220 35469 <ad3d1b43-884f-4f85-a365-ad6ed8158d9e@isocpp.org> article
Path: news.gmane.org!.POSTED!not-for-mail
From: Arthur O'Dwyer <arthur.j.odwyer@gmail.com>
Newsgroups: gmane.comp.lang.c++.isocpp.proposals
Subject: Re: Re: On P0829 - a freestanding implementation
Date: Wed, 22 Nov 2017 22:19:23 -0800 (PST)
Lines: 209
Approved: news@gmane.org
Message-ID: <ad3d1b43-884f-4f85-a365-ad6ed8158d9e@isocpp.org>
References: <32147114.z48B4pQc9d@tjmaciei-mobl1> <10213508.VWnTgIxFMp@tjmaciei-mobl1> <ac891deb-fd2c-4eb1-a401-c8b470ec4320@isocpp.org>
 <2405194.zksCxUNAzK@tjmaciei-mobl1>
Reply-To: std-proposals@isocpp.org
NNTP-Posting-Host: blaine.gmane.org
Mime-Version: 1.0
Content-Type: multipart/mixed; 
	boundary="----=_Part_12645_578139516.1511417963840"
X-Trace: blaine.gmane.org 1511417965 23771 195.159.176.226 (23 Nov 2017 06:19:25 GMT)
X-Complaints-To: usenet@blaine.gmane.org
NNTP-Posting-Date: Thu, 23 Nov 2017 06:19:25 +0000 (UTC)
To: ISO C++ Standard - Future Proposals <std-proposals@isocpp.org>
Original-X-From: std-proposals+bncBDLZJYWNDQIO3UGZ2ACRUBDKOPLK6@isocpp.org Thu Nov 23 07:19:20 2017
Return-path: <std-proposals+bncBDLZJYWNDQIO3UGZ2ACRUBDKOPLK6@isocpp.org>
Envelope-to: gclcip-std-proposals@m.gmane.org
Original-Received: from mail-vk0-f72.google.com ([209.85.213.72])
	by blaine.gmane.org with esmtp (Exim 4.84_2)
	(envelope-from <std-proposals+bncBDLZJYWNDQIO3UGZ2ACRUBDKOPLK6@isocpp.org>)
	id 1eHkr0-0005mw-Uz
	for gclcip-std-proposals@m.gmane.org; Thu, 23 Nov 2017 07:19:19 +0100
Original-Received: by mail-vk0-f72.google.com with SMTP id o70sf10272510vkc.17
        for <gclcip-std-proposals@m.gmane.org>; Wed, 22 Nov 2017 22:19:26 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=isocpp-org.20150623.gappssmtp.com; s=20150623;
        h=date:from:to:message-id:in-reply-to:references:subject:mime-version
         :x-original-sender:reply-to:precedence:mailing-list:list-id
         :list-post:list-help:list-archive:list-subscribe:list-unsubscribe;
        bh=Rbfls9HPuqkoI/rm3ddz8mZk/TfKrQOIIWjkRJUiEDI=;
        b=wWmzuXVTgfC4RN/2PfOdovhpenZ+v5GaSVz5ORe55RCnDd7jVcTzPb5F8Dovcs8/Ij
         oYI00ZSoIiYRpKwot07x+QJZPiOImhsYUoI2zyplwGjXBkmYLXoetQne72uc14meHLa3
         bPpXVvRAIq2GxxTg5OsO5goSdZK/JPLqlsaD3Iu7dpBjX7jB0JleBw4KYudgFTmXoKam
         UVZrekEXFqv29Id0N5pNhuF8rBL7t/auRGRC7PLu8fPwaiDcbF461l3K4GcV2yIlI3KN
         rSK81m8VA6IxAM5ISrwbb0enwWM3SHSakiBVYP2w3nK3WzdPJvL84uWgFZc2XqSXpw4Y
         SiRw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20161025;
        h=date:from:to:message-id:in-reply-to:references:subject:mime-version
         :x-original-sender:reply-to:precedence:mailing-list:list-id
         :list-post:list-help:list-archive:list-subscribe:list-unsubscribe;
        bh=Rbfls9HPuqkoI/rm3ddz8mZk/TfKrQOIIWjkRJUiEDI=;
