Live data from Hacker News

ORWL – The first open source, physically secure computer

crowdsupply.com

91–100 of 195 posts

Re: ORWL – The first open source, physically secure computer

#91
post #4

I scowled when I read about the Intel chip, and I stopped reading when they mentioned USB. Assuming for a moment that there's no hidden backdoor in the Intel chip (which seems exceedingly unlikely from all that I've read regarding IME, not to mention the un-auditable microcode), all this fancy hackery is still going to get pwned by BadUSB. Secure computing cannot and will not move forward until we have a way to mitig…

They address this a bit. Their CPU supports device virtualization and the default OS install dedicates a VM to just the USB ports, and the USB data lines are electrically disconnected from the HCIs when the machine is in locked mode.

I'd be more concerned about the wifi and bluetooth chips' firmware.

Re: ORWL – The first open source, physically secure computer

#92

Isn't the phrase Evil Maid a bit off-key? I'm sure this must have been discussed at great length elsewhere. We could express the same idea without the power and gender relations implied.

HAHAHAHAHAHAHA

Why would you even think of this as an issue? I had to read your comment, then read the replies, then read your comment again, twice, in order to actually understand what you were saying because it made literally no sense to me that anyone would have a problem with this.

Why does it matter? There are plenty of words that used to mean something and now mean something completely different when in context.

Re: ORWL – The first open source, physically secure computer

#93
post #68

This appears to be a good solution to the wrong problem. Maybe if they team with someone working on secure computer software...

I thought that, too, but decided to give them credit for an open solution to a hard, neglected problem. Let's face it: we need parallel developments in each of these areas since nobody is going to do all of them. It's good so long as the pieces can be securely composed by an integrator later. Just like the old incremental MLS paper or Karger's smartcard project. A piece at a time, even if extra time or cost on individual pieces, increases odds high-security product will emerge in long-term when each parties' interest (or funding or management) is often short-term.

If they were serious, I'd say work with Genode team for FOSS or partner with Sirrix to port their TrustedDesktop system to it. Both are using models with low TCB's and trusted paths architecturally similar to B3/A1 systems. Turaya used by Sirrix is basically Perseus Framework with pre-built drivers, VPN, disk crypto, management software, etc. Batteries-included. Here's Perseus:

http://www.perseus-os.org/content/pages/Overview.htm

I think a port of TrustedDesktop to ORWL-like solution would be a nice start on secure desktops for businesses or individuals willing to pony up dough. Can use something like Genode once it gets mature enough with necessary components. I've moved on from separation kernel stuff to HW-centric security but combining a thing that works with one that might seems like a good default for now.

So, a Turaya-like product combined with ORWL. I'll add requirements of parsers auto-generated LANGSEC-style with any TCB code run through SAFEcode or Softbound+CETS at a minimum. Kernel on bottom is seL4 or Muen (SPARK). Drivers done statically in subset of C or SPARK amendable to thorough analysis. Would that strategy for rapidly getting a high-security product out the door address most of your expectations or exceed them?

Re: ORWL – The first open source, physically secure computer

#94
post #43
post #29

Earlier quoted context omitted.

FTA: This project is about having a standard, physically secure computer that anyone can use – as open as we can make it. All these concepts are important, and they mean that x86 and flawless out-of-the-box Windows support are not optional. There are reasons everyone is using x86, even in the security community and in governmental agencies around the world: compatibility, performance, and security. Make no mistake, s…

That's all fine and good but they should not advertise it as secure if it's not.

There's no such thing as "secure", and frankly complaining that anything that has better security than regular products shouldn't advertise as such is ridiculous.

How else is there any progress when the community's just pulling everyone down with this "it's no good if it isn't completely perfect" crap?

Re: ORWL – The first open source, physically secure computer

#95
post #79

Earlier quoted context omitted.

If you want to get away from that kind of thing, right now I think you're options are POWER8: https://www.raptorengineering.com/TALOS/prerelease.php AMD has something similar to the Intel Management Engine: https://libreboot.org/faq/#amd

If only I had ~8000 dollars to spend on a desktop I'd be waist-deep in porting Linux packages.

AFAIK IBM's spent a good amount of engineering effort on making linux stuff run on power.

Re: ORWL – The first open source, physically secure computer

#96
post #90

> The battery itself is projected to last about six months without being connected to power. It seems like a lot of the security of the device depends on active scanning (e.g. the LDS clamshell mesh, the IMU, the temp sensor, etc.), which stops working after 6 months. Is the vector of a malicious actor taking the device and waiting 6 months before breaking in considered not worth protecting against?

The webpage says it zeroes the key material when the battery runs low. So it'll fail "secure" in that case, presumably.

Ah, I missed that bit! Thanks :)

Re: ORWL – The first open source, physically secure computer

#97

Having some physical security in a OSS-hacker-compliant form factor is really quite nice. This is not going to replace a proper HSM, and almost certainly is a less secure place to store your data than an iPhone; but it's a good start for those unwilling to give up on (the performance of) PCs. It's worth noting that QubesOS, which is supported by this system, protects against e.g. USB-based attacks by running a virtua…

ORWL will go in stand-by if the user is further than 10meters away from the device, if moved when away, it will shut down. If the hardware is tampered with, or chilled, the SSD encryption key is deleted within milliseconds. iPhone or any other consumer product at this point have less or no physical protection. The physical level of protection is taken from the payment industry standard and applied to the consumer dev…

If you guys succeed, you should think about making phones.

Re: ORWL – The first open source, physically secure computer

#98
I strongly advise anyone to ask one or more security engineers to look at your use-case for anything where the actual security of your system is important.

Until then its best to not think of this as any more secure than an off-the shelf system, for your use-case.

This would require a thorough analysis of the system as implemented. For example, can my adversary intercept the original delivery and send an alternative that always works no matter what PIN is used? Can the adversary really not learn the PIN you've been sent? Does the adversary have zero day exploits against USB drivers for your platform? Can the adversary shoulder-surf your password and steal both the device and key? Is it really not possible to get info by smashing the box, desoldering the RAM and doing cold boot?

And so on - the last one may seem impossible to defend against, but if it matters to the use-case then it must be considered.

Edit to add: I expect most cases will have better luck with computer systems that are more ephemeral (buy second hand laptop or raspberry pi in person, destroy often), or more portable (a secured mobile kept in person and used only for the sensitive task).

Re: ORWL – The first open source, physically secure computer

#99

Earlier quoted context omitted.

Not SPARC?

Specifically, the OpenSPARC T2: http://www.oracle.com/technetwork/systems/opensparc/openspar... The ASIC implementation was nice: https://en.wikipedia.org/wiki/UltraSPARC_T2 On a 65nm node... very outdated one... it might get 8 threads in 8 cores at 1.6GHz each with hardware RNG, crypto accelerators, and hypervisor support. That's the kind of implementation that would be useless for an open-source, secure workstation…

Sadly the T1/T2 are ancient now. The non-open SPARC is up to T7, which is 20nm process, 256 threads on 32 cores.

Re: ORWL – The first open source, physically secure computer

#100
post #79

Earlier quoted context omitted.

If only I had ~8000 dollars to spend on a desktop I'd be waist-deep in porting Linux packages.

AFAIK IBM's spent a good amount of engineering effort on making linux stuff run on power.

Yes, in practice the only things that really need "porting" to POWER are low-level compilers, languages, runtimes, tooling, etc. that may have arch-specific code. Sometimes IBM does this (e.g. Google v8 + Node.js), sometimes not... yet? (e.g. rust).
Post reply on HN