7 ms·
In discussions like this the phrase "security by obscurity" gets used as an accusation. We all agree "security by obscurity" does not work. But that's not what
by davideous 10y ago
In discussions like this the phrase "security by obscurity" gets used as an accusation. We all agree "security by obscurity" does not work. But that's not what is happening here.
Wikipedia's definition: "the reliance on the secrecy of the design or implementation as the main method of providing security for a system or component of a system."
Youbico isn't saying that the security of the device is increased by keeping the source code secret.
They say they are increasing the security by things like this: disabling user-loading of new firmware (which could be a bad actor loading bad firmware), using hardware with built-in side-channel countermeasures, and disabling JTAG ports (which could be used for key extraction).
This isn't obscurity. These are some good engineering arguments. Engineering is always full of trade-offs.
- deleted 10y ago[deleted]
- sigmar 10y ago>They say they are increasing the security by things like this: disabling user-loading of new firmware (which could be a bad actor loading bad firmware), using hardware with built-in side-channel countermeasures, and disabling JTAG ports (which could be used for key extraction). Are all of those listed features only possible with secret code? And if yes, once someone unobscures the code or methods, they'll be able to defeat the security. Isn't that the exact definition of 'security through obscurity'?
- pritambaral 10y agoI think what Yubico meant is that they aren't closing code for the sake of closing code, but since it can't be loaded onto the devices anyway, there's no need for the code to remain open.
- sigmar 10y agoOh. Now I'm reading davideous' comment much differently. But the title of the blog post (ie "vs") makes it seem like they aren't making it open source so that the hardware is secure.
- davideous 10y agoYes, pritambaral described what I'm trying to point-out. In think the "vs" in the title is saying this: they had to choose between open source (that is functional meaning you can really use the code and re-flash the device) and the secure hardware. It was a trade off of one "vs" the other, and this is their reasoning behind that trade-off.
- sigmar 10y agoOpen source doesn't necessarily mean that you can put it on the device. I'm sure a lot of Yubico's critics would be happy with seeing the code even if it can't be flashed.
- davideous 10y agoYes, it would technically meet the Open Source Initiative's definition (https://opensource.org/osd https://opensource.org/osd), but if there was no way to re-flash the device, no way to verify the binary on the device, or possibly even no way build a binary (which may require proprietary tools under NDA from the chip manufacturer) -- I think a lot of critics would still be critics, but I could be wrong. If Yubico did this it would be very interesting to see the reaction.
- jevinskie 10y agoIt would allow a third party to discover a vulnerability similar to the one in the Neo just by just reading the code.
- mavhc 10y agoThe general issue is when all hardware has software in, in the end it has to be open source. Going even further: The distinction between hardware, firmware, and software is logically irrelevant in terms of trust.
- discreditable 10y ago> disabling user-loading of new firmware Am I understanding correctly that these devices can never have their firmware updated? That there is no update mechanism seems insane. They could prevent bad firmware updates by wiping keys on upgrade. The risk now is that some firmware version is discovered to have flaws, and that device is vulnerable forever.
- pfg 10y ago> The risk now is that some firmware version is discovered to have flaws, and that device is vulnerable forever. This happened last year and they offered free replacements for affected users[1]. [1]: https://www.yubico.com/2015/04/yubikey-neo-openpgp-security-bug/ https://www.yubico.com/2015/04/yubikey-neo-openpgp-security-...
- davideous 10y ago> They could prevent bad firmware updates by wiping keys on upgrade This does not close the attack vector of someone intercepting the device before you get it and surreptitiously installing firmware with a backdoor.
- discreditable 10y agoHow do they do that to begin with?
- jacobush 10y agoModify the hardware to look the same but with added features. Like a radio transmitter.
- e12e 10y agoThere's been various news on this, like (first Google search I came across): http://www.geek.com/news/nsas-top-hacking-unit-intercepts-mail-order-electronics-can-get-the-ungettable-1561691/ http://www.geek.com/news/nsas-top-hacking-unit-intercepts-ma...
- mpeg 10y ago
- colemickens 10y agoNone of which precludes the implementation from being open source. In fact, it just means that even if the software were open source, it would be near-meaningless since I can't verify the code running on the device and can't reflash it myself. "Youbico isn't saying that the security of the device is increased by keeping the source code secret." Yeah, they're not really saying anything other than trying to provide an excuse for why they won't release it. "You can't use it anyway" isn't much of a response (I actually find it rather patronizing and dismissive). Not to pile on, but regarding: "Engineering is always full of trade-offs."... what exactly is the supposed trade off here? (Maybe they're using licensed code that they can't redistrib?)