        b=Xx2C3nq4Dpd9JJydjtt2fGdZx3AFejciiAJdbRLKh5MffIWyshGIMX0GNDbTq2JKQA
         CWP8Bc6xeJ5XP7jpsxFucysEF9RYaoNMpmZAnjbe3xJlwgVGei8B46Sa6C63qg0VEZNg
         HMXqZ+Nxf8LIkmWn/dvvgbc9xZlPwEOwXdc55UHURGwMXHRW2ZXQIOMg0XXzfb+VpJu8
         sURHHApiksyX+Hl7uSCy8BwhC2wm8eVqNAb7S8bZBLK6oyZXdFl+5apjAty+IZWv+/DI
         CkiVg/2YP6tP5etifuFh6DGyB7mwfUV9FGPOY/56S0nUNv2gutLQ3su4nkkvXNPH4AFc
         Q+1g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20161025;
        h=x-gm-message-state:date:from:to:message-id:in-reply-to:references
         :subject:mime-version:x-original-sender:reply-to:precedence
         :mailing-list:list-id:x-spam-checked-in-group:list-post:list-help
         :list-archive:list-subscribe:list-unsubscribe;
        bh=Rbfls9HPuqkoI/rm3ddz8mZk/TfKrQOIIWjkRJUiEDI=;
        b=l35MOw0LaA25+cAJHsVmqGny6Frnq+8ux+P/i7UfKzTIVOvxj4q1uGFVSz5u5n/MGD
         kIL+khAdld5DAOxlJcU0TR4+sK6XIZyW+/Sdf4kQSzdue/omugAFz+PlA688XypA//eW
         R5wb/JnU54Jr/BbVaxyyuu0KZkJiMKPEcP9yypzPsGKoOIJ8x0W9s8kTutfJqZHQOc7s
         nmveJXyftz/o5ZoojX9YA9biPbIFSxOPEBmRLwU7behJQhZKC4n4G/NZUDWou1B+CaVe
         xfxLWQUmt+aXO+uS0CfXtSVjZ2127uGRr6b72aTpXADQGBsGwThQGuuq1gXIF+sNNRzQ
         Y4nA==
X-Gm-Message-State: AJaThX7NjPtHSvqBkbWC6/Y3JEfB4rEJwzfQZ2dVVx4HpS+G06l8Ku2U
	SUZkUOkf2SRU0VKkl5EzT0iHNw==
X-Google-Smtp-Source: AGs4zMZRjgWZh8OMykYlLU/NW/0ZCPebBT1VCD/2WucFto5slAHYGNNStBMG70w8yGYIXktIr5WPuQ==
X-Received: by 10.159.45.154 with SMTP id v26mr12142522uaj.48.1511417966123;
        Wed, 22 Nov 2017 22:19:26 -0800 (PST)
X-BeenThere: std-proposals@isocpp.org
Original-Received: by 10.31.168.147 with SMTP id r141ls1382904vke.8.gmail; Wed, 22 Nov
 2017 22:19:24 -0800 (PST)
X-Received: by 10.31.94.198 with SMTP id s189mr2098304vkb.9.1511417964361;
        Wed, 22 Nov 2017 22:19:24 -0800 (PST)
In-Reply-To: <2405194.zksCxUNAzK@tjmaciei-mobl1>
X-Original-Sender: arthur.j.odwyer@gmail.com
Precedence: list
Mailing-list: list std-proposals@isocpp.org; contact std-proposals+owners@isocpp.org
List-ID: <std-proposals.isocpp.org>
X-Google-Group-Id: 399137483710
List-Post: <https://groups.google.com/a/isocpp.org/group/std-proposals/post>, <mailto:std-proposals@isocpp.org>
List-Help: <https://support.google.com/a/isocpp.org/bin/topic.py?topic=25838>, <mailto:std-proposals+help@isocpp.org>
List-Archive: <https://groups.google.com/a/isocpp.org/group/std-proposals/>
List-Subscribe: <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>,
 <mailto:std-proposals+subscribe@isocpp.org>
List-Unsubscribe: <mailto:googlegroups-manage+399137483710+unsubscribe@googlegroups.com>,
 <https://groups.google.com/a/isocpp.org/group/std-proposals/subscribe>
Xref: news.gmane.org gmane.comp.lang.c++.isocpp.proposals:35469
Archived-At: <http://permalink.gmane.org/gmane.comp.lang.c++.isocpp.proposals/35469>

