Live data from Hacker News

ORWL – The first open source, physically secure computer

crowdsupply.com

191–195 of 195 posts

Re: ORWL – The first open source, physically secure computer

#191
post #70

I was very recently looking into physically secure computing solutions, and the "industry standard" seems to be the SafeNet Network HSM, formerly Luna SA Network-Attached HSM (for example, it's what Amazon uses for their CloudHSM service: https://aws.amazon.com/cloudhsm/ ), which costs like $30,000. With that number in mind, the ORWL price of $700 is quite enticing!

Yes, HSMs are very expensive and after talking to a few people in this industry we got the impression, some of the ORWL features are not present in HSMs. Like the ability to Geo-lock the device using the key (mounted in the ceiling). Waling away with the device will render it useless as the keyFOB is missing.

Re: ORWL – The first open source, physically secure computer

#192

Did you think about manufacturing or designing your own ARM CPUs and releasing HDL for the CPU?

We thought long and hard about the type of platform we want to use for this project. While the x86 platform has many shortcomings, it also provides a big ecosystem of OS and SW, as well as support. The fact that we have two subsystems, secure micro controller being in charge of supplying (and denying) power from the x86 gives us a lot of leverage and protection.

Re: ORWL – The first open source, physically secure computer

#193

Earlier quoted context omitted.

what temperature (approximately) is "freezing" (or less likely, overheating)?

We currently have a Spec temperature of triggering a 'freezing event" at just above freezing Temperature 33-35F.

so if I live in a cold place and take it outside then it might erase my data? or what yellowapple said about losing heating, if I live in a really cold place; if pipes can go below 0 C due to cold temperature, why can I expect that ORWL won't?

Re: ORWL – The first open source, physically secure computer

#194
post #177

Earlier quoted context omitted.

what are you doing about offline attacks against the SSD crypto?

Offline this SSD is protected with "AES 256-bit Encryption". Simple Brute force attempts would need WAY too long to make any sense. Does this answer your question?

AES-256 ! Excellent.

Re: ORWL – The first open source, physically secure computer

#195

Earlier quoted context omitted.

Can a tamper event be triggered through software? It would really simplify the ability to create trap passwords which wipe the device.

Particularly by overheating the processor or other components like one might do if melting stuff off the outside with flame or acid application.

I was hoping for something a little more direct, deterministic, immediate, and non-damaging.
Post reply on HN