[Libre-soc-dev] microwatt grows up LCA2021

Luke Kenneth Casson Leighton lkcl at lkcl.net
Sun Jan 31 13:08:18 GMT 2021

(context of link: analysis process for testing RNGs)

paul the last question asked, about the RNG, slapped wrist for saying it
can be trusted to be secure! :)

mathematically, nobody can give guarantees (ever), in a nutshell the only
thing you can say 100% is, "no nightmare scenario has occurred... so far".

there are "degrees of catastrophic breakage" that can be demonstrated
quicker with less resources, these eliminate the worst algorithms quickly.
 over time you have to spend progressively more resources to find the ways
in which to find broken-ness, and the really good algorithms survive that
process far longer...

... but nobody, not ever, can make a categorical statement, "this
cryptographic algorithm is secure".

ultimately there is no 100% categorical test which proves security.  the
best that can be done is a process which cautiously declares, "it ain't
broke... so far"

sorry for picking up on that and nit-picking :)


