6 ms·
Yubico announces tiny, cheap YubiHSM 2
- nikolay 9y ago$650 is cheap?
- alwillis 9y agoFor a security product for enterprise data centers, this is cheap.
- nikolay 9y agoI'm talking about absolute price, not relative to competitors. What's so complicated about this device to justify the cost?
- kalleboo 9y agoHigh development costs (security experts don't come cheap) spread over a small amount of sold devices?
- alexchamberlain 9y agoIt may be priced in value, rather than cost.
- jamespo 9y agoWhy should yubi price it any cheaper? It will never compete on cost with storing your private keys insecurely.
- tiernano 9y agoYup. Hsm pcie cards are around $5k, maybe more. The pizza box versions are upwards of 10k... that’s the last price I seen.
- convivialdingo 9y agoWell, certainly the number of keys you can manage is the downside here. This HSM has limited key storage capabilities to a hundred or so security objects. The "pizza box vendors" stores hundreds to thousands of keys. We typically employ key wrapping to reduce HSM key storage requirements, but only in certain situations.
- deleted 9y ago[deleted]
- confounded 9y agoWhat's the advantage of this over the ~$100 open source NitroKey HSM? https://www.nitrokey.com/files/doc/Nitrokey_HSM_English.pdf https://www.nitrokey.com/files/doc/Nitrokey_HSM_English.pdf
- CaliforniaKarl 9y agoFrom a quick check, I'd say the big differences (Yubikey HSM 2 over Nitrokey HSM) are: 4096-bit RSA, curve25519, higher capacity, and smaller form factor. EDIT: On further thought, the small form factor would be good for physical verification. I could get a good, high-quality server, plug this into the front USB port, and then use some sort of transparent epoxy to seal it in. Having it on the front of the server would make it easy to quickly confirm that it's in place (instead of hunting around the back of the server, and it would be small enough to seal into the USB port.
- baby 9y agoHow is 4k RSA a plus?
- vertex-four 9y agoSometimes you're stuck needing RSA for something. When you are, you want 4k RSA.
- pault 9y agoIs 2048 RSA broken? I think that's what ssh-keygen creates by default, right?
- j_s 9y ago> Is 2048 RSA broken? Today(-ish)? HN's anointed crypto expert says no. https://news.ycombinator.com/item?id=14317331 https://news.ycombinator.com/item?id=14317331 >tptacek(2017May): The point of modern RSA is that we use a modulus that can't be factored by any conceivable computer, with limits derived from the physics of computation and projected far out into the future. We aren't a supercomputer advance away from factoring 2048 bit moduli.
- ApplePrincess 9y agoWhat's the advantage of this over the ~$100 open source NitroKey HSM?
- deleted 9y ago[deleted]
- babar 9y agoHow much of a market is there for HSMs that are not FIPS 140-2 certified?
- CaliforniaKarl 9y agoIt looks like the original YubiHSM wasn't FIPS 140-2 certified either. https://www.yubico.com/support/knowledge-base/categories/articles/yubihsm1-security-certified-fips-140-similar/ https://www.yubico.com/support/knowledge-base/categories/art... Presumably, the original YubiHSM sold well enough to justify the R&D to make the YubiHSM 2, even one that's not FIPS 140-2!
- jnwatson 9y agoFIPS 140-2 is not all that it is cracked up to be these days. Older algorithms, embarrassing failures in certified products, and general distrust of NIST since the Dual EC PRNG catastrophe means that the only folks that should be using FIPS 140-2 are legally required to. (Disclosure: I once took a hardware product through the FIPS process)
- mey 9y agoFIPS 140-2 also defines requirements around tamper evident, tamper resistant and tamper proof. https://en.wikipedia.org/wiki/FIPS_140-2#Security_levels https://en.wikipedia.org/wiki/FIPS_140-2#Security_levels It's a subsection of the larger FIPS 140. Tamper resistant/Tamper evident (and not being able to simply pop the hsm in your pocket while walking by) are important considerations around physical security. These look great for home or SMB use, but wouldn't work in PCI-DSS or Classified environments.
- viraptor 9y agoEverybody who isn't working for us gov. It's a big market.
- convivialdingo 9y agoEverything in the mid to small market commercial space, basically. I've worked on several FIPS projects, and there's not a big demand for FIPS 140-2 unless the customer is handling government contracts and/or data. It's a good checkmark to have though.
- synicalx 9y agoNever really touched one of these HSMs before, what happens if you're using one in production and it dies?
- jlgaddis 9y agoYou retrieve the backup HSM and continue on.
