12 ms·
Why I don't like smartcards, HSMs, YubiKeys, etc.
- Spooky23 10y agoThe author is not thinking about why these things are built and marketed as they are. The use case for the smart card is different than a HSM with FIPS 140-2 level 3 or 4 validation. The whole point is to operate in a tested, known valid state while resisting tampering. The higher level devices are filled with epoxy and have other anti-tampering features. A smartcard is most often a form of MFA. It can be used as an HSM of sorts, but offers limited benefit for that purpose.
- hlandau 10y agoYes, I know. I want those anti-tamper features, and I want to be able to take advantage of them to secure cryptographic policies designed and coded by myself or other people in the open source community. And of course I would be free to audit that code before making use of it. And if you don't think a secure tamperproof general-purpose Turing-complete execution environment in a compact form factor with contactless induction-powered interface isn't an interesting opportunity for innovation, I really don't know what to say.
- aftbit 10y agoCould something like this be built using ARM's TrustZone features?
- nicolas314 10y agoNope, TrustZone is not tamperproof, cannot resist determined attackers who have access to the hardware. HSMs and smart cards are designed precisely to cover this use case.
- nehcsivart 10y agoAs is with many things, the business decisions that makes sense usually overwrites the technical decisions that makes sense.
- kevhito 10y agoThis is a somewhat older rant (at least 2015, I think). And the title is misleading. It is really "Why I wish there were a product similar to but different than smartcards, HSMs, YubiKeys, etc." Because there isn't much in there that argues why smartcards (or yubikeys, etc.) are not good at what they do. The author just wants a different thing, and doesn't understand why this fantasy product doesn't exist.
- gcb0 10y agoyou missed the point, which it easy because author is mostly rambling :) the irony is that smart cards and even SIM cards in your phone are already general secure computers. the problem is that only by spending a lot of money and signing your life away on a NDA you can have access to it. the result: inefficiency beyond belief.
- detaro 10y agoHow is a title "Why I don't like X" misleading if the article explains what properties of all existing examples of X the author doesn't like?
- reffaelwallen 10y agoDo you also not like CSS?
- asdffderty 10y agoThere's nothing wrong with that page, it's readable and it serves it purpose. Please don't be a snob.
- pzb 10y agoThe author brings up many reasonable points but seems to mix issues of HSMs & Smart Cards not providing a generic open hardware platform with possible security problems of a platform. There is no question that there would be value in having a hardware platform that has certain security features, but that alone doesn't meet the requirements of most users of HSMs and Smart cards. The primary use cases I've seen are allowing a third party to have assurance of protection of data stored in the device and assurance of the rules for accessing the data. In most cases this assurance comes from a combination of the hardware itself and the software/firmware running on the hardware. A hardware platform only solves half the problem that most purchasers of HSMs and smart cards are asking vendors to solve.
- jaas 10y ago"A hardware platform only solves half the problem that most purchasers of HSMs and smart cards are asking vendors to solve." A hardware platform alone solves less than half the problem for many HSM buyers, myself included. There's also software, then there's support. HSMs, at least the kind we use, are niche products because relatively few people have reasons to operate them (they're not cheap either). There aren't a lot of people who know how to use them well. We need to be able to get support on the phone 24/7/365 to deal with problems that come up because like most people who own HSMs, they are critical to the functioning of our systems. Just throwing this out there to remind people interested in open HSMs (a fine idea) that at least when it comes to most people buying HSMs today, there needs to be an organization backing the product with good support. Otherwise it's probably a non-starter for critical systems.
- hlandau 10y agoThese are valid concerns, but they're not good reasons not to provide general-purpose compute HSMs. If you want an external company to have certified the software, the policy which goes on a general-purpose HSM, that may be entirely sensible from a business perspective; I'm sure if general-purpose HSMs were a thing, with standard HSM platforms, such certified programs would be available on the market. Many would probably be made by the manufacturers of the HSMs themselves, providing a vertically integrated solution, support-wise. Fulfilling this market, with the need for the outsourcing of liability, etc. is not mutually exclusive with providing general-purpose HSMs.
