4 ms·
Valid points, though I would consider the requirements for writing really secure software quite high, so I do not think most open source projects could meet suc
by FieryTransition 10y ago
Valid points, though I would consider the requirements for writing really secure software quite high, so I do not think most open source projects could meet such standards. Maybe it could be compared to developing mission critical software, like Nasa for example. The amount of resources and rigor they use to get bugs out of the code is out of the scope of most free/donation software projects. There are probably a few open source projects which gets close to being considered secure though, mostly those which are very used and backed by big companies or foundations.
So we have Veracrypt as the 'good enough' option right now and ease of use, but you shouldn't happen to know any secure alternatives? You seem to know a bit about this.
- nickpsecurity 10y ago"though I would consider the requirements for writing really secure software quite high, so I do not think most open source projects could meet such standards. " Data from prior work indicates it ranges considerably from significantly harder to extremely hard. The LOCK system with an Orange Book A1 development process was highly secure and gave cost breakdown. A1 assurance acyivities added around 37% or so on top of regular, labor cost. Altran/Praxis's Correct-by-Construction that does highly-assured systems with mix of Z specs, Ada, SPARK, reviews, and testing costs 50% premium on top of normal development. Just using SPARK automatically knocks out whole classes of bugs. Galois did and open-sourced CRYPTOL so people can specify algorithms in easy DSL then generate C from it. Also parser and protocol generators. So, prior evidence shows it takes specialized skill and domain knowledge... at least two extra people unless one has both... but otherwise costs 30-50% more time. Like Cleanroom methodology, it partly achieved this by saving you time debugging and refactoring due to reduced bugs in general plus doing fixes earlier in lifecycle. Most OSS projects dont do this stuff just because they dont know it's necessary, don't care, or don't have staff for both demanded features and assurance activities. Interestingly, there's more high-assurance products in proprietary than FOSS software despite the huge labor advantage FOSS has. That there's little of even medium-assurance work in majority of both says even worse things about IT's priorities or apathy given medium assurance cost little to nothing. Microsoft is the one exception of big, software houses via SDL and MS Research's work. For FOSS, DJB, OpenBSD, and SQLite come to mind.
- FieryTransition 10y agoThanks for the info, did some searching based on your comment and I managed to find a report made by Altran/Praxis detailing the development process and technologies for a tokeneer ID station implementation they did for the NSA. Very interesting stuff. http://www.adacore.com/uploads/downloads/Tokeneer_Report.pdf http://www.adacore.com/uploads/downloads/Tokeneer_Report.pdf It really shows the amount of resources and knowledge required for actually having safe or secure systems.
- nickpsecurity 10y agoGlad you enjoyed it. Remember Praxis' method next time some fool says you can't engineer software. A few companies like them do. They're now just called Altran. The Tokeneer link was good since they published the source code on AdaCore website for people to learn from. However, the highest-security thing they did was the CA below under UK equivalent of EAL6/7. http://www.anthonyhall.org/c_by_c_secure_system.pdf http://www.anthonyhall.org/c_by_c_secure_system.pdf Example of new one for model-to-code-to-ASM verification https://www.umsec.umn.edu/sites/www.umsec.umn.edu/files/hardin-icfem09-proof.pdf https://www.umsec.umn.edu/sites/www.umsec.umn.edu/files/hard... LOCK project was pretty landmark in all that it accomplished with Sidewinder firewall & SELinux being in its ripple effects http://www.cyberdefenseagency.com/publications/LOCK-An_Historical_Perspective.pdf http://www.cyberdefenseagency.com/publications/LOCK-An_Histo... The B method is one of most successful in industry. You'll definitely see the engineering aspect in this one. http://www.methode-b.com/wp-content/uploads/sites/7/2012/08/ClearSy-Industrial_Use_of_B1.pdf http://www.methode-b.com/wp-content/uploads/sites/7/2012/08/... Cleanroom was early one in 1980's (start at p13) https://www.sei.cmu.edu/reports/96tr022.pdf https://www.sei.cmu.edu/reports/96tr022.pdf Note: Cleanroom had excellent results at low cost but disappeared for some reason. I saw someone recently combine Python with Cleanroom with good results. Cleanroom's compositional style means something like Haskell + QuickCheck could be great combo. If anyone tries it, let me know about the results.
- JoachimSchipper 10y agoReally secure software isn't easy to write. But we're not holding the VeraCrypt developers to a higher bar than the one they've set for themselves. For disk encryption, use whatever comes with your system. If you have no preference, Microsoft's BitLocker is excellent - it can incorporate hardware security features such as a TPM, self-encrypting (OPAL) SSD, it's somewhat easy to administer, etc.
- pjc50 10y agoBitlocker is excellent in a commercial environment, but the question some people are concerned about is how it might handle state-level threats. Although I suspect after Windows 10 techies would find that consideration moot, there are quite a lot of human rights people still using it for the usual reasons.
- JoachimSchipper 10y agoIf BitLocker seems riskier to you than VeraCrypt, might I suggest you recalibrate your threat model? See e.g. https://news.ycombinator.com/item?id=8193364 https://news.ycombinator.com/item?id=8193364.
- hannob 10y agoIf your threat model is that you assume your OS vendor is part of the attack then you can't use a proprietary OS. There's probably no free OS either that can give you the confidence level you'd want, because you probably would want to have reproducible builds, a trustworthy update process (preferably with some kind of transparency log), a wide array of exploit mitigations (aslr/pie/pic, grsec kernel, maybe CFI). There's currently no free OS offering all of those.
- keithpeter 10y agoJust out of interest: is there any OS that offers all of those? Libre/Open Source/Free or proprietary (latter with source access I assume)?
- GordonS 10y ago
- deleted 10y ago[deleted]
- Cthulhu_ 10y agoOpen source or not shouldn't be a constraint for spending resources and effort on code; it'd just mean development would be a bit slower and more tedious. But we're dealing with encryption here; if there's anything that should be done slowly, tediously and with an enormous amount of OCD, it's encryption software.