Live data from Hacker News

ORWL – The first open source, physically secure computer

crowdsupply.com

41–50 of 195 posts

Re: ORWL – The first open source, physically secure computer

#41

Earlier quoted context omitted.

how is it "criminally" irresponsible on a personal computer? I should be able to delete my own data whenever i want to, unless ordered by a court not to. Also OpenBSD has had the ability to wipe the system on failed password attempts for many years now.

It's criminally irresponsible to sell such a computer, because it will easily result in data loss and not all users are educated enough to understand the consequences of such a flawed "security" design. Of course, you can claim that it's ultimately the customers fault in this case, and I agree, but they should nevertheless expect some lawsuits. There is always a tradeoff between security and data integrity, something…

It's not illegal or irresponsible to sell a computer that deletes data when tampered with when "deletes data when tampered with" is _advertised as one of the primary features of the machine_.

Re: ORWL – The first open source, physically secure computer

#42

Earlier quoted context omitted.

how is it "criminally" irresponsible on a personal computer? I should be able to delete my own data whenever i want to, unless ordered by a court not to. Also OpenBSD has had the ability to wipe the system on failed password attempts for many years now.

It's criminally irresponsible to sell such a computer, because it will easily result in data loss and not all users are educated enough to understand the consequences of such a flawed "security" design. Of course, you can claim that it's ultimately the customers fault in this case, and I agree, but they should nevertheless expect some lawsuits. There is always a tradeoff between security and data integrity, something…

The same argument could be applied to nearly any product. Knowing how to use the product is the user's responsibility and helping educate users is the manufacturer's responsibility. If you don't have data back ups, regardless of the type of computer, then you're setting yourself up for disappointment.

Re: ORWL – The first open source, physically secure computer

#43
post #29

How do they deal with the intel management engine in all intel chips? https://libreboot.org/faq/

FTA: This project is about having a standard, physically secure computer that anyone can use – as open as we can make it. All these concepts are important, and they mean that x86 and flawless out-of-the-box Windows support are not optional. There are reasons everyone is using x86, even in the security community and in governmental agencies around the world: compatibility, performance, and security. Make no mistake, s…

That's all fine and good but they should not advertise it as secure if it's not.

Re: ORWL – The first open source, physically secure computer

#44

Isn't the phrase Evil Maid a bit off-key? I'm sure this must have been discussed at great length elsewhere. We could express the same idea without the power and gender relations implied.

Sure, but it's an industry trope now. The same way we use Alice, Bob, and Eve as everypersons when talking about communications.

Re: ORWL – The first open source, physically secure computer

#45

Isn't the phrase Evil Maid a bit off-key? I'm sure this must have been discussed at great length elsewhere. We could express the same idea without the power and gender relations implied.

Evil maid or the "cleaning man scenario" is a pretty standard term.

Also technically whilst it does originate from maiden it is mostly gender neutral today, just like busboy or a bodyman are.

Re: ORWL – The first open source, physically secure computer

#46
post #4

I scowled when I read about the Intel chip, and I stopped reading when they mentioned USB. Assuming for a moment that there's no hidden backdoor in the Intel chip (which seems exceedingly unlikely from all that I've read regarding IME, not to mention the un-auditable microcode), all this fancy hackery is still going to get pwned by BadUSB. Secure computing cannot and will not move forward until we have a way to mitig…

I had a very similar thought. Also hdmi can double as ethernet. DVI uses a serial bus to negotiate features if I'm not mistaken. Probably room for exploits over that port too.

Seems like using built in input and display and giving up some external ports would be the only reasonable strategy if you were being as serious about physical security as this wants to be.

Re: ORWL – The first open source, physically secure computer

#47

Earlier quoted context omitted.

Uhh.. yes but enjoy brute forcing a 256 bit key. See you in a few trillion years.

Quite a lot more than a few trillion.

Isn't brute force a chance? Should it not be "see you in next minute to few years?"

Re: ORWL – The first open source, physically secure computer

#48

Earlier quoted context omitted.

Uhh.. yes but enjoy brute forcing a 256 bit key. See you in a few trillion years.

Quite a lot more than a few trillion.

You have to account for Moore's Law within the few trillions GP mentioned

Re: ORWL – The first open source, physically secure computer

#49

It's an interesting concept, for sure – but could someone more knowledgeable than me explain whether this leaves the system vulnerable to the potential, alleged backdoors present in Intel's chips via the Intel Management Engine?

Our long term plan is to limit ME capabilities using the BIOS configuration. We just released the SOW of the 1st BIOS with Eltan on the WiKi. https://www.orwl.org/wiki/index.php?title=File%3ASowDESIGN-S... We are planning to investigate how to further limit ME capabilities with Eltan and we will update the SOW as we make progress. We also believe that the current secure micro controller implementation severely limit the ME capability through power management and the SSD key management.
Post reply on HN