- j_s 9y agohttps://news.ycombinator.com/item?id=12069784 https://news.ycombinator.com/item?id=12069784 >mdewinter(2016Jul): They [undisclosed HSM vendor] did, with undocumented commands, export the key from the device in an unencrypted format and loaded it into the other model so that we could continue our operation. (The first comment I ever favorited on HN.)
- synicalx 9y agoWow thanks for the link, that's a bit concerning. Not an expert on HSMs, but this does seem like a fairly serious design flaw?
- gumby 9y agoThink there's a chance we could get a Type C key someday that's as small as that (well, literally smaller, but I'm thinking something not much larger than the shell that will stick out of my machine about as much as that Type A one does.
- stedaniels 9y agoHow many servers have you got with Type C being primary accessible/secure ports? You realise this is the HSM and not the key right? Yubico has a Type C Yubikey called the 4C Nano https://www.yubico.com/product/yubikey-4-series/#yubikey-4c-nano https://www.yubico.com/product/yubikey-4-series/#yubikey-4c-... of you're just looking for keys. Though I can't see why you'd be so interested in a tiny HSM, could you tell me your use case?
- gumby 9y agoThanks I didn’t notice this was the HSM. I hadn’t seen the Nano when I got a machine and have an ugly leash right now.
- Xylakant 9y agoLike the 4C nano? https://www.yubico.com/product/yubikey-4-series/#yubikey-4c-nano https://www.yubico.com/product/yubikey-4-series/#yubikey-4c-...
- gumby 9y agoThanks, i hadn’t noticed they had released that.
- xchaotic 9y agoMore generally why is this not $3. Can we get a Kickstarter for this please?
- eropple 9y agoIt is not $3 because it provides more than $3 of value to the small audience that has a need for a HSM. If you--not "we"--want a Kickstarter for something like this, you should go try it. It's much, much more difficult than you think, even without FIPS compliance.
- gruturo 9y agoAn open source project, called SC-4, actually does that - although it won't offer the same level of security. https://sc4.us/hsm/ https://sc4.us/hsm/ It was also featured on HN: https://news.ycombinator.com/item?id=12053181 https://news.ycombinator.com/item?id=12053181
- benevol 9y agoHow useful are such measures when Intel has backdoored each and everyone of their CPUs with its "Intel Management Engine" [0] (and AMD has a similar mechanism)? If Intel/AMD have a backdoor into every PC and server, then so does the US gov't (NSA, CIA, FBI, etc.) and of course other uninvited hackers from even hostile countries. And how did Western society just accept all of this anti-democratic craziness? [0] https://libreboot.org/faq.html#intel https://libreboot.org/faq.html#intel
- baby 9y agoHSMs are not protections against the gocernment. Simple as that
- vortico 9y agoDoes the recent successes of disabling Intel ME essentially solve this? https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Disabling_the_Intel_Management_Engine https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Di... It's not easy, but for a security firm where the data on each computer is worth millions, it might be worth it.
- eeZah7Ux 9y agoCompletely useless.
- nickik 9y agoIf you make that assumption then you have already lost. However that is no reason not to use good security otherwise. > And how did Western society just accept all of this anti-democratic craziness? Because people buy it voluntary.
- hdhzy 9y agoI hope te EdDSA curve 25519 support in YubiHSM2 means we'll see the curve also in Yubikeys (e.g. OpenPGP applet). Currently Yubico's OpenPGP supports only RSA but there are already tokens supporting this modern crypto [0]. [0]: https://debconf17.debconf.org/talks/162/ https://debconf17.debconf.org/talks/162/
- j_s 9y ago> there are already tokens supporting this modern crypto I looked briefly but can anyone link to where to buy one? Thanks in advance (either way: "buy" link or no) for the info.
- hdhzy 9y agoErrr, I was referring to Gnuk [0] that claims support, but it's rather a DIY project [1] than something to be mass manufactured. Sorry to disappoint you but from my shallow research in this matter the hardware used has several flaws (e.g. no secure element). [0]: https://github.com/RaymiiOrg/gnuk/blob/master/README https://github.com/RaymiiOrg/gnuk/blob/master/README [1]: http://www.fsij.org/gnuk/howto-make-gnuk-usb-token-by-stm32-part-of-stm8s-discovery-kit.html http://www.fsij.org/gnuk/howto-make-gnuk-usb-token-by-stm32-...
