Verification of Random Number Generators

Andrew Loewenstern andrew_loewenstern at il.us.swissbank.com
Tue Sep 19 09:58:16 PDT 1995


>  Just an idle thought: it might be possible to do a probabalistic
>  verification of a RNG by sampling it over some number of samples,
>  and statistically analyzing the sample space. This would be analysis
>  under the model of "RNG as black box" as opposed to (or rather, if
>  you're smart, in addition to) code inspection & review. Any
>  statisticians among us?

But this wouldn't have solved Netscape's problem.  Netscape was using a  
pretty good PRNG (the one in RSAREF).  The problem was they were/are using a  
naive method of seeding it.  The output of the PRNG would have been  
statistically random, but since the seed had ridiculously little entropy it  
was easy to guess.

andrew






More information about the cypherpunks-legacy mailing list