- Cyph0n 10y agoThe issue of affordable HSM/TPM for general purpose use is something my research group is trying to solve. We have most of the theory down, but the implementation is a work in progress. The key point is trying to maintain full physical isolation from the CPU and OS, while also providing general low-level computing capabilities. Do you guys think something like this could be patented and/or commercialized?
- guelo 10y ago> patented I hope not. > commercialized I hope so.
- helloiamaperson 10y agoSince you're doing research in this area, have you taken a look at something like https://www.dyadicsec.com/ https://www.dyadicsec.com/ at all? I looked at the whitepaper a while ago, and it seemed to make sense, though I was way out of my depth.
- Cyph0n 10y agoNo, I have not actually. I will definitely check the whitepaper out. Thanks!
- csomar 10y agoI think Intel has done something similar to what you are looking for: http://www.intel.com/content/www/us/en/architecture-and-technology/advanced-encryption-standard--aes-/data-protection-aes-general-technology.html http://www.intel.com/content/www/us/en/architecture-and-tech...
- Cyph0n 10y agoNo, that's different. The crypto is done in hardware, yes, but keys and plaintext are still seen in software, and software is inherently untrusted. Our aim is to support use cases where you do not want software to handle anything. I think Intel's SGX is a better solution for hardware-supported software isolation, but it still isn't widespread and has a number of weaknesses.
- georgyo 10y agoHe mentions yubikey in the title, but then nowhere else. The Yubikey Neo seems to be pretty close to his target device. The Yubikey 4 removed the ability to write new apps. The stuff about the NDA I do find alarming. In order to write "secure" programs for the chip on the Yubikey, you must have an NDA with the manufacturer. In fact the open source pgpcard app for the Yubikey is different than what ships with the Yubikey because they can't open source the secure bits. Which is a bit upsetting. So uploading the open source version weakens your security. That said, having my keys there still gives me much higher degree of security then an encrypted file on my computer. Malware may be able to get my pin, but not my keys.
- subway 10y agoOnly the dev version of the Neo supported altering apps on the device. Later versions were locked -- causing Yubico to issue replacement devices when it was discovered their GPG applet contained a vulnerability a couple years ago.
- closeparen 10y agoWhen I dug into the smart card scene, it was clearly a world meant for enterprises that make deals on golf courses. The official specs, SDKs, etc. for the hardware is sold for many thousands under "call us" licensing and NDA from NXP. There's some working GPG applets but the open source PKI applets are all abandonware; you're meant to license one (Windows only, of course) from Gemalto, also a "call us" deal. I've seen some references to anti-side-channel techniques that are trade secret or patented or both. I think you can only get them in a Windows-based "solution" deployed by consultants who are authorized resellers of these companies. Yubikey has done an incredible thing in democratizing the technology as far as they have for smaller-scale, Linux and Mac-centric users. It's shitty, but don't blame Yubikey.
- deleted 10y ago[deleted]
- StavrosK 10y agoIsn't the Fidesmo card what he wants? You can write JavaCard applications for it and run them within the secure element, as far as I know.
- sigil 10y agoHas the author seen the SC4-HSM I wonder? https://sc4.us/hsm/ https://sc4.us/hsm/ Show HN thread: https://news.ycombinator.com/item?id=12053181 https://news.ycombinator.com/item?id=12053181
- wzdd 10y agoOdd -- JavaCard smartcards are available for under $5, have crypto co-processors, and certainly support general-purpose code. See for example my project for KeePass, http://code.lardcave.net/2016/08/06/1/ http://code.lardcave.net/2016/08/06/1/ . After programming, you can choose to lock down the card (which means you can only erase the card, not modify it). I'm using NXP chips and although I haven't investigated completely I would be highly surprised if it was not possible to get the tamper-resistant and cryptographic properties the author is after. There is an open-source toolchain for generating code for the card which works great from OS X or Linux. Contactless writers are available on eBay for like twenty bucks. And they will even work (via NFC) with Android phones. It's a great time to be playing with contactless general-purpose smartcards.
