Earlier quoted context omitted.
Both things can be true.
The knee-jerk hysterical reaction to any talk of hardware roots of trust on Hacker News is getting tiresome and I expect better given the reputation of the site. It actually reminds me of old slashdot.
OpenTitan Shipping in Production
31–39 of 39 posts
Re: OpenTitan Shipping in Production
#32Earlier quoted context omitted.
The knee-jerk hysterical reaction to any talk of hardware roots of trust on Hacker News is getting tiresome and I expect better given the reputation of the site. It actually reminds me of old slashdot.
The software running on such devices is usually proprietary and never installed by the user. That is user-hostile.
Re: OpenTitan Shipping in Production
#33Earlier quoted context omitted.
The software running on such devices is usually proprietary and never installed by the user. That is user-hostile.
What software?
https://en.wikipedia.org/wiki/Trusted_Platform_Module#Field_...
For ASIC-only devices, the keys are burned-in, which is user-hostile too.
Re: OpenTitan Shipping in Production
#34I'm not seeking to criticise this product, I think this is a great development. But, for almost all people this is shifting from one kind of "trust me bro" to .. another. We're not going to be able to formally prove the chip conforms to some (verilog?) model, has no backdoors, side channels, you-name-it. We're in the same place we were, with the same questions. Why do we trust this and the downstream developments? Be…
Re: OpenTitan Shipping in Production
#35I'm not seeking to criticise this product, I think this is a great development. But, for almost all people this is shifting from one kind of "trust me bro" to .. another. We're not going to be able to formally prove the chip conforms to some (verilog?) model, has no backdoors, side channels, you-name-it. We're in the same place we were, with the same questions. Why do we trust this and the downstream developments? Be…
Re: OpenTitan Shipping in Production
#36Earlier quoted context omitted.
What software?
The firmware implementing TPM functionality, which definitely exists in at least some cases: https://en.wikipedia.org/wiki/Trusted_Platform_Module#Field_... For ASIC-only devices, the keys are burned-in, which is user-hostile too.
Re: OpenTitan Shipping in Production
#37Earlier quoted context omitted.
... and usually deployed in a user-hostile manner.
Any evidence of this? Computer security was a complete disaster before hardware roots of trust became standard.
It is still a complete disaster. Nobody needs the password to your bootloader when it can access all your data through your web browser.
Re: OpenTitan Shipping in Production
#38Earlier quoted context omitted.
Any evidence of this? Computer security was a complete disaster before hardware roots of trust became standard.
> Computer security was a complete disaster It is still a complete disaster. Nobody needs the password to your bootloader when it can access all your data through your web browser.
Re: OpenTitan Shipping in Production
#39Earlier quoted context omitted.
The firmware implementing TPM functionality, which definitely exists in at least some cases: https://en.wikipedia.org/wiki/Trusted_Platform_Module#Field_... For ASIC-only devices, the keys are burned-in, which is user-hostile too.
Is the firmware in my NIC user-hostile?
https://www.blackduck.com/blog/cyrc-discovers-asus-tplink-wl...