------=_Part_12645_578139516.1511417963840
Content-Type: multipart/alternative; 
	boundary="----=_Part_12646_1381776361.1511417963840"

------=_Part_12646_1381776361.1511417963840
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Tuesday, November 21, 2017 at 4:27:41 PM UTC-8, Thiago Macieira wrote:
>
> On ter=C3=A7a-feira, 21 de novembro de 2017 14:34:58 PST Arthur O'Dwyer w=
rote:=20
> >
> > Major point: std::seed_seq is irreparable, and also unnecessary. For=20
> each=20
> > problem that a naive user might think is solved by std::seed_seq, the=
=20
> > correct solution is found in Moritz Klammler's proposal P0205 "Allow=20
> > Seeding Random Number Engines with std::random_device"=20
> > <http://www.open-std.org/jtc1/sc22/wg21/docs/papers/2016/p0205r0.html>,=
=20
> > which (AFAIK) sadly was not discussed at Albuquerque because no champio=
n=20
> > was present.=20
>
> Indeed. That's also how I seed tthe Mersenne Twister using=20
> QRandomGenerator:=20
> skip std::seed_seq.=20
>
>     static void securelySeed(QRandomGenerator *rng)=20
>     {=20
>         // force reconstruction, just to be pedantic=20
>         new (rng) QRandomGenerator{System{}};=20
>
>         rng->type =3D MersenneTwister;=20
>         new (&rng->storage.engine()) RandomEngine(self()->sys);=20
>     }=20
>
> [RandomEngine is std::mersenne_twister_engine<quint32,=20
>         32,624,397,31,0x9908b0df,11,0xffffffff,=20
>         7,0x9d2c5680,15,0xefc60000,18,1812433253>]=20
>
> But if you can't find 2500 bytes to seed the twister but you have more=20
> than 4,=20
> what should you do?=20
>


One plausible option is to use the seed bytes you have, padded out with=20
1-bits; and then discard(10000). AFAIK, this is just as good as any other=
=20
method. Trying to deterministically "scramble up" the seed bytes will not=
=20
increase their entropy one bit (ha!).

Notice that "use the seed bytes you have, padded out with 0-bits" is LESS=
=20
SECURE than padding with 1-bits, because in the case that "the seed bytes=
=20
you have" are all zeros, then you've just seeded the Mersenne Twister with=
=20
19937 bits of zeros, which is its bad state. This is a quirk of the=20
Mersenne Twister. Other engines will inevitably have other quirks.=20
`std::seed_seq`, being a single class not templated on the engine, cannot=
=20
possibly know and avoid all the quirks of all possible engines. Its *entire=
=20
raison d'etre* is to try to deterministically "scramble up" some seed=20
bytes; which means that, IMHO, it is in a state of sin.

http://www.pcg-random.org/posts/cpp-seeding-surprises.html

For another example: I would be leery of code that claimed to seed a=20
"cryptographically secure" PRNG with nothing but the std::seed_seq=20
algorithm. The smarts for how to appopriately seed a PRNG engine (such as=
=20
the need to avoid all-bits-zero for the Mersenne Twister) *need* to be=20
programmed into the engine's own e.seed(q) method. And once the engine has=
=20
these smarts, it is pointless and stupid for q.generate() to do its *own*=
=20
"scrambling" on top of that.