- kawsper 10y agoI even have a ring that runs JavaCard software on its JVM, they are sold for cheap, and I bought one just for fun and history, there is an eBay listing here: http://www.ebay.co.uk/itm/JAVA-RING-RARE-Sun-Microsystems-JAVA-ONE-Promo-/300495374337 http://www.ebay.co.uk/itm/JAVA-RING-RARE-Sun-Microsystems-JA...
- Gruselbauer 10y agoThat is the weirdest ebay listing I saw in a while. Also I want to have one super-badly now. Thank you :)
- pjmlp 10y agoI remember the JavaONE when they were given. Oh getting old!
- spullara 10y agoI think I still have one somewhere from that JavaOne.
- jaytaylor 10y agoWhat can you actually do with it?
- 10y ago
- gravypod 10y agoI'm quite a big fan of OPs work and I think that if they take some time with JavaScript they will change their "Let me be clear about this: JavaScript sucks. It’s not the worst, but it’s also not by any means good" opinion. Check out JavaScript the Good Parts. It's a great language hidden under a layer of horrible horrible design choices.
- konstmonst 10y agoWhat is the problem to take a 10$ stm32f discovery board and use it as TPM. There are different flash protections: 1) you can read/write flash via JTAG 2) you can only write flash, but not read the old one 3) you can't rewrite flash, neigher can you read it. You will still have to implement USB communication, but there is already a lib from STM for it. Some models also have generous flash (in MB ranges). You can use internal SRAM which is more than enough and use AES acceleration peripherial. One can attach sdcard and use SPI + DMA + AES periherial to shuffle data along if one needs alot of storage.
- bogomipz 10y agoI had to look up TPM, I didn't realize there was an open standard for crypto processors. Is it safe to say that most HSMs are TPMs?
- nicolas314 10y agoThey are quite different beasts. HSMs offer tamper protection through various physical means like wrapping all components in resin, or implementing self-destruction mechanisms. Smart cards protect their secrets against all kinds of side channel attacks trying to read keys off a thermal signature for example. TPMs in most cases are based on smart cards but can also be implemented in a TEE (Trusted Execution Environment). Security does not always mandate tamperproof hardware.
- bogomipz 10y agoThanks for the clarification.
- kosma 10y agoSend me a locked STM32F1 chip and I'll send you back the binary contained in it. Not kidding. The problem with general purpose MCUs is that they are trivial to break.
- konstmonst 10y ago
- bogomipz 10y agoThe OP states: "Smartcards and HSMs are essentially two “brands” for the same thing: a chip which guards access to the data stored within it, and will only allow that data to be accessed in certain ways or under certain conditions. HSMs are the “enterprise” label for such devices, whereas smartcards are essentially the same thing, only cheaper." Yubikey(mentioned in the title) is a TOTP card that works with the HSM on the far end though. They serve different purposes. You load the tokens into the HSM device. They aren't the same thing. What am I missing?
- brassic 10y agoAn HSM consists of some secure memory to store a secret and a program, and a processor to run the program to perform computations using the secret. A Yubikey consists of some secure memory to store a secret and a program, and a processor to run the program to perform computations using the secret. The programs are different but they are basically the same thing. The author wonders why there isn't a simple general purpose gadget you can load your own program on to. As long as the action of loading a program clears existing secrets, the device could be secure. Or to put it another way, consider a Raspberry Pi acting as a router and as a Raspberry Pi acting as a media streamer. They have completely different purposes, but they are the same thing.
- bogomipz 10y agoI see, thanks for the clarification. That makes sense.
