Why is Google selling potentially compromised Chinese security keys?
11–20 of 29 posts
Re: Why is Google selling potentially compromised Chinese security keys?
#12Go read the U2F FIDO spec. I'll wait. How exactly do you expect anyone to backdoor these devices?
It would be difficult, but the one thing I've learned to trust in security is that there's no such thing as a system that can't be broken. For U2F, the first thing that comes to mind is timing channels, or perhaps building in a radio and letting anyone nearby use the key as if it were theirs.
If I we're the paranoid type, I'd avoid bluetooth security keys all together. NFC should be fine for use with a mobile phone, and while there are attacks that let you read NFC from a few meters away, if you credibly think you have an adversary who can identify you in public, and has this type of specialized hardware, you're dealing with someone who would have a much easier time just throwing you in the back of a van to extract whatever they wanted out of you.
Re: Why is Google selling potentially compromised Chinese security keys?
#13Exactly how does a Feitian key differ from a Google one? Where is the SoC produced? How secure is the enclave equivalent and that bit which produces the private key? What is the chain of trust?
I don't trust the UK or US governments, but why on earth would I trust China?
Re: Why is Google selling potentially compromised Chinese security keys?
#14Go read the U2F FIDO spec. I'll wait. How exactly do you expect anyone to backdoor these devices?
I don't see anything in the U2F FIDO spec that can prevent that.
Re: Why is Google selling potentially compromised Chinese security keys?
#15We live in an interesting time and place where China could declare war on the democratic countries in the next 5 years...let me explain. China is in a very bad situation where it has accumulated too much debt in its national and local governments, and corporations. Inflation is going through the roof - rent has increased 30% from 2017 in Beijing and other cities, and food costs are going up because of the tariffs. An…
Re: Why is Google selling potentially compromised Chinese security keys?
#16While I freely admit that I use a lot of Google services, have an Android phone, and so on... I can't fathom why anyone would think it's a good idea to buy security hardware from an advertising company.
Because it is an extremely high-value target that has proven capable of defending itself from numerous sophisticated attacks, and it has a vested interest in keeping its users and customers secure as well.
Re: Why is Google selling potentially compromised Chinese security keys?
#17Re: Why is Google selling potentially compromised Chinese security keys?
#18The fact is google are very good as managing security of their supply chain and if you’re worried about China interfering with hardware then I’m wondering where you think your phones, laptops, tv, tablets, IoT fridges are made... they are full of parts from China, almost impossible to check everything inside your laptop - however a single hardware device provided by Google?
People in the UK are sent directly to a chinese online store which means at that point Google has no control over anything anymore.
Re: Why is Google selling potentially compromised Chinese security keys?
#19While I freely admit that I use a lot of Google services, have an Android phone, and so on... I can't fathom why anyone would think it's a good idea to buy security hardware from an advertising company.
Re: Why is Google selling potentially compromised Chinese security keys?
#20Earlier quoted context omitted.
Because it is an extremely high-value target that has proven capable of defending itself from numerous sophisticated attacks, and it has a vested interest in keeping its users and customers secure as well.
It's under US jurisdiction, so it has failed at least one major attack by default.
Uh, German data protection laws, yadda yadda - they didn't stop the police from raiding several activist non profit organizations a couple of months ago, with no repercussions.
The "US jurisdiction"-line is just tiresome and weak. Show me the country that guards user data that isn't part of 5 eyes and where attempts of the state to gain access to said data is actually penalized.