Having some physical security in a OSS-hacker-compliant form factor is really quite nice. This is not going to replace a proper HSM, and almost certainly is a less secure place to store your data than an iPhone; but it's a good start for those unwilling to give up on (the performance of) PCs. It's worth noting that QubesOS, which is supported by this system, protects against e.g. USB-based attacks by running a virtua…
Why is it potentially less secure than an iPhone? Attackers can't scan the RAM because of the enclosure, whereas they might do so on an iPhone, correct?
ORWL – The first open source, physically secure computer
61–70 of 195 posts
Re: ORWL – The first open source, physically secure computer
#62Re: ORWL – The first open source, physically secure computer
#63Earlier quoted context omitted.
FTA: This project is about having a standard, physically secure computer that anyone can use – as open as we can make it. All these concepts are important, and they mean that x86 and flawless out-of-the-box Windows support are not optional. There are reasons everyone is using x86, even in the security community and in governmental agencies around the world: compatibility, performance, and security. Make no mistake, s…
That's all fine and good but they should not advertise it as secure if it's not.
Re: ORWL – The first open source, physically secure computer
#64Earlier quoted context omitted.
It's criminally irresponsible to sell such a computer, because it will easily result in data loss and not all users are educated enough to understand the consequences of such a flawed "security" design. Of course, you can claim that it's ultimately the customers fault in this case, and I agree, but they should nevertheless expect some lawsuits. There is always a tradeoff between security and data integrity, something…
It's not illegal or irresponsible to sell a computer that deletes data when tampered with when "deletes data when tampered with" is _advertised as one of the primary features of the machine_.
Re: ORWL – The first open source, physically secure computer
#65Earlier quoted context omitted.
Quite a lot more than a few trillion.
You have to account for Moore's Law within the few trillions GP mentioned
Moore's Law doesn't really factor into it.
Re: ORWL – The first open source, physically secure computer
#66Earlier quoted context omitted.
https://libreboot.org/faq/#amd . ARM maybe?
ARM has TrustZone.
It's worth mentioning that there is at least one OSS implementation of a TEE software stack, OP-TEE, making this even less of an issue. Assuming your device/soc mfg doesn't lock you out.
http://www.linaro.org/blog/core-dump/op-tee-open-source-secu...
Re: ORWL – The first open source, physically secure computer
#67Earlier quoted context omitted.
Quite a lot more than a few trillion.
Isn't brute force a chance? Should it not be "see you in next minute to few years?"
Re: ORWL – The first open source, physically secure computer
#68Re: ORWL – The first open source, physically secure computer
#69Earlier quoted context omitted.
Uhh.. yes but enjoy brute forcing a 256 bit key. See you in a few trillion years.
NSA Engineer: Hey boss, this one's using a 256 bit key. NSA Manager: Connect it to the quantum computer that doesn't "exist". Five minutes later.. NSA Engineer: We now have access.