Live data from Hacker News

ORWL – The first open source, physically secure computer

crowdsupply.com

51–60 of 195 posts

Re: ORWL – The first open source, physically secure computer

#51

Isn't the phrase Evil Maid a bit off-key? I'm sure this must have been discussed at great length elsewhere. We could express the same idea without the power and gender relations implied.

It's the common name of the attack that people get. So it's useful whether PC types, who are a tiny minority of many audiences, like it or not. I'm not sure how "Evil Maid" label was derived. I do know from espionage reading that the most common form of the attack came from maids in hotels of business or government people passing through. Janitors and maintenance types, too, but they were in a trusted, protected building instead of a third party's. French intelligence is particularly notorious for using maids or other hotel employees. Calling it a (adjective-here) Maid attack given all the maids involved makes since for historical and current significance of that attack vector. As in, the label is also a reminder to watch your ass and never leave gear unattended in hotels. ;)

Re: ORWL – The first open source, physically secure computer

#53

Earlier quoted context omitted.

how is it "criminally" irresponsible on a personal computer? I should be able to delete my own data whenever i want to, unless ordered by a court not to. Also OpenBSD has had the ability to wipe the system on failed password attempts for many years now.

It's criminally irresponsible to sell such a computer, because it will easily result in data loss and not all users are educated enough to understand the consequences of such a flawed "security" design. Of course, you can claim that it's ultimately the customers fault in this case, and I agree, but they should nevertheless expect some lawsuits. There is always a tradeoff between security and data integrity, something…

People should learn what a computer is. Those who don't will get screwed anyway.

Re: ORWL – The first open source, physically secure computer

#54

Earlier quoted context omitted.

Quite a lot more than a few trillion.

You have to account for Moore's Law within the few trillions GP mentioned

https://www.reddit.com/r/theydidthemath/comments/1x50xl/time...

tl;dr if all the matter in the whole universe was a computer, it'd still be unlikely.

Re: ORWL – The first open source, physically secure computer

#55
post #43
post #29

Earlier quoted context omitted.

FTA: This project is about having a standard, physically secure computer that anyone can use – as open as we can make it. All these concepts are important, and they mean that x86 and flawless out-of-the-box Windows support are not optional. There are reasons everyone is using x86, even in the security community and in governmental agencies around the world: compatibility, performance, and security. Make no mistake, s…

That's all fine and good but they should not advertise it as secure if it's not.

It's secure, "trust us".

Re: ORWL – The first open source, physically secure computer

#57
post #4

I scowled when I read about the Intel chip, and I stopped reading when they mentioned USB. Assuming for a moment that there's no hidden backdoor in the Intel chip (which seems exceedingly unlikely from all that I've read regarding IME, not to mention the un-auditable microcode), all this fancy hackery is still going to get pwned by BadUSB. Secure computing cannot and will not move forward until we have a way to mitig…

You simply can't have a secure computer if untrustworthy chips are in the TCB. They did say open-source, physically-secure computer. They didn't say the whole thing was secure. The use-case is whatever security you usually have plus tamper-resistant case, drive encryption, better authentication, and whatever Intel's extensions bring to the table. Better than regular computer in terms of defending against many more attack vectors. Assuming design works.

Also, such a device can be combined with a secure, open computer to divide risk up among software and physical attacks.

Re: ORWL – The first open source, physically secure computer

#58
post #32

ORWL was designed specifically to prevent undetected tampering with any of its electrical components, including the entire motherboard and storage drive. When tampering is detected, ORWL immediately and irrevocably erases all your data, even if it is unplugged at the time. and... Upon any tampering, the secure microcontroller instantly erases the encryption key, causing all data on the SSD to be irrevocably lost. If…

Uhh.. yes but enjoy brute forcing a 256 bit key. See you in a few trillion years.

NSA Engineer: Hey boss, this one's using a 256 bit key.

NSA Manager: Connect it to the quantum computer that doesn't "exist".

Five minutes later..

NSA Engineer: We now have access.

Re: ORWL – The first open source, physically secure computer

#59
post #50

Where does the name come from? When pronouncing it I can't help but notice it's very close to "Orwell"

In their post on the Ubuntu blog [0] they say it is pronounced "or-well". Assumedly ironically.

[0] https://insights.ubuntu.com/2016/09/29/meet-orwl-the-first-o...

Re: ORWL – The first open source, physically secure computer

#60

Earlier quoted context omitted.

It's criminally irresponsible to sell such a computer, because it will easily result in data loss and not all users are educated enough to understand the consequences of such a flawed "security" design. Of course, you can claim that it's ultimately the customers fault in this case, and I agree, but they should nevertheless expect some lawsuits. There is always a tradeoff between security and data integrity, something…

The same argument could be applied to nearly any product. Knowing how to use the product is the user's responsibility and helping educate users is the manufacturer's responsibility. If you don't have data back ups, regardless of the type of computer, then you're setting yourself up for disappointment.

True, maybe I overreacted. What worries me is that is apparently supposed to be sold as a general computing device. Tamper-resistant hardware may be used in the military to protect implementations and keys stored in hardware that will eventually get stolen. For other types of data stored? Probably not so much. As I said, reasonable uses for this kind of device are limited.

For ordinary users, deleting everything immediately when someone tampers with it is a recipe for disaster. Sure, they can backup everything in encrypted form, but then the data is not really deleted when somebody tampers with the machine, isn't it?

Regarding the security, well, apart from software-based attacks, how about installing a tiny USB keylogger inside a USB cable that is already used by the user? Or in the keyboard itself? Or a camera that records your keystrokes?

That's what the would be doing in such a case.

Post reply on HN