14 ms·
Titan in depth: Security in plaintext
- sbarre 9y agoPardon my ignorance in hardware matters, but I would assume Google gets these manufactured via a third-party. What would be the process for verifying that the chip itself has not been compromised during manufacture? Is this a hardware + software verification combo, so a tainted chip would not be recognized as valid by the software - so you'd need to compromise both to bypass?
- kyrra 9y agoI'm not sure what Google does, but there are companies out there that help detect counterfeit hardware in bulk parts shipments. They will chose random samples from a batch and crack them open to compare with what they expect. EDIT: example company that does this: http://velocityelec.com/ http://velocityelec.com/
- kurthr 9y agoTypically, a digital chip such as this is designed with Verilog (or VHDL in europe) for RTL. Most hardware compilers then also provide test vectors (for registers and logic) and built in boundary scan through SPI. When contracting the chip your in-house design software then generates GDS (semiconductor mask design format) which you provide to the vendor. Even without obfuscation, it would be enormously difficult to reverse engineer enough of the design to pass the boundary scan test vectors. Certainly, after manufacture you can decap and check that the product matches the mask. There are various extra design and production steps I'd go through for crypto verification and test, but it would be difficult to fake a chip if they allow verification after SMT on the PCB. After that, physical access and fairly sophisticated methods could bypass it, but you're already trusting TehGoog... so NoSuchAgency shouldn't be your concern.
- sbarre 9y agoThanks so much! I had to google a few terms but this is a great explanation, and I learned something today.. I love HN for this. :)
- buildbot 9y agoUnfortunately this is still susceptible to attacks like this: http://jantsch.se/AxelJantsch/papers/2016/ChristianKrieg-ICCAD.pdf http://jantsch.se/AxelJantsch/papers/2016/ChristianKrieg-ICC... Which is focused on attacking an FPGA, however the general idea of injecting hard to detect hardware via the tools themselves is a real problem.
- ckastner 9y agoThere are supposedly attacks that cannot be detected by visual inspection (I realize that this was only part of your argument), eg: sharps.org/wp-content/uploads/BECKER-CHES.pdf
- egberts1 9y agoOh. This chip is a fail, security-wise.
- andbberger 9y agoWhy?
- rhencke 9y agoCan you explain your thoughts in more detail? What about it do you feel is a failure, regarding security?
- Simon_says 9y agoWhat does any of this matter against National Security Letters? There's no place safe in the US.
- Buge 9y agoTitan is not a protection against National Security Letters, it's a protection against hacking. NSA, China, and Russia have all successfully hacked Google or Google accounts in the past. National Security Letters can be challenged in court. You fight legal attacks with legal defenses. You fight technical attacks with technical defenses. Although swapping them does give rise to some interesting techniques. Legally challenging technical attacks can be tricky due to jurisdiction, but it would be cool if Google could at least try suing the countries that attacked them. Technical defenses against legal attacks can also sometimes work, by building systems where the company themselves don't have access, such as E2E crypto.
- pcunite 9y agoThe red circuit board/chip image in the article is not of the actual chip. May I see it? The caption reads, "Photograph of Titan up-close on a printed circuit board", which is unfortunately untrue: https://1.bp.blogspot.com/-027iovJ94yk/WZ8ZDw4MNvI/AAAAAAAAEUM/LHjr4KnsLjw-L5owy2RJinEC2VqdIbECACLcBGAs/s1600/titan-1.png https://1.bp.blogspot.com/-027iovJ94yk/WZ8ZDw4MNvI/AAAAAAAAE...
- bluegate010 9y agoWe've actually got Titan earring swag we'll hopefully start distributing at upcoming recruiting / customer events, so images may start cropping up in short order. Why earrings? See the Titan announce video[0]. [0] https://www.youtube.com/watch?v=kwnWfHq2EfQ&t=1882 https://www.youtube.com/watch?v=kwnWfHq2EfQ&t=1882
- nellydpa 9y agoHey there, I am one of the authors behind this blog. How about we will share our Titan earrings swag instead for your close examination? We fixed captions on the blog, thanks for pointing it out.