- tjohns 10y agoA Yubikey can be run either in TOTP mode, in U2F mode, or as a generic smartcard. (Or a combination of the above.) It's configurable. I use a Yubikey that's configured both as a U2F token for Google, as well as a smartcard for PGP/SSH use. And their core, the construction of a Yubikey, smartcard, and HSM are very similar. The core idea is that you have physically secure memory guarded by a dedicated cryptoprocessor, so that your secrets never have to be exposed to the host OS when performing a signing operation.
- jmgrosen 10y agoWhat about the FST-01? It's what I use and it works pretty well in my experience. http://wiki.seeedstudio.com/wiki/FST-01 http://wiki.seeedstudio.com/wiki/FST-01
- rincebrain 10y agoFST-01 is an STM32F1-based board, which according to [1] can be dumped fairly cheaply. [1] - https://news.ycombinator.com/item?id=13031484 https://news.ycombinator.com/item?id=13031484
- danpalmer 10y agoI'd like to address the difference between a SmartCard and an HSM as I feel like the author doesn't acknowledge some of the practical differences. While at the core they are both "hardware security", i.e. a physical chip that implements security, an "HSM" as I have commonly seen the term used is a completely different thing in most other ways. An HSM is typically a 1-2U server, that is designed to provide high throughput of cryptographic operations. It is ultimately a collection of a few high performance servers networked together, with some custom ICs - not just a small chip. As a result, you pay up to tens of thousands of dollars for one, because it's a piece of critical infrastructure that is made to high tolerances. It's akin to buying hardware load balancers or firewalls appliances. In addition to this, the validation process of an HSM is long. An HSM company will likely have teams of hardware engineers, software engineers, and specialised cryptography teams. There are audits for things like FIPS compliance, as well as extensive pentesting by external companies. All of this is expensive, to create a device that will never be mass market.
- pzb 10y agoBoth Smart Cards and HSMs can (and frequently do) contain FIPS validated cryptographic modules and can be USB devices. What seems to set them apart is content capacity and speed. A "HSM" can usually store dozens, hundreds, or even tens of thousands of keys and can do numerous cryptographic operations per second. Most "smart cards" can only store a few keys and frequently 1-2 operations per second. Many HSMs also add advanced authentication capabilities, such as M-of-N access control and/or hardware authenticators (e.g. you need 3 of 5 smart cards to use the HSM). The other key feature usually found in HSMs but not smart cards is backup/cloning without exporting the key (in PKCS#11 terms). This means that the key can be moved between HSMs with all the protections in place. I've yet to see a smart card that does this.
- amluto 10y ago> The other key feature usually found in HSMs but not smart cards is backup/cloning without exporting the key (in PKCS#11 terms). This means that the key can be moved between HSMs with all the protections in place. I've yet to see a smart card that does this. How does this work? Can an attacker buy an identical HSM, back up the key, and restore it onto the new HSM?
- sofaofthedamned 10y agoHSMs are shit. In a previous role we used a major vendor's HSM to protect our private keys. VERY expensive kit, more expensive than the load balancers and servers combined. We needed to use Elliptic Curve keys for a particular customer - so it got even more expensive as we had to buy: 1. A license from the LB vendor to use the HSM 2. A licence from the HSM vendor to use EC with the LB. ... even though they trumpeted these announcements of how radically great they were together we found: 1. The integration didn't work, full stop. 2. The version of OpenSSL we had to use (supplied) was about 18 months out of date 3. The specially b0rked version of OpenSSL supplied didn't support EC via a HSM Even better - when Heartbleed came out I had a patch from RedHat on day 1. The load balancer? Nope - nothing on their website - I had to create a ticket which said 'we are aware of the issue', at which point the ticket was closed. I questioned this and was told they couldn't keep it open, I had to create a new ticket every few weeks to find out whether they'd actually deigned to assign a bug id to the issue. The HSM vendor just said nothing, zero, until a new version of the firmware was silently released 4 months later. The whole industry is shit. I'd rather have a farm of Yubikeys than one of those HSMs.
