7 ms·
How about a whitelist of hardware fingerprints, similar to what Microsoft does with Windows installations. Also, Google is known to have custom manufactured ha
by bmon 10y ago
How about a whitelist of hardware fingerprints, similar to what Microsoft does with Windows installations. Also, Google is known to have custom manufactured hardware, specifically with security in mind. I don't think the idea that Google is able to secure their own network against foreign devices is really that far-fetched.
- kuschku 10y agoNone of that would solve the issue. Google can only verify what hardware you're running by sending a packet via ethernet to your device. You control all software running on your device, and can send a spoofed result. If you were crazy, you could even just emulate Google's hardware entirely and proxy all requests to that emulated hardware. Nonetheless, while this guy certainly wouldn't be able to do it, many Google employees would.
- etler 10y agoCouldn't they do a chip and pin style hardware solution where a security chip generates a response using a unique secret algorithm?
- kuschku 10y agoThat would work — until someone decaps a few of these chips. They're already doing something similar, after all.
- etler 10y agoWouldn't you need to decap every individual chip you want to compromise?
- MertsA 10y agoBut that's really not the case here. Making secure computing elements like TPMs or HSMs, or Apple's Secure Enclave or the plethora of other devices out there is a solved problem. You can decap it and try to get that data out of it but at the very least with the current state of the art you can make this very unlikely to succeed and extremely expensive to even attempt. Handwaving away all of this as just a minor nuisance is silly. An attacker would have to find some unknown side channel or try to physically modify the TPM to get at the data, either approach means the attacker has significant resources, certainly well beyond the means of our hypothetical attacker. Heck, it's been speculated that even the NSA couldn't get data out of something like Apple's Secure Enclave without risking destroying it in an attempt.
- deleted 10y ago[deleted]