- bluegate010 9y agoHey HN, I'm one of the engineers on the team behind Titan, feel free to AMA.
- convery 9y agoWhat did you have for breakfast?
- bluegate010 9y agoSpicy raisin bars, an old family recipe. And a cucumber.
- puzzle 9y agoDoes LOAS use Titan, then? https://twitter.com/jbeda/status/715373975182807040 https://twitter.com/jbeda/status/715373975182807040 Will you convince Niels to publish a paper?
- nellydpa 9y agoGreat question. We are working on it. LOAS is about server or device credentials that only will be issued if Titan will pass the validation of bios firmware. re: Niels paper, out of my control.
- puzzle 9y agoWhen asked about releasing a paper a few months ago at Next, it didn't sound like a high priority, maybe because it wasn't too exciting or not too many people would be interested. I disagree, but perhaps, if enough people ask Niels or whoever else makes the call, something might happen.
- polygot 9y agoThis looks like a pretty cool project. How much research went into creating Titan? Why did Google decide to create a custom hardware-based solution (Titan) instead of using something off the shelf, like Intel's Secure Boot?
- pmlnr 9y agoNews like this make me sad. google is becoming a government agency-like customised fortress from the cold war, and general computing gets phased out, just like Cory Doctorow said.[^1] Technologically, it's fantastic, but I do not welcome the philosophy it's bringing. [^1]: https://techcrunch.com/2015/04/18/on-the-war-on-general-purpose-computing/ https://techcrunch.com/2015/04/18/on-the-war-on-general-purp...
- Buge 9y agoI agree with Doctorow that it is a problem if I the consumer am prevented from making my computer do what I want by secure boot. But Titan doesn't really have that problem. Google owns the computers, and Google can make the computers do what they want because they have the signing keys. If Titan-controlled devices were sold to consumers with no way to disable it, that would be a problem.
- bobbypage 9y agoI wonder how this type of security hardware compares to other clouds (AWS, Azure, etc...)? Do they have something comparable?
- nellydpa 9y agoAWS and Azure most likely (not publicly announced) are working on hardening their servers. Based on http://ca.reuters.com/article/technologyNews/idCAKCN1B22D6-OCATC?utm_source=34553&utm_medium=partner http://ca.reuters.com/article/technologyNews/idCAKCN1B22D6-O...: "Neither Amazon.com nor Microsoft - which hold 41 percent and 13 percent of cloud market share, respectively, according to Synergy Research Group - have said if they have similar features."
- danielvf 9y agoBeyond the secure boot, this is really cool "...Titan cryptographically associates the log messages with successive values of a secure monotonic counter maintained by Titan, and signs these associations with its private key. This binding of log messages with secure monotonic counter values ensures that audit logs cannot be altered or deleted without detection, even by insiders with root access to the relevant machine."
- colllectorof 9y agoIf you trust the software you booted (which seems to be the main feature), why would you need a hardware module to sign your logs? I.e. what additional attack scenarios does hardware-based log signing prevent?
- demosthenes111 9y agoThe best security is like an onion. Let's say something goes wrong/funky and you're concerned an outside actor may have somehow gained access to the "secure" system. Can you trust your logs?
- bluegate010 9y agoThe log signing prevents undetected tampering after-the-fact; the goal is to make it readily apparent when log messages are altered or deleted, even by parties with root access.
- ThomasTheToilet 9y ago> While there are no absolutes in computer security, we design, build and operate Google Cloud Platform (GCP) with the goal to protect customers' code and data. Cute.
- colllectorof 9y agoI've heard about this chip, but I still don't get what specific scenarios it's designed to prevent compared to "traditional" secure boot. The article lists a lot of things Titan does without going into what practical benefits all of those features offer compared to the current industry practices.
- bluegate010 9y agoA couple practical benefits of Titan is that we can use it in many different environments where traditional secure boot is not available. For example, we're using it in both servers and in our custom networking card. In addition, traditional secure boot doesn't give us a hardware root of trust, nor does it enable tamper-evident logging.