- nailer 10y agoWant to (please) name the vendor?
- sofaofthedamned 10y agoNope, they'll know who they are and i'm not dealing with these things anymore.
- akytt 10y agoWhy do you have your HSM where Heartbleed matters?
- mentat 10y agoThis exactly. You use a HSM so it doesn't matter if your server gets popped.
- nailer 10y agoSince zooming won't fix the line width, here's a quick fix - paste into the console: var article = document.querySelector('article'); article.style['max-width'] = '650px'; article.style['margin'] = '0 auto';
- akytt 10y agoThe statement that "all HSMs and smartcards are the same" shows limited understanding. High-end HSMs can take 1000s of hits per second, a smartcard only a few.
- guitarbill 10y agowhy would this distinction result in a new name? my consumer switch and an enterprise switch are both switches, because that's what they do. or e.g. all cars, it doesn't matter if it's a ferrari or a lada, it's still a car.
- kmad 10y agoHow does something like the U2F Zero[1] compare? As I understand it, the u2f zero acts as an HID device and not as a smartcard provider, but could one modify the firmware to do that? Isn't this basically an open source yubikey you can make yourself for < $25? 1. https://github.com/conorpp/u2f-zero https://github.com/conorpp/u2f-zero
- JimmaDaRustla 10y agoDoes this guy realize you can buy PCI HSM devices that fit what he describes?
- rhizome 10y agoPost first, UPDATE later.
- AgentME 10y agoIt's not exactly in small card form, but someone looking for a general-purpose programmable tamper-proof computer might be interested in the ORWL: https://www.crowdsupply.com/design-shift/orwl https://www.crowdsupply.com/design-shift/orwl
- dredmorbius 10y agoHSM: Hardware security module https://en.m.wikipedia.org/wiki/Hardware_security_module https://en.m.wikipedia.org/wiki/Hardware_security_module Please expand your acronyms.
- appleflaxen 10y agoThis is the key quote: The feature table also lists various supported applications, demonstrating the interest of the manufacturer in programming the device for specific applications, rather than providing a platform for others to do so. (Imagine if manufacturers of USB drives made USB drives for text files and USB drives for image files and USB drives for MP3 files and so on, and the idea of selling a USB block device was alien to these people. If you wanted to store a new kind of file on a USB drive, you had to convince the manufacturer to implement support for it.) The draw of the Nitrokey then is the possibility the manufacturer merely incidentally allows alternate firmware to be flashed, rather than the manufacturer explicitly capitalising on the premise of an HSM as a general-purpose platform. Great point, and completely lost on manufacturers.
- mtgx 10y agoSpeaking of which, whatever happened to Google's Project Vault? Did it die after Mudge quit Google? It looked so promising. https://www.youtube.com/watch?v=V6qrQzn8uBo https://www.youtube.com/watch?v=V6qrQzn8uBo
- lisper 10y agoThis site is down so I was not able to read the original article, but I would like to take this opportunity to draw HN's attention to my current project: https://sc4.us/hsm https://sc4.us/hsm It's a fully open USB HSM based on an STM32F405 SoC. Includes an HWRNG, 1MB Flash, and 196k of RAM. Currently runs TweetNaCl and also functions as a FIDO U2F token. Technical details are here: https://sc4.us/hsm/manual.html https://sc4.us/hsm/manual.html Currently out of stock but we will be shipping again in early January.
- saganus 10y agoI'm interested in buying a couple of these. Howver I'm wondering if there's a way I can also use it as a TOTP to replace my Google Authenticator app for several accounts? I don't really like having it in the phone because when I lose it I need to reset everything and it's a pain. Is it possible with SC4 to achieve this functionality?