- na85 10y agoThere's a market disruption opportunity here. Carpe consumer base.
- schoen 10y agoPerhaps "carpe emptores"!
- davideous 10y agoI think if they released the source, but you weren't able to reflash the device (which is a design trade-off they chose to close some attack vendors), people would be up-in-arms and saying "it's not true open source because I can't re-flash or verify the device."
- colemickens 10y agoExcept that I was just able to make the distinction... If their response wasn't patronizing enough, now you're adding on by saying we're too stupid to acknowledge the difference? Nah.
- tadfisher 10y agoIf I'm reading the statement correctly, they are unable to release the source due to an NDA with their hardware provider, which is at least a reason other than "it's not software under the Free Software definition".
- zobzu 10y agoThis isnt about security. Its about its was open source before and user modifiable and it no longer is. You can force wipe on flash for example. They clearly changed stance to ensure users cannot play with the hardware and competitors cannot copy the code. Which is fine. But its always weird when the argument of security is used instead of being genuine. You can copy the freaking key by removing the plastic of the yubikey4. you dont need a jtag port. you just connect to the pins. And guess what. its no big deal. You can't do that remotely and its not a device for 007 spies.
- uola 10y ago"They clearly changed stance to ensure users cannot play with the hardware" As per the statement (and earlier statements) you can't change the firmware unless you have a yubikey neo developer edition, which was only sold during 2012 and 2013. The change here is that the yubikey 4 doesn't run open source code (for the pgp part) as a result of changing platforms. The best way to show that you support open source is to buy the YubiKey NEO instead of the YubiKey 4.
- deleted 10y ago[deleted]
- xaduha 10y ago> The best way to show that you support open source is to buy the YubiKey NEO instead of the YubiKey 4. YubiKey NEO isn't a unique product, it's basically a cardreader and a java smartcard all-on-one, but there are plenty of vendors for both, it will probably can be even cheaper in some circumstances/regions. If you support open source, then give https://github.com/philipWendland/IsoApplet https://github.com/philipWendland/IsoApplet a look instead. A separate cardreader also means that you can use several smartcards for various things.
- uola 10y agoIt's a unique product in the sense that it has nice form factor and holds additional functionality for more main stream uses. I have a number of these devices, including the external card reader, the usb key card reader and the integrated rubber usb key. Everyone can decide what they want of course, just don't be surprised when they discontinue the NEO. If you read between the lines of how it went from closed, to very open, to less open, to now not open at all. It seems like they tried open source but failed. They were probably looking for people to integrate it into some e-mail client, chat application or even bitcoin wallet. Now they've gone back to focus on their core customer and using a cheaper more integrated chip.
- Alupis 10y agoTo take an alternate approach... Could this be a sly attempt to close-up the source (and hardware) before they have a Tangibot[1] situation? That scenario played out poorly for MakerBot, and perhaps YubiCo learned the wrong lessons from the entire ordeal. [1] http://www.cnet.com/news/pulling-back-from-open-source-hardware-makerbot-angers-some-adherents/ http://www.cnet.com/news/pulling-back-from-open-source-hardw...
- bonzini 10y agoUnlikely. The MCU in a Yubikey is not something you can order from aliexpress.
- datenwolf 10y ago> In discussions like this the phrase "security by obscurity" gets used as an accusation. We all agree "security by obscurity" does not work. But that's not what is happening here. Well, sort of. In the linked article Jakob Ehrensvard (Yubico CTO) wrote: >> (…) One could say it actually works the other way. In fact, the attacker’s job becomes much easier as the code to attack is fully known and the attacker owns the hardware freely. (…) While the rest of the article makes good points, this particular sentence hints at "security through obscurity".
- rkangel 10y agoSecurity through obscurity is when obscurity is your only security measure. When used on top of an otherwise secure system, obscurity actually makes finding vulnerabilities harder. The principle with open source is that you can trade that obscurity away in favour of the "many eyes" on your code and the fact that it is then proven secure. That tradeoff is definitely worth it, but that doesn't mean that the obscurity doesn't help security.