Random Problems in IoT

No ratings

Presented at BSidesLondon 2018 by

Random Numbers are important. Really f***ing important! Yet, they are so often misunderstood. Decent Random Number generation is relied upon by large chunks of our cryptographic wizardry, and yet mistakes are repeatedly made - and we're seeing these mistakes bleeding into IoT.With the proliferation of 'smart' devices, what affects the security of these devices could affect anything from lightbulbs to pacemakers. The author's own research has found some real problems with embedded devices generating random numbers, some proposed fixes, and then some problems with those for good measure.We will present an overview of what 'random' is (with little to no scary maths), the current state of the art, and overview of embedded devices RNG's, our assessment results, and how things can move forward.This talk will give you:A solid overview of the basics of RNGSome handy hints and nifty tricks for understanding what 'random' really isAn overview of the well-known problems in embedded/IoT RNG's - microcontrollers and SDK's just doing it wrongAn assessment of what fixes are available - which ones we found issues with, and which seem to work betterHSM's and other solutions we look to assessWhat manufacturers, vendors, compliance bodies, and developers can doThis talk is suitable for people of any technical level, but is aimed at those with an interest in IoT security, cryptography, and hardware.