Live data from Hacker News

Yubico: Secure Hardware vs. Open Source

yubico.com

91–100 of 114 posts

Re: Yubico: Secure Hardware vs. Open Source

#91

> we, as a product company The most important thing any security company needs to realize is that their primary product is their reputation, not the physical or digital goods that they produce. "We, as a product company" is totally the wrong attitude. There's really no question about it, every ounce of closed source software/hardware in a security offering is something the customer should be concerned about it. From…

> A company can build up a reputation in the security industry, produce world class hardware and software, and charge a sharp premium on it, because security is _so_ important and protects some of our most valuable assets.

Hmm. I think there's considerable limits on how true this is. I would argue Yubikey's current security is more than good enough for almost everyone.

As mentioned in your edit, there's not a lot Yubico can do about the hardware restrictions. Given these restrictions, a common way companies in this industry assure users of the security of their device is FIPS 140-2 certifications, which range from levels 1 to 4.

Level 4-certified devices are extremely expensive, and the market for them is tiny, which seems to indicate that there's a definite limit on the amount people and organisations are prepared to pay to ensure security.

Re: Yubico: Secure Hardware vs. Open Source

#92
post #46

Earlier quoted context omitted.

This isnt about security. Its about its was open source before and user modifiable and it no longer is. You can force wipe on flash for example. They clearly changed stance to ensure users cannot play with the hardware and competitors cannot copy the code. Which is fine. But its always weird when the argument of security is used instead of being genuine. You can copy the freaking key by removing the plastic of the yu…

> You can copy the freaking key by removing the plastic of the yubikey4 Any more information available? googling for "yubikey 4 takeapart" got me nowhere.

The plastic dissolves in acetone, this is a neo not a 4: http://www.hexview.com/~scl/neo/

Re: Yubico: Secure Hardware vs. Open Source

#93
post #82
post #78

Earlier quoted context omitted.

The problem there is that in usual case, the read-only access to software will not be provided directly by the hardware, but by the same software you are trying to verify. In theory, this could be solved by verifying whole memory of the device, but that still depend on you believing that the device does not have more memory than what it should have.

> the read-only access to software will not be provided directly by the hardware, but by the same software you are trying to verify. Why not?

Because in the usual case you want to do such verification through same interface as normal operation, both for usability reasons and to limit number of interfaces that cross the security boundary.

Re: Yubico: Secure Hardware vs. Open Source

#94
post #47

In discussions like this the phrase "security by obscurity" gets used as an accusation. We all agree "security by obscurity" does not work. But that's not what is happening here. Wikipedia's definition: "the reliance on the secrecy of the design or implementation as the main method of providing security for a system or component of a system." Youbico isn't saying that the security of the device is increased by keepin…

To take an alternate approach... Could this be a sly attempt to close-up the source (and hardware) before they have a Tangibot[1] situation? That scenario played out poorly for MakerBot, and perhaps YubiCo learned the wrong lessons from the entire ordeal. [1] http://www.cnet.com/news/pulling-back-from-open-source-hardw...

Unlikely. The MCU in a Yubikey is not something you can order from aliexpress.

Re: Yubico: Secure Hardware vs. Open Source

#97
post #12

You can get blank 'java' smart cards and load open source applets on them, you don't need Yubico. Personally I only tried IsoApplet, but openpgp applet should work too.

Previous/other Yubico products are flashable javacards.

You can buy a java smartcard for about $2-$5 without compromising on security.

Re: Yubico: Secure Hardware vs. Open Source

#98
post #96

Very long post. Apparently, very simple explanation: they want to use NXP hardware, and NXP requires NDAs, preventing them from meaningfully opening source code to the platform.

This is the only comment that has figured out the real reason for not releasing the code - they can't due to NDA.

Re: Yubico: Secure Hardware vs. Open Source

#99
post #22

I thought about this for awhile, and here are my thoughts about having the source code: With the older YubiKey NEO devices, the applet source was available and I could freely upload an applet. This was great for a few reasons. I could modify or upgrade the app (of course, doing so would cause me to lose existing keys, which makes sense from a security PoV). (I actually did this on my old YubiKey.) I could also, in pr…

Attackers will just use the JTAG/Debug port and be done with it. They probably didn't even give it a single thought whether there is a vulnerability to exploit in the opensourced firmware. The YubiKey NEO was always "unsecure" now with the YubiKey 4 it's only possibly "unsecure".

I think you may be reading the OP wrong. The YK NEO used a secure element chip, too.

Re: Yubico: Secure Hardware vs. Open Source

#100
post #75

Earlier quoted context omitted.

What would be the purpose of an NDA with the hardware provider? Surely not to hide it from GCHQ/NSA?! I imagine a company like Yubico has all of its employees on GCHQ/NSA lists and may even have cell tower simulators outside of its offices. The NDA makes this even more suspicious. Who's the hardware provider? Huawei?

NXP makes you sign an NDA to use their secure stuff. The purpose is anti-competitive, preventing NXP's competitors from learning how the devices work. These devices often have advanced hardware and firmware countermeasures. The secure modules are considered weapons technology if they're allowed to be updated after sale; the company is responsible for tracking each one, they're impossible to ship overseas, etc. It's n…

Trade secrets are not 'anti-competitive'.
Post reply on HN