Live data from Hacker News

Viewing profile — cobratbq

cobratbq

HN member
Joined
Fri, Sep 13, 2013, 3:29 PM UTC
HN karma
32
Public activity
27 items

About cobratbq

openpgp4fpr:341C10EB7FD6648F30AFBC32D049DB6CD0B0C436

Recent public activity

  1. comment
    Comment #39854739

    The comment is meant to separate the hardware from the protections possible in software. TKey provides a unique secret per device, that transforms into a unique secret per (device …

  2. comment
    Comment #39853484

    You're right. I misremembered; read up on a lot of things in last months. Doesn't really matter, because we're discussing a protocol anyways.

  3. comment
    Comment #39852201

    Yeah, sorry, I realized that later. I forgot I posted the comment already.

  4. comment
    Comment #39843669

    > No protocol exists completely separate from its implementation. That's a fair point. I am well aware of this.

  5. comment
    Comment #39843655

    I'd love to respond to this, but your comment "... that explicitly provides no security guarantees when someone has physical access to it, .." is too abstract for me. I'll make a f…

  6. comment
    Comment #39843556

    I'm not sure if we're talking about the same things. I am not confident that I understand your comment well enough to confirm/reject, so I'm going to clarify for that reason. > I u…

  7. comment
    Comment #39840615

    > I don't know much about the TKey, but it looks like they have some kind of remote attestation protocol available? ( https://github.com/tillitis/tkey-verification/tree/main/cmd/ .…

  8. comment
    Comment #39840265

    That's fine. It is indeed possible to perform a check for genuine hardware. (I'm not sure it qualifies as "attestation".) It does not protect you from malicious program-binaries an…

  9. comment
    Comment #39840231

    > I think you're over-describing your use case, to the point that it's unclear what you're really saying. I read your "Introduction" section several times, and I don't understand i…

  10. comment
    Comment #39840118

    I will have a look. I checked quickly already, so if I understand the notation, I also leave out the last transaction. (2 messages vs 3 messages) Presumably because the authenticat…

  11. comment
    Comment #39835173

    You're right. I wanted to abstract away from specific hardware and express that in the requirements. I definitely failed at that. See other comments for specifics and details on th…

  12. comment
    Comment #39835064

    Yeah, thanks for reminding me. That is a nice suggestion.

  13. comment
    Comment #39835023

    You're right, mostly. I am not sure if TKey is officially considered an enclave. See more details here: https://news.ycombinator.com/item?id=39834820 >

  14. comment
    Comment #39835005

    I understand the "roll-your-own-crypto" comment. Note that I am taking the perspective of the protocol here, right? So, sure, vulnerabilities in the program are definitely a possib…

  15. comment
    Comment #39834962

    To check: did you realize that you plug this device in your USB port, then send a program to it, then start using the device with that program loaded? (This is at run-time, every t…

  16. comment
    Comment #39834933

    Thanks, much appreciated. I'm not claiming to know everything, far from it. However, given this simple but interesting device (see other comments for details) I prefer to keep thin…

  17. comment
    Comment #39834917

    I get that Verifpal is not perfect, doesn't do everything. I have considered switching. However, a significant part of proving the mechanism is having correct definitions for all o…

  18. comment
    Comment #39834896

    See also my other comments. The device is tillitis TKey. There is a True RNG (source of entropy) but not recommended, i.e. not cryptographically-secure. However, together with Blak…

  19. comment
    Comment #39834848

    Thanks for the input. See https://news.ycombinator.com/item?id=39834820 > for more details. The device is the TKey, so essentially only 32-byte secret value that is determined at p…

  20. comment
    Comment #39834827

    Thanks for the feedback. See also comment https://news.ycombinator.com/item?id=39834820 Note that this device is general purpose security device with no persistence. So the require…

  21. comment
    Comment #39834820

    The device I have in mind, primarily, is tillitis' TKey. The TKey does not have persistence, and offers a 32-byte secret value that is deterministically unpredictable (Blake2s) dep…

  22. comment
    Comment #39834762

    The device I primarily had in mind is tillitis' TKey. Essentially a general purpose (slow) processing unit. The secret is 32-bytes long and given no storage, that's essentially all…

  23. comment
    Comment #21659815

    1. Be thorough. Be sure you fully understand the issue, instead of jumping to conclusions. 2. Keep asking 'why'. Make sure you understand what the problem (or rather the requested …

  24. story
  25. comment
    Comment #19708632

    Updates on his situation (more recent on top): - 2019-04-18: Ola Bini's statement, from arbitrary detention, statement discussed in an article. [10] - 2019-04-16: Ola's parents are…