Live data from Hacker News

Why is Google selling potentially compromised Chinese security keys?

zdnet.com

11–20 of 29 posts

Re: Why is Google selling potentially compromised Chinese security keys?

#11
There are zero genuine technical complaints here. Its just a long winded article saying "but China" (implying anything manufactured there could be compromised). That concern, legitimate or not, covers >99% of electronics, including the computer or smartphone these keys are intended to be used with.

Re: Why is Google selling potentially compromised Chinese security keys?

#12

Go read the U2F FIDO spec. I'll wait. How exactly do you expect anyone to backdoor these devices?

It would be difficult, but the one thing I've learned to trust in security is that there's no such thing as a system that can't be broken. For U2F, the first thing that comes to mind is timing channels, or perhaps building in a radio and letting anyone nearby use the key as if it were theirs.

The existence of a hidden radio should be trivial to confirm - at minimum it would require a battery and an antenna.

If I we're the paranoid type, I'd avoid bluetooth security keys all together. NFC should be fine for use with a mobile phone, and while there are attacks that let you read NFC from a few meters away, if you credibly think you have an adversary who can identify you in public, and has this type of specialized hardware, you're dealing with someone who would have a much easier time just throwing you in the back of a van to extract whatever they wanted out of you.

Re: Why is Google selling potentially compromised Chinese security keys?

#13
It's a good point, even if it is a shit article.

Exactly how does a Feitian key differ from a Google one? Where is the SoC produced? How secure is the enclave equivalent and that bit which produces the private key? What is the chain of trust?

I don't trust the UK or US governments, but why on earth would I trust China?

Re: Why is Google selling potentially compromised Chinese security keys?

#14

Go read the U2F FIDO spec. I'll wait. How exactly do you expect anyone to backdoor these devices?

I don't think the article is talking about some random third party diddling the devices to install a backdoor. I think it is talking about the manufacturer building in a backdoor.

I don't see anything in the U2F FIDO spec that can prevent that.

Re: Why is Google selling potentially compromised Chinese security keys?

#15

We live in an interesting time and place where China could declare war on the democratic countries in the next 5 years...let me explain. China is in a very bad situation where it has accumulated too much debt in its national and local governments, and corporations. Inflation is going through the roof - rent has increased 30% from 2017 in Beijing and other cities, and food costs are going up because of the tariffs. An…

High IQ post, I luuv it

Re: Why is Google selling potentially compromised Chinese security keys?

#16
post #5

While I freely admit that I use a lot of Google services, have an Android phone, and so on... I can't fathom why anyone would think it's a good idea to buy security hardware from an advertising company.

Because it is an extremely high-value target that has proven capable of defending itself from numerous sophisticated attacks, and it has a vested interest in keeping its users and customers secure as well.

It's under US jurisdiction, so it has failed at least one major attack by default.

Re: Why is Google selling potentially compromised Chinese security keys?

#17
The fact is google are very good as managing security of their supply chain and if you’re worried about China interfering with hardware then I’m wondering where you think your phones, laptops, tv, tablets, IoT fridges are made... they are full of parts from China, almost impossible to check everything inside your laptop - however a single hardware device provided by Google?

Re: Why is Google selling potentially compromised Chinese security keys?

#18

The fact is google are very good as managing security of their supply chain and if you’re worried about China interfering with hardware then I’m wondering where you think your phones, laptops, tv, tablets, IoT fridges are made... they are full of parts from China, almost impossible to check everything inside your laptop - however a single hardware device provided by Google?

They don't mean the Google Titan security key but rather the one that's offered to you when signing up to their advanced protection program.

People in the UK are sent directly to a chinese online store which means at that point Google has no control over anything anymore.

Re: Why is Google selling potentially compromised Chinese security keys?

#19

While I freely admit that I use a lot of Google services, have an Android phone, and so on... I can't fathom why anyone would think it's a good idea to buy security hardware from an advertising company.

Because they're paying top dollar to some of the brightest people in security right now? Because they're a high value target that uses their own products in their fleet? Because they've shown that they care about security and were willing to step up their game to achieve it? Because they routinely share their expertise in form of either open source contributions or scientific papers?

Re: Why is Google selling potentially compromised Chinese security keys?

#20
post #5

Earlier quoted context omitted.

Because it is an extremely high-value target that has proven capable of defending itself from numerous sophisticated attacks, and it has a vested interest in keeping its users and customers secure as well.

It's under US jurisdiction, so it has failed at least one major attack by default.

Is anyone actually taking this serious? As if all other countries are any better.

Uh, German data protection laws, yadda yadda - they didn't stop the police from raiding several activist non profit organizations a couple of months ago, with no repercussions.

The "US jurisdiction"-line is just tiresome and weak. Show me the country that guards user data that isn't part of 5 eyes and where attempts of the state to gain access to said data is actually penalized.

Post reply on HN