Live data from Hacker News

Security research on Private Cloud Compute

security.apple.com

11–20 of 124 posts

Re: Security research on Private Cloud Compute

#11
post #5

I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…

Concrete example of such backdoors: https://www.bloomberg.com/news/features/2018-10-04/the-big-h...

The system is protecting you against Apple employees, but not against law enforcement.

No matter how much layer of technology you put, at the end of the day, the US companies have to respect the law of the US.

The requests can be routed to specific investigation / debugging / beta nodes.

Just to turn-on a flag on specific users.

It's not like ultimate privacy, but at least it will prevent Apple engineers from snooping into private chatlogs.

(like some pervert at Gmail was stalking a little girl https://www.gawkerarchives.com/5637234/gcreep-google-enginee... , or Zuckerberg himself reading chatlogs https://www.vanityfair.com/news/2010/03/mark-zuckerberg-alle... )

Re: Security research on Private Cloud Compute

#12
post #11
post #5

I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…

Concrete example of such backdoors: https://www.bloomberg.com/news/features/2018-10-04/the-big-h... The system is protecting you against Apple employees, but not against law enforcement. No matter how much layer of technology you put, at the end of the day, the US companies have to respect the law of the US. The requests can be routed to specific investigation / debugging / beta nodes. Just to turn-on a flag on speci…

iirc, no real proof was ever provided for that bloomberg article (despite it also never being retracted). many looked for the chips and from everything I heard there was never a concrete situation where this was discovered.

Doesn't make the possible threat less real (see recent news in Lebanon), but that story in particular seems to have not stood up to closer inquiry.

Re: Security research on Private Cloud Compute

#14
post #11
post #5

I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…

Concrete example of such backdoors: https://www.bloomberg.com/news/features/2018-10-04/the-big-h... The system is protecting you against Apple employees, but not against law enforcement. No matter how much layer of technology you put, at the end of the day, the US companies have to respect the law of the US. The requests can be routed to specific investigation / debugging / beta nodes. Just to turn-on a flag on speci…

> Concrete example

This has not been corroborated and Bloomberg has not produced any supporting evidence.

Re: Security research on Private Cloud Compute

#15
post #6
post #5

I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…

This is an interesting idea. However what does open hardware mean? How can you prove that the design or architecture that was “opened” is actually what was built? What does the attestation even mean in this scenario?

This is my thought exactly. I really love the idea of open hardware, but I don’t see how it would protect against cover surveillance. What’s stopping a company/government/etc from adding surveillance to an open design? How would you determine that the hardware being used is identical to the open hardware design? You still ultimately have to trust that the organisations involved in manufacturing/assembling/installing/operating the hardware in question hasn’t done something nefarious. And that brings us back to square one.

Re: Security research on Private Cloud Compute

#16
post #5

I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…

[deleted]

Re: Security research on Private Cloud Compute

#17
I've been working on technology like this for the past six years.

The benefits of transparent systems are likely considerable. The combination of reproducible builds, remote attestation and transparency logging allows trivial detection of a range of supply chain attacks. It can allow users to retroactively audit the source code of remote running systems. Yes, there are attacks that the threat model doesn't protect against. That doesn't mean it isn't immensely useful.

Re: Security research on Private Cloud Compute

#18
post #11
post #5

I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…

Concrete example of such backdoors: https://www.bloomberg.com/news/features/2018-10-04/the-big-h... The system is protecting you against Apple employees, but not against law enforcement. No matter how much layer of technology you put, at the end of the day, the US companies have to respect the law of the US. The requests can be routed to specific investigation / debugging / beta nodes. Just to turn-on a flag on speci…

The Bloomberg SuperMicro implant in its various forms is an exceptionally poor example here: it's been widely criticized, never corroborated, and, Apple's Private Compute architecture has extensive mitigation against every type of purported attack in the various forms the SuperMicro story has taken. UEFI/BIOS backdoors, implanted chips affecting the BMC firmware, and malicious/tampered storage device firmware are all accounted for in the Private Compute trust model.

Re: Security research on Private Cloud Compute

#19
post #6

Earlier quoted context omitted.

This is an interesting idea. However what does open hardware mean? How can you prove that the design or architecture that was “opened” is actually what was built? What does the attestation even mean in this scenario?

This is my thought exactly. I really love the idea of open hardware, but I don’t see how it would protect against cover surveillance. What’s stopping a company/government/etc from adding surveillance to an open design? How would you determine that the hardware being used is identical to the open hardware design? You still ultimately have to trust that the organisations involved in manufacturing/assembling/installing/…

This website in particular tends to get very upset and is all too happy to point out irrelevant counter examples every time I point this out but the actual ground truth of the matter here is that you aren’t going to find yourself on a US intel targeting list by accident and unless you are doing something incredibly stupid you can use Apple / Google cloud services without a second thought.

Re: Security research on Private Cloud Compute

#20
post #11
post #5

I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…

Concrete example of such backdoors: https://www.bloomberg.com/news/features/2018-10-04/the-big-h... The system is protecting you against Apple employees, but not against law enforcement. No matter how much layer of technology you put, at the end of the day, the US companies have to respect the law of the US. The requests can be routed to specific investigation / debugging / beta nodes. Just to turn-on a flag on speci…

I can't believe Bloomberg still hasn't retracted that article. As other commenters have indicated - it has never in any way been corroborated.

https://www.bloomberg.com/news/articles/2018-10-04/the-big-h...

Post reply on HN