, you don’t need to be a globetrotter for a second language to be a useful skill. And if you’re looking to learn that second language (or a third, or fourth), uTalk Language Education is the learning program that makes progression not only easy but fun. If you can’t […]
Smokers on the go can breathe a little easier. With an innovative, easy-loading spiral design, the Twisty Glass Blunt offered a smoother, more consistent draw than conventional pipes. Now the Twisty Glass Mini delivers the benefits of its heavy-duty sister pipe in a more discreet package. For those that haven’t already made the Twisty Glass […]