- lisper 10y agoTOTP is tricky because that requires a real time clock, which the SC4-HSM does not have. That would require adding a battery and associated power management circuitry, which would considerably increase the cost. However, you could run a driver on the host machine that provided the time to the HSM, which would still securely store your secret key. But then you could only use it on a machine that had this driver installed. So yes, it's possible, but it's not straightforward.
- lisper 10y agoAlso... why do you want TOTP rather than U2F? U2F is better in every way (unless you don't have access to a USB port).
- pekk 10y agoMany more services implement TOTP and not U2F, so this would tend to be seen as a useful thing for end users even if the technology is unattractive.
- HNSucksAss 10y agoI remember the '90s, when smartcards were supposedly about to revolutionize our personal data storage. Imagine, your MasterCard, American Express, ATM, stored-value, medical card (and history!), passport, loyalty cards... ALL IN ONE! Here we are in the U.S. 20 years later, and we can't even get the credit-card portion right. We still have separate cards for everything, and somehow the card vendors in the U.S. are too stupid to implement chip-&-PIN, which the rest of the planet has understood for ages. So now our transactions take longer, and we're STILL SIGNING for our card transactions with not a PIN in sight. And given the results of the latest election, things aren't going to get better anytime soon.
- SEJeff 10y agoSo FWIW, I asked about how Redhat signs their packages some time ago (about 6-7 years ago!) and was introduced to Fedora's "Signing Server" service, which is entirely open source. The email in full is: Hi Jeff, good to hear from you. There's really two parts to our signing server; the first is the separation of signing to a separate machine with the associated client/server and ACL controls, and the second is the interface to the nCipher HSM. The first part we've not made open because it's quite specific to Red Hat internal build systems and our kerberos setup. The second part is mostly straightforward use of nCipher utilities but includes a patch to GNUpg which I was originally going to make public but came into difficulty because it requires headers from the nCipher developer kit, and linking to it, and it's under a very non-compatible license. Given the cost of nCipher HSM units we didn't think other projects would want that solution either. So I'd actually prefer to point you to the work that has been done on a signing server for Fedora, which is open. See http://fedoraproject.org/wiki/ReleaseEngineering/Projects/SigningServer The Fedora folks looked into various hardware solutions too which were cheaper and didn't have the proprietary API issues, I can't find a link to that at the moment but Jesse Keating should be able to give you more info. Hope that's a good starting point... If anyone is interested, the project is actually named Sigul and is located at: https://fedorahosted.org/sigul/ https://fedorahosted.org/sigul/
- dalai 10y agoA blog post by Mozilla on the topic of package signing with an HSM: https://blog.mozilla.org/security/2013/02/13/using-cryptostick-as-an-hsm/ https://blog.mozilla.org/security/2013/02/13/using-cryptosti...
- hlandau 10y agoI'm the author of the article. After musing on the comments here I wrote a followup about improv HSMs. These aren't tamperproof and as such are suitable for use in secure datacentres only. https://www.devever.net/~hl/improvhsm https://www.devever.net/~hl/improvhsm
- audunw 10y agoFor the microchip itself, I'm pretty sure this already exists. Try looking at nRF52. It has NFC, Bluetooth radio, and hardware RNG. I'm pretty sure it has the features he asks for (firmware can lock down and block reading/writing from debug port. but debug can always do a complete erase/reset of the chip) A future SKU will probably have USB as well. The only problem is it is probably too power hungry to be powered by the NFC radio waves itself. And that is probably true for anything with an powerful ARM microcontroller. Maybe it'd be best to use a microcontroller with ARM TrustZone as well though. That should help bring the security of the device up to a more acceptable level.
- suchabag 10y agoWould that answer OP's needs: https://www.ledgerwallet.com/products/9-ledger-blue https://www.ledgerwallet.com/products/9-ledger-blue ?
- matthiasb 10y agoI am curious to hear why the device you are looking for should be a compact and portable device. You listed it as your very first requirement so it must be a must-have.