Live data from Hacker News

Google reveals its servers all contain custom security silicon

theregister.co.uk

61–70 of 129 posts

Re: Google reveals its servers all contain custom security silicon

#61
post #7

> Disks get the following treatment: > “We enable hardware encryption support in our hard drives and SSDs and meticulously track each drive through its lifecycle. Before a decommissioned encrypted storage device can physically leave our custody, it is cleaned using a multi-step process that includes two independent verifications. Devices that do not pass this wiping procedure are physically destroyed (e.g. shredded)…

'multi-step process' doesn't imply they are wiping more than once, only that their procedure consists of multiple steps (e.g. wipe + verification)

The article specifies two independent verifications.

Re: Google reveals its servers all contain custom security silicon

#62
post #21

This is another signal of an interesting development on the hardware front. What used to be decoupled, with some companies offering hardware, and different companies buying hardware, is now coupled and hidden within these mega-companies (Google, Amazon, FB). Google is big enough to develop a trusted hardware solution for internal use only, it has no financial need to sell it. Worse, due to competitiveness in the clou…

More ground is lost in the cold[1] civil war[2] for control of the General Purpose Computer. I hope that everyone choosing to centralize computing power likes the future they are creating. [1] https://www.youtube.com/watch?v=nT-TGvYOBpI#t=2824 (sec. 10 - http://geer.tinho.net/geer.blackhat.6viii14.txt ) [2] http://boingboing.net/2012/08/23/civilwar.html

What is different about centralized compute power compared with centralized energy production?

Re: Google reveals its servers all contain custom security silicon

#63
post #22
post #15

Earlier quoted context omitted.

> I understand how one may consider this a "closed ecosystem" from one perspective. However, from a customer point of view any startup or mom-and-pop can leverage these very complex and expensive world-class security developments, whereas in the past this access has been reserved to the very select few that could afford it. When the barrier to entry is lowered and access is commoditized, customer wins. I don't unders…

Pressure from governments to not supply consumers with hardware that is resistant to surveillance is one reason. AFAIK, the consumer systems that are most resistant to physical attack (and that lack spooky things like Intel's system management CPU) are game consoles. The hardening is a requirement for anti-piracy and anti-cheating, and in newer generations of consoles it's been quite successful. Recent iPhones are a…

> Recent iPhones are a distant second in terms of security architecture.

Source? Apple does some pretty sophisticated stuff around hardware security mechanisms and software correctness.

(I genuinely want a technical description of the mechanisms consoles use these days so I can read it -- not trying to start an argument...)

Re: Google reveals its servers all contain custom security silicon

#64

This is another signal of an interesting development on the hardware front. What used to be decoupled, with some companies offering hardware, and different companies buying hardware, is now coupled and hidden within these mega-companies (Google, Amazon, FB). Google is big enough to develop a trusted hardware solution for internal use only, it has no financial need to sell it. Worse, due to competitiveness in the clou…

> gave us the immense positive benefit of moving all capex to opex

Isn't it more correctly stated moving fixed costs to marginal costs? capex is mostly fixed, and opex is mostly variable, so you are not strictly incorrect.

Re: Google reveals its servers all contain custom security silicon

#65
post #60
post #40

Earlier quoted context omitted.

Exactly, and I think it's worth noting that they likely only apply this level of security because of state actors. Which then shows that they are trying to prevent eavesdropping by NSA & Co., they probably just realized too late how far advanced they were.

Which then shows that they are trying to prevent eavesdropping by NSA & Co. Why would the NSA eavesdrop on Google, they are in bed with them, aren't they?

Got links?

Re: Google reveals its servers all contain custom security silicon

#67
"Before a decommissioned encrypted storage device can physically leave our custody, it is cleaned using a multi-step process that includes two independent verifications. Devices that do not pass this wiping procedure are physically destroyed (e.g. shredded) on-premise"

Why not just shred all decommissioned disks? Someone must be buying them for enough money that Google created a multi-step process for cleaning and verifying them. Presumably Google keeps disks in commission until they're no longer economic in their own operation.

So, does anyone know about the operation that makes profitable use of disks that are no longer economic for Google?

Re: Google reveals its servers all contain custom security silicon

#68
post #59
post #40

Earlier quoted context omitted.

Exactly, and I think it's worth noting that they likely only apply this level of security because of state actors. Which then shows that they are trying to prevent eavesdropping by NSA & Co., they probably just realized too late how far advanced they were.

Eric Grosse from Google says as much here, ... Edit, it seems I have copied the wrong video, please us the link in the child comment

This talk is also discusses the adversaries: https://www.youtube.com/watch?v=0knR6vXba7g

Re: Google reveals its servers all contain custom security silicon

#69
post #63
post #22

Earlier quoted context omitted.

Pressure from governments to not supply consumers with hardware that is resistant to surveillance is one reason. AFAIK, the consumer systems that are most resistant to physical attack (and that lack spooky things like Intel's system management CPU) are game consoles. The hardening is a requirement for anti-piracy and anti-cheating, and in newer generations of consoles it's been quite successful. Recent iPhones are a…

> Recent iPhones are a distant second in terms of security architecture. Source? Apple does some pretty sophisticated stuff around hardware security mechanisms and software correctness. (I genuinely want a technical description of the mechanisms consoles use these days so I can read it -- not trying to start an argument...)

I don't have any details but without a exploit a game console will never run a single line of code that isn't signed. It makes the attack surface rather smaller than an iPhone.

Re: Google reveals its servers all contain custom security silicon

#70
post #65
post #60

Earlier quoted context omitted.

Which then shows that they are trying to prevent eavesdropping by NSA & Co. Why would the NSA eavesdrop on Google, they are in bed with them, aren't they?

Got links?

For me, the whole takeaway of the Snowden leaks was that the NSA can legally force Google (or anyone) to hand over basically anything, am I mistaken? Articles like [1] seems to underline they are indeed working together.

[1] http://www.huffingtonpost.com/2014/05/06/nsa-google_n_527343...

Post reply on HN