=E2=80=93Arthur

P.S., minor point: It is possible, but awkward, to write a non-owning=20
"seed_seq_view" that models SeedSequence and does its own pointless=20
scrambling a la std::seed_seq, without any further cooperation from the=20
standard or the vendor. Here's my contribution on the subject.
https://github.com/Quuxplusone/from-scratch/blob/master/include/scratch/bit=
s/random/seed-seq-view.h

--=20
You received this message because you are subscribed to the Google Groups "=
ISO C++ Standard - Future Proposals" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to std-proposals+unsubscribe@isocpp.org.
To post to this group, send email to std-proposals@isocpp.org.
To view this discussion on the web visit https://groups.google.com/a/isocpp=
..org/d/msgid/std-proposals/ad3d1b43-884f-4f85-a365-ad6ed8158d9e%40isocpp.or=
g.

------=_Part_12646_1381776361.1511417963840
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">On Tuesday, November 21, 2017 at 4:27:41 PM UTC-8, Thiago =
Macieira wrote:<blockquote class=3D"gmail_quote" style=3D"margin: 0;margin-=
left: 0.8ex;border-left: 1px #ccc solid;padding-left: 1ex;">On ter=C3=A7a-f=
eira, 21 de novembro de 2017 14:34:58 PST Arthur O&#39;Dwyer wrote:
<br>&gt;<br>&gt; Major point: std::seed_seq is irreparable, and also unnece=
ssary. For each
<br>&gt; problem that a naive user might think is solved by std::seed_seq, =
the
<br>&gt; correct solution is found in Moritz Klammler&#39;s proposal P0205 =
&quot;Allow
<br>&gt; Seeding Random Number Engines with std::random_device&quot;
<br>&gt; &lt;<a href=3D"http://www.open-std.org/jtc1/sc22/wg21/docs/papers/=
2016/p0205r0.html" target=3D"_blank" rel=3D"nofollow" onmousedown=3D"this.h=
ref=3D&#39;http://www.google.com/url?q\x3dhttp%3A%2F%2Fwww.open-std.org%2Fj=
tc1%2Fsc22%2Fwg21%2Fdocs%2Fpapers%2F2016%2Fp0205r0.html\x26sa\x3dD\x26sntz\=
x3d1\x26usg\x3dAFQjCNFbGHhiBFuZ0nJ6FhA5A2E1avg0qw&#39;;return true;" onclic=
k=3D"this.href=3D&#39;http://www.google.com/url?q\x3dhttp%3A%2F%2Fwww.open-=
std.org%2Fjtc1%2Fsc22%2Fwg21%2Fdocs%2Fpapers%2F2016%2Fp0205r0.html\x26sa\x3=
dD\x26sntz\x3d1\x26usg\x3dAFQjCNFbGHhiBFuZ0nJ6FhA5A2E1avg0qw&#39;;return tr=
ue;">http://www.open-std.org/jtc1/<wbr>sc22/wg21/docs/papers/2016/<wbr>p020=
5r0.html</a>&gt;,
<br>&gt; which (AFAIK) sadly was not discussed at Albuquerque because no ch=
ampion
<br>&gt; was present.
<br>
<br>Indeed. That&#39;s also how I seed tthe Mersenne Twister using QRandomG=
enerator:=20
<br>skip std::seed_seq.
<br>
<br>=C2=A0 =C2=A0 static void securelySeed(QRandomGenerator *rng)
<br>=C2=A0 =C2=A0 {
<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 // force reconstruction, just to be pedanti=
c
<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 new (rng) QRandomGenerator{System{}};
<br>
<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 rng-&gt;type =3D MersenneTwister;
<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 new (&amp;rng-&gt;storage.engine()) RandomE=
ngine(self()-&gt;sys);
<br>=C2=A0 =C2=A0 }
<br>
<br>[RandomEngine is std::mersenne_twister_engine&lt;<wbr>quint32,
<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 32,624,397,31,0x9908b0df,11,<wbr>0xffffffff=
,
<br>=C2=A0 =C2=A0 =C2=A0 =C2=A0 7,0x9d2c5680,15,0xefc60000,18,<wbr>18124332=
53&gt;]
<br>
