Live data from Hacker News

Yubico: Secure Hardware vs. Open Source

yubico.com

1–10 of 114 posts

Re: Yubico: Secure Hardware vs. Open Source

#3
post #2

This reads more like an excuse then a reason. Nothing of what he says is a reason that prevents them from being more open. All that he says is summarized in "it was too hard to think of a solution, so we didn't do it."

I'm not sure what distinction you're making? "Too hard" is often a valid reason for not doing something.

Re: Yubico: Secure Hardware vs. Open Source

#4
post #3
post #2

This reads more like an excuse then a reason. Nothing of what he says is a reason that prevents them from being more open. All that he says is summarized in "it was too hard to think of a solution, so we didn't do it."

I'm not sure what distinction you're making? "Too hard" is often a valid reason for not doing something.

Yes, unless you refuse to admit it and instead claim that security is improved by obscurity you chose to engage in.

Re: Yubico: Secure Hardware vs. Open Source

#5
After thinking through the initial "this is terrible" reaction, I actually don't mind what they're doing. Even though if there was an equivalent solution that was based on open source I'd definitely choose it over YK 4.

I also don't see anything that would really prevent them from just releasing the source they're using, even if we can't realistically do anything useful with it. The whole point of those systems is that it's secure via algorithms and hardware silos - releasing their sources shouldn't change anything.

But in practice it doesn't really matter that much - as long as they use standard interfaces and replace your key for free if someone finds a vulnerability, I'm (cautiously) fine with their new position. I think a big part of the issue is that they did something better before, but if they started with the current design, people wouldn't really complain about it that much.

Re: Yubico: Secure Hardware vs. Open Source

#6
A lot of handwaving which may throw those off who haven't pondered the design constraints of hardened hardware. But alas, it essentially boils down to the same reason that every productized solution goes closed: it's the expedient lazy option. Age-old antisecure solipsism.

Re: Yubico: Secure Hardware vs. Open Source

#7
post #4
post #3

Earlier quoted context omitted.

I'm not sure what distinction you're making? "Too hard" is often a valid reason for not doing something.

Yes, unless you refuse to admit it and instead claim that security is improved by obscurity you chose to engage in.

But this isn't completely security by obscurity, it's security granted by hardware that is built for secure purposes for which it is difficult to provide a software platform.

Re: Yubico: Secure Hardware vs. Open Source

#8
post #2

This reads more like an excuse then a reason. Nothing of what he says is a reason that prevents them from being more open. All that he says is summarized in "it was too hard to think of a solution, so we didn't do it."

That's a very disingenuous summary. It seems impossible to make the device open due to the NDAs. Can you explain how they would get around these?

With regards to the applet manager, that seems to be an issue with customer friction less so than being too hard. While "crypto nerds" would be fine, business applications could be affected.

Re: Yubico: Secure Hardware vs. Open Source

#9
> we, as a product company

The most important thing any security company needs to realize is that their primary product is their reputation, not the physical or digital goods that they produce. "We, as a product company" is totally the wrong attitude. There's really no question about it, every ounce of closed source software/hardware in a security offering is something the customer should be concerned about it.

From a product perspective it totally makes sense to be worried about open sourcing the entire design. "Our competition will make clones!" And that may be true of every other kind of product. But would you buy a cheap knockoff Yubikey? I certainly wouldn't. Again, reputation is the key here. That's what a security company sells to their customers. Confidence that when they buy from company X they know that company X has put the best engineers to the task and crafted a device that will protect their valuable digital information.

A company can build up a reputation in the security industry, produce world class hardware and software, and charge a sharp premium on it, because security is _so_ important and protects some of our most valuable assets. That premium is completely derived from the trust that they've garnered. It's insane for Yubico to squander theirs under some false sense of IP security.

EDIT: And all that said, I totally understand where they're coming from on some of their points. They have to depend on chip manufacturers, and chip manufacturers are just the absolute worst when it comes to open source and security. Sometimes there are hard constraints and compromises have to be made. Most of cryptography is a trade-off. So don't take my comment to mean that designs absolutely have to be 100% open source. That's infeasible most of the time for hardware. But Yubico should be striving for it and pressuring the market.

Re: Yubico: Secure Hardware vs. Open Source

#10
It's a shame to see that they used the goodwill of security-conscious cryptonerds to gain a foothold on the market only to, effectively, say "We're now targeting enterprise and government who can afford to pay for third party contracting security auditors. You can't, so just take our word that it's secure."

Other companies have managed secret distribution for secure devices just fine - randomise the card manager key and bundle a tamper proof packet containing the key along with the product. Provide instructions on how to verify the integrity of the packet, and confirm a digitally signed affirmation of the key against Yubico's public key online.

That's more than RSA offers for SecurID seed verification and more than my business bank offers for two factor device PIN integrity checking.

I'm not sure who they use for their Secure Element (NXP?) but it also sounds like Yubico has gone along with their request (and NDA) to keep implementation details secret. We've seen a similar situation in SE implementations in mobile phones (for contactless payment, primarily).

Again, enterprise customers don't care (mid-sized one have insurance that will cover loss if their Common Criteria EAL 5+ vendor's hardware is compromised, big enterprise can pay for auditing). Governments don't care (they'll pay for auditing or negotiate it in any significantly high volume contract).

End users and the tech community are the only groups who'll really lose out here.

Post reply on HN