The maintainers of the security-conscious FreeBSD operating system have declared that they will no longer rely on the random number generators in Intel and Via's chips, on the grounds that the NSA likely has weakened these opaque hardware systems in order to ease surveillance. The decision is tied to the revelations of the BULLRUN/EDGEHILL programs, wherein the NSA and GCHQ spend $250M/year sabotaging security in standards, operating systems, software, and networks.
"For 10, we are going to backtrack and remove RDRAND and Padlock backends and feed them into Yarrow instead of delivering their output directly to /dev/random," FreeBSD developers said. "It will still be possible to access hardware random number generators, that is, RDRAND, Padlock etc., directly by inline assembly or by using OpenSSL from userland, if required, but we cannot trust them any more."
In separate meeting minutes, developers specifically invoked Snowden's name when discussing the change.
"Edward Snowdon [sic] -- v. high probability of backdoors in some (HW) RNGs," the notes read, referring to hardware RNGs. Then, alluding to the Dual EC_DRBG RNG forged by the National Institute of Standards and Technology and said to contain an NSA-engineered backdoor, the notes read: "Including elliptic curve generator included in NIST. rdrand in ivbridge not implemented by Intel... Cannot trust HW RNGs to provide good entropy directly. (rdrand implemented in microcode. Intel will add opcode to go directly to HW.) This means partial revert of some work on rdrand and padlock."
“We cannot trust” Intel and Via’s chip-based crypto, FreeBSD developers say [Dan Goodin/Ars Technica]
America's telcoms sector is hugely concentrated and corrupt, and systematically underinvests in maintenance and infrastructure even as it gouges customers, which it can get away with thanks to its monopoly power, leaving Americans with some of the world's worst, most expensive communications services.
The past two years have seen a tremendous shift in the public perception of capitalism and socialism, the character of philanthropy as reputation-laundry rather than generosity, and the nature of wealth as an indicator of sociopathy, not virtue or cleverness.
Elizabeth Warren has released a characteristically detailed campaign plan to counter white nationalist violence in the USA, whose multi-pronged approach includes directing the DoJ to be more vigorous in pursuing white nationalist groups (and to lay off the Cointelpro-style surveillance of groups that advocate for protections for racialized people); centralized data collection on white nationalist […]
There are fast-paced card games, and some of them even require enough dexterity for a mini-workout (like Skip-Bo or Snap). But there’s nothing quite like the Mokuru® Card Game, which uses an already addictive fidget toy as the centerpiece for a cutthroat game of tabletop challenges. The game is named for the toy that gets […]
People who ask themselves why they need a dashcam usually have one thing in common: They’ve never been a serious collision. Even in fender benders, these gadgets can save you an immense amount of time and hassle, stopping headaches before they even start. If you’re looking for a reliable starter cam, the myGEKOgear Orbit 110 […]
There’s no shortage of wireless chargers out there. So when one scores a Best of Innovation Award at the Consumer Electronics Show, we take notice. And, those industry nods mean good news for just about anybody with a smartphone, because the HyperCharger X Wireless Charger means there’s no excuse for losing power when you’re out […]