Live data from Hacker News

Hardware Touch, Stronger SSH

ubicloud.com

51–53 of 53 posts

Re: Hardware Touch, Stronger SSH

#51
post #28

Earlier quoted context omitted.

while you are right, security is generally not cheap. you can get that $5 china fido key, but are you sure it's you who owns it? I was recently looking for a security key, and eventually I did pay the yubico tax, because saving $20 by getting another one seemed unwise given the stakes.

>you can get that $5 china fido key, but are you sure it's you who owns it? Seems like a moot point because it'd be very difficult for a rogue fido key to exfiltrate data. I'd be far more concerned about random chinese IOT gadgets, which most people don't have a problem with.

Hmm yes but it's possible to compromise private key generation to only create a very small predictable subset of keys. In fact some smartcards from Infineon suffered from this as a bug. And thus they can be brute forces. It requires some serious crypto chops to determine if this is the case. Obviously it's not like the first 60 bits being zero or something. And the private key is made to not be extracted in this kind of device making it even harder.

Re: Hardware Touch, Stronger SSH

#52
post #31
post #28

Earlier quoted context omitted.

>you can get that $5 china fido key, but are you sure it's you who owns it? Seems like a moot point because it'd be very difficult for a rogue fido key to exfiltrate data. I'd be far more concerned about random chinese IOT gadgets, which most people don't have a problem with.

Couldn't they ship pre-compromised? Storing the RNG seed and private key at the factory.

It won't be as easy as that because you can generate a private key multiple times and notice it's the same.

However yes a very limited entropy in the private key is much harder to detect especially because on this kind of device you can't see the private key directly.

Re: Hardware Touch, Stronger SSH

#53
post #32

Earlier quoted context omitted.

You're paying for brand and the fact they make key exfiltration very hard. Getting the key out of rpi4 will be trivally easy if someone stoles it, not so much for hardware key. I am surprised that competition didn't kept them in check, we're using them for more than a decade and the price just keeps slowly creeping in.

Run-off-the-mill smart cards have had non-extractable keys for decades. They only cost cents in manufacturing.

In raw materials, yes, but a lot of people were involved in developing and then conducting security evaluations on the MCU on the card, as well as all the software that runs on top, and those people do not work for free.
Post reply on HN