<br>But if you can&#39;t find 2500 bytes to seed the twister but you have m=
ore than 4,=20
<br>what should you do?
<br></blockquote><div><br></div><div><br></div><div>One plausible option is=
 to use the seed bytes you have, padded out with 1-bits; and then discard(1=
0000). AFAIK, this is just as good as any other method. Trying to determini=
stically &quot;scramble up&quot; the seed bytes will not increase their ent=
ropy one bit (ha!).</div><div><br></div><div>Notice that &quot;use the seed=
 bytes you have, padded out with 0-bits&quot; is LESS SECURE than padding w=
ith 1-bits, because in the case that &quot;the seed bytes you have&quot; ar=
e all zeros, then you&#39;ve just seeded the Mersenne Twister with 19937 bi=
ts of zeros, which is its bad state. This is a quirk of the Mersenne Twiste=
r. Other engines will inevitably have other quirks. `std::seed_seq`, being =
a single class not templated on the engine, cannot possibly know and avoid =
all the quirks of all possible engines. Its=C2=A0<i>entire raison d&#39;etr=
e</i>=C2=A0is to try to deterministically &quot;scramble up&quot; some seed=
 bytes; which means that, IMHO, it is in a state of sin.</div><div><br></di=
v><div><a href=3D"http://www.pcg-random.org/posts/cpp-seeding-surprises.htm=
l">http://www.pcg-random.org/posts/cpp-seeding-surprises.html</a><br></div>=
<div><br></div><div>For another example: I would be leery of code that clai=
med to seed a &quot;cryptographically secure&quot; PRNG with nothing but th=
e std::seed_seq algorithm. The smarts for how to appopriately seed a PRNG e=
ngine (such as the need to avoid all-bits-zero for the Mersenne Twister) <i=
>need</i> to be programmed into the engine&#39;s own <font face=3D"courier =
new, monospace">e.seed(q)</font> method. And once the engine has these smar=
ts, it is pointless and stupid for <font face=3D"courier new, monospace">q.=
generate()</font>=C2=A0to do its <i>own</i> &quot;scrambling&quot; on top o=
f that.</div><div><br></div><div>=E2=80=93Arthur</div><div><br></div><div><=
div>P.S., minor point: It is possible, but awkward, to write a non-owning &=
quot;seed_seq_view&quot; that models SeedSequence and does its own pointles=
s scrambling a la std::seed_seq, without any further cooperation from the s=
tandard or the vendor. Here&#39;s my contribution on the subject.</div><div=
><a href=3D"https://github.com/Quuxplusone/from-scratch/blob/master/include=
/scratch/bits/random/seed-seq-view.h">https://github.com/Quuxplusone/from-s=
cratch/blob/master/include/scratch/bits/random/seed-seq-view.h</a></div></d=
iv></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;ISO C++ Standard - Future Proposals&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:std-proposals+unsubscribe@isocpp.org">std-proposa=
ls+unsubscribe@isocpp.org</a>.<br />
To post to this group, send email to <a href=3D"mailto:std-proposals@isocpp=
..org">std-proposals@isocpp.org</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/a/isocpp.org/d/msgid/std-proposals/ad3d1b43-884f-4f85-a365-ad6ed8158d9e%=
40isocpp.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.=
com/a/isocpp.org/d/msgid/std-proposals/ad3d1b43-884f-4f85-a365-ad6ed8158d9e=
%40isocpp.org</a>.<br />

------=_Part_12646_1381776361.1511417963840--

------=_Part_12645_578139516.1511417963840--

.
