TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Backdooring the Lottery [pdf]

99 pointsby enricotalalmost 8 years ago

7 comments

dghughesalmost 8 years ago
Didn&#x27;t read the pdf but I used to work for a lottery Corp and from what I heard security was nuts. One of the server room IT guys left for Blue Cross and later said Blue Cross was much less strict than the lottery.<p>I also recall one of the compliance guys telling me about the balls used in one of those bingo ball tumbling machines. He said they had to wash, dry and weigh each ball before every draw. Of course it was fun to yell to him saying on draw day &quot;hey it&#x27;s Friday did you wash and dry your balls?&quot;
评论 #14885533 未加载
mrbalmost 8 years ago
As an infosec pro, If I was in charge of a lottery RNG, I would require the use of a recent unmodified Linux or OpenBSD distro and simply use getrandom(2). These custom RNG introduce 100% unnecessary complexity and risks. I am baffled none of them seem to do that and they need thirdparty certification procedures (who miss RNG flaws anyway.)
评论 #14894060 未加载
评论 #14884321 未加载
评论 #14888951 未加载
madezalmost 8 years ago
I wonder why they didn&#x27;t go for an easy technique to defend against backdoors: use two independent sources for random numbers that don&#x27;t know of each other and xor their output together. The increase in cost is small and the win for integrity and security is huge.
评论 #14884345 未加载
评论 #14885267 未加载
评论 #14893527 未加载
评论 #14885430 未加载
评论 #14884440 未加载
thephyberalmost 8 years ago
I remember reading about the MUSL RNG fraud recently (1-2 years ago). Interesting that they are tying state lottery frauds to that malicious insider from as far back as 2005 (or so the slides suggest).
评论 #14885557 未加载
matt_wulfeckalmost 8 years ago
The idea of a public&#x2F;random mixing source is always fun. Everybody has a fun pet idea but they all suffer from one issue or another. Here&#x27;s some of mine:<p>1. Move the mouse around<p>2. Force someone to dance and read the output from a webcam<p>3. Record various RF signals<p>4. Speak a joke into a microphone.<p>The best solution is probably just a plain, non-network computer with an open-hardware TRNG to mix the CSPRNG (I believe BSD is switching to Fortuna). Read from the CSPRNG all day loooong.
gwernalmost 8 years ago
Anyone getting SSL errors trying to load the slides? Nothing seems to work, including proxying over Tor.
评论 #14883941 未加载
评论 #14883665 未加载
评论 #14883714 未加载
评论 #14883710 未加载
callesggalmost 8 years ago
Is there a video of their talk?
评论 #14893397 未加载