Isn't the phrase Evil Maid a bit off-key? I'm sure this must have been discussed at great length elsewhere. We could express the same idea without the power and gender relations implied.
ORWL – The first open source, physically secure computer
51–60 of 195 posts
Re: ORWL – The first open source, physically secure computer
#52Re: ORWL – The first open source, physically secure computer
#53Earlier quoted context omitted.
how is it "criminally" irresponsible on a personal computer? I should be able to delete my own data whenever i want to, unless ordered by a court not to. Also OpenBSD has had the ability to wipe the system on failed password attempts for many years now.
It's criminally irresponsible to sell such a computer, because it will easily result in data loss and not all users are educated enough to understand the consequences of such a flawed "security" design. Of course, you can claim that it's ultimately the customers fault in this case, and I agree, but they should nevertheless expect some lawsuits. There is always a tradeoff between security and data integrity, something…
Re: ORWL – The first open source, physically secure computer
#54Earlier quoted context omitted.
Quite a lot more than a few trillion.
You have to account for Moore's Law within the few trillions GP mentioned
tl;dr if all the matter in the whole universe was a computer, it'd still be unlikely.
Re: ORWL – The first open source, physically secure computer
#55Earlier quoted context omitted.
FTA: This project is about having a standard, physically secure computer that anyone can use – as open as we can make it. All these concepts are important, and they mean that x86 and flawless out-of-the-box Windows support are not optional. There are reasons everyone is using x86, even in the security community and in governmental agencies around the world: compatibility, performance, and security. Make no mistake, s…
That's all fine and good but they should not advertise it as secure if it's not.
Re: ORWL – The first open source, physically secure computer
#56Where does the name come from? When pronouncing it I can't help but notice it's very close to "Orwell"
Re: ORWL – The first open source, physically secure computer
#57I scowled when I read about the Intel chip, and I stopped reading when they mentioned USB. Assuming for a moment that there's no hidden backdoor in the Intel chip (which seems exceedingly unlikely from all that I've read regarding IME, not to mention the un-auditable microcode), all this fancy hackery is still going to get pwned by BadUSB. Secure computing cannot and will not move forward until we have a way to mitig…
Also, such a device can be combined with a secure, open computer to divide risk up among software and physical attacks.
Re: ORWL – The first open source, physically secure computer
#58ORWL was designed specifically to prevent undetected tampering with any of its electrical components, including the entire motherboard and storage drive. When tampering is detected, ORWL immediately and irrevocably erases all your data, even if it is unplugged at the time. and... Upon any tampering, the secure microcontroller instantly erases the encryption key, causing all data on the SSD to be irrevocably lost. If…
Uhh.. yes but enjoy brute forcing a 256 bit key. See you in a few trillion years.
NSA Manager: Connect it to the quantum computer that doesn't "exist".
Five minutes later..
NSA Engineer: We now have access.
Re: ORWL – The first open source, physically secure computer
#59Where does the name come from? When pronouncing it I can't help but notice it's very close to "Orwell"
[0] https://insights.ubuntu.com/2016/09/29/meet-orwl-the-first-o...
Re: ORWL – The first open source, physically secure computer
#60Earlier quoted context omitted.
It's criminally irresponsible to sell such a computer, because it will easily result in data loss and not all users are educated enough to understand the consequences of such a flawed "security" design. Of course, you can claim that it's ultimately the customers fault in this case, and I agree, but they should nevertheless expect some lawsuits. There is always a tradeoff between security and data integrity, something…
The same argument could be applied to nearly any product. Knowing how to use the product is the user's responsibility and helping educate users is the manufacturer's responsibility. If you don't have data back ups, regardless of the type of computer, then you're setting yourself up for disappointment.
For ordinary users, deleting everything immediately when someone tampers with it is a recipe for disaster. Sure, they can backup everything in encrypted form, but then the data is not really deleted when somebody tampers with the machine, isn't it?
Regarding the security, well, apart from software-based attacks, how about installing a tiny USB keylogger inside a USB cable that is already used by the user? Or in the keyboard itself? Or a camera that records your keystrokes?
That's what the would be doing in such a case.