{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T20:38:07Z","timestamp":1772051887731,"version":"3.50.1"},"reference-count":19,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2022,6,30]],"date-time":"2022-06-30T00:00:00Z","timestamp":1656547200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Queue"],"published-print":{"date-parts":[[2022,6,30]]},"abstract":"<jats:p>Many in the cryptographic community scoff at the mistakes made in implementing RNGs. Many cryptographers and members of the IETF resist the call to make TLS more resilient to this class of failures. This article discusses the history, current state, and fragility of the TLS protocol, and it closes with an example of how to improve the protocol. The goal is not to suggest a solution but to start a dialog to make TLS more resilient by proving that the security of TLS without the assumption of perfect random numbers is possible.<\/jats:p>","DOI":"10.1145\/3546933","type":"journal-article","created":{"date-parts":[[2022,7,18]],"date-time":"2022-07-18T21:18:50Z","timestamp":1658179130000},"page":"18-40","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["The Challenges of IoT, TLS, and Random Number Generators in the Real World"],"prefix":"10.1145","volume":"20","author":[{"given":"James P.","family":"Hughes","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Whitfield","family":"Diffie","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,7,18]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Althouse J. 2019. TLS fingerprinting with JA3 and JA3S. Salesforce Engineering; https:\/\/engineering.salesforce.com\/tls-fingerprinting-with-ja3-and-ja3s-247362855967."},{"key":"e_1_2_1_2_1","volume-title":"Recommendation for random number generation using deterministic random bit generators (revised). U.S. Department of Commerce","author":"Barker E.B.","unstructured":"Barker, E.B., Kelsey, J.M., et al. 2007. Recommendation for random number generation using deterministic random bit generators (revised). U.S. Department of Commerce, National Institute of Standards and Technology; https:\/\/www.nist.gov\/publications\/recommendation-random-number-generation-using-deterministic-random-bit-generators-2."},{"key":"e_1_2_1_3_1","series-title":"Lecture Notes in Computer Science Essays, The New Codebreakers","volume-title":"Dual EC: a standardized back door","author":"Bernstein D.J.","unstructured":"Bernstein, D.J., Lange, T., Niederhagen, R. 2016. Dual EC: a standardized back door. In Lecture Notes in Computer Science Essays, The New Codebreakers, volume 9100, ed. P.Y.A. Ryan, D. Naccache, and J.-J. Quisquater, 256?281. Springer-Verlag; https:\/\/dl.acm.org\/doi\/abs\/10.1007\/978-3-662-49301-4_17."},{"key":"e_1_2_1_4_1","volume-title":"10th Usenix Workshop on Offensive Technologies; https:\/\/www.usenix.org\/conference\/woot16\/workshop-program\/presentation\/bock.","author":"B\u00f6ck H.","year":"2016","unstructured":"B\u00f6ck, H., Zauner, A., Devlin, S., Somorovsky, J., Jovanovic, P. 2016. Nonce-disrespecting adversaries: practical forgery attacks on GCM in TLS. In 10th Usenix Workshop on Offensive Technologies; https:\/\/www.usenix.org\/conference\/woot16\/workshop-program\/presentation\/bock."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32101-7_1"},{"key":"e_1_2_1_6_1","volume-title":"The Mythical Man-month: Essays on Software Engineering","author":"Brooks","unstructured":"Brooks Jr., F.P. 1995. The Mythical Man-month: Essays on Software Engineering. Addison-Wesley Professional."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2013.29"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Diffie W. Van Oorschot P.C. Wiener M.J. 1992. Authentication and authenticated key exchanges. Designs Codes and Cryptography 2(2) 107?125; https:\/\/dl.acm.org\/doi\/10.1007\/BF00124891.","DOI":"10.1007\/BF00124891"},{"key":"e_1_2_1_10_1","volume-title":"Proceedings of the Workshop on the Theory and Application of Cryptographic Techniques, 329?354","author":"Flajolet P.","year":"1989","unstructured":"Flajolet, P., Odlyzko, A.M. 1989. Random mapping statistics. In Proceedings of the Workshop on the Theory and Application of Cryptographic Techniques, 329?354. Springer; https:\/\/dl.acm.org\/doi\/10.5555\/111563.111596."},{"key":"e_1_2_1_11_1","unstructured":"Garske D. 2021. Deprecate CyaSSL library #151. GitHub; https:\/\/github.com\/cyassl\/cyassl\/pull\/151."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2987443.2987486"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the 21st Usenix Security Symposium, 35; https:\/\/dl.acm.org\/doi\/10","author":"Heninger N.","year":"2012","unstructured":"Heninger, N., Durumeric, Z., Wustrow, E., Halderman, J.A. 2012. Mining your Ps and Qs: detection of widespread weak keys in network devices. In Proceedings of the 21st Usenix Security Symposium, 35; https:\/\/dl.acm.org\/doi\/10.5555\/2362793.2362828."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPS-ISA48467.2019.00030"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-75670-5_1"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32009-5_37"},{"key":"e_1_2_1_18_1","series-title":"January 14","volume-title":"Flaw found in an online encryption method. New York Times","author":"Markoff J.","year":"2012","unstructured":"Markoff, J. 2012. Flaw found in an online encryption method. New York Times (January 14); https:\/\/www.nytimes.com\/2012\/02\/15\/technology\/researchers-find-flaw-in-an-online-encryption-method.html."},{"key":"e_1_2_1_19_1","volume-title":"The scandalous history of the last rotor cipher machine","author":"Paul J.D.","unstructured":"Paul, J.D. 2021. The scandalous history of the last rotor cipher machine. IEEE Spectrum; https:\/\/spectrum.ieee.org\/the-scandalous-history-of-the-last-rotor-cipher-machine."},{"key":"e_1_2_1_20_1","volume-title":"Recommendation for the entropy sources used for random bit generation. NIST Special Publication 800-90B. U.S. Department of Commerce","author":"Turan M.S.","unstructured":"Turan, M.S., Barker, E., Kelsey, J., McKay, K.A., Baish, M.L., Boyle, M., et al. 2018. Recommendation for the entropy sources used for random bit generation. NIST Special Publication 800-90B. U.S. Department of Commerce, National Institute of Standards and Technology; https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-90b\/final."}],"container-title":["Queue"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3546933","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3546933","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:42Z","timestamp":1750186842000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3546933"}},"subtitle":["Bad random numbers are still with us and are proliferating in modern systems."],"short-title":[],"issued":{"date-parts":[[2022,6,30]]},"references-count":19,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022,6,30]]}},"alternative-id":["10.1145\/3546933"],"URL":"https:\/\/doi.org\/10.1145\/3546933","relation":{},"ISSN":["1542-7730","1542-7749"],"issn-type":[{"value":"1542-7730","type":"print"},{"value":"1542-7749","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,30]]},"assertion":[{"value":"2022-07-18","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}