- unwind 9y agoNo mention of the actual hardware (processor) they've used. I guess the bill of materials would be funny (although of course I realize that the value is in their expertise and software etc). The performance specs [1] say "HMAC-SHA-(1|256): ~4ms avg" which I guess is for 256 bits [2], compared to [3] which list a 6th gen Skylake 3.1 GHz doing it at 535 MB/s. [1]: https://www.yubico.com/products/yubihsm/ https://www.yubico.com/products/yubihsm/ [2]: But I have no idea, perhaps this is a stupid interpretation, in which case I'll turn around and blame them for being unclear. [3]: https://www.cryptopp.com/benchmarks.html https://www.cryptopp.com/benchmarks.html
- JohnHam 9y agoLike the 4C nano?
- JohnHam 9y agoLike the 4C nano? https://www.yubico.com/product/yubikey-4-series/#yubikey-4c-.. https://www.yubico.com/product/yubikey-4-series/#yubikey-4c-....
- xelxebar 9y agoI know very little about hardware security. What are some of the issues that HSMs address that make R&D so challenging?
- jarman 9y agoRegulations & compatibility.
- wav-part 9y agoHow can HSMs be considered MITM-proof if does not have dedicated input system (touchscreen/keyboard) ?
- consp 9y agoBecause it is a clever way of not considering that MITM but man in the machine (which is almost the same in my opinion in the case of possible damage but has more attack vectors). Most companies consider MITM an external compromise since the malicious actor is not on the machine itself or has no-longer access to the machine(s). Even most 'dedicated' systems do NOT have a direct link to the input terminals most of the times since they are simple usb keypads. Some smartcard readers for PC have pin-pads but this is rarely the case and they are way more expensive than a keyboard and a regular reader. The normal way is to process transaction data through the hsm, and onto the terminal after which the user has to see/check (on the terminal) if the data is correct. This is how the better (not best) Bank-transaction-verifiers work. A secure connection to the pinpad/terminal has and can be set up (either in advance, via a pre-known mechanism or ad-hoc), but there are some attack vectors there as well. HSMs are not "MITM proof", the system at-large has to be. Using a HSM does not give you MITM proofness, but makes it sure the old-fashioned 'steal the private key and act like nothing happened' won't happen. Stupid design choices or even simple "call them and ask for a new intermediary certificate" sometimes cause more harm. You CA Root/CSP keys are safe but you are still screwed. Unless you steal the usb drive of course. There are still other ways to do a mitm though. The main advantage is for small and medium businesses that they won't have to buy a hugely expensive ethernet/pcie HSMs from the known companies which are hugely overpriced (I have several on my desk and they range from 1-2K to 10K+, which are the cheap ones). It also helps with some legal compliance if YubiCo can get it FIPS 140-2 approved (which I doubt). Considering they made it small, I guess they need to provide some form of duplication/backup since people are going to lose them.
- wav-part 9y agoAn ideal HSM serve only one purpose: store secrets (privatekeys/passwords) and give specific access (sign/spend/login). > Most companies consider MITM an external compromise since the malicious actor is not on the machine itself or has no-longer access to the machine(s). Securing HSM+Laptop is impossible compared to HSM. If laptop is secure, why even need HSM ? > Even most 'dedicated' systems do NOT have a direct link to the input terminals most of the times since they are simple usb keypads. Some smartcard readers for PC have pin-pads but this is rarely the case and they are way more expensive than a keyboard and a regular reader. If usbkeypad is not connected to a network and not attacked by evil maid, HSM+usbkeypad is still secure. But laptop is complex system, always connected to internet and has loosly regulated physical access. > HSMs are not "MITM proof", the system at-large has to be. Again if whole system is secure why need HSM ? If user satisfy few conditions of using HSM, such as being rubberhose attack proof, the secrets MUST be secure irregardless of how insecure the larger system is.
- yosito 9y agoI bought a Yubico key once. The thing was so cheap that between the time I set it up and the first time I actually had to use it, it had disintegrated just from sitting in my pocket every day on my keychain. The plastic was brittle and fell apart piece by piece until eventually the electronics fell apart too.
- graton 9y agoI've had two on my keychain for years now. One of them maybe 8 years and the other one a little over 3 years. Zero problems with them so far. They still work just fine.
- davidpelaez 9y agoThis is amazing and literally filling a void for companies aware of the benefits but lacking the budget. There's one last barrier though: how to use this in the cloud? A partnership with AWS to have this as a service would be amazing because their HSM offering is not affordable and also because for many compliance reasons companies use AWS (PCI DSS for example) and there would be no way to include HSM 2 there. Let's hope this happens!
- Shtirlic 9y agoI must add this post https://plus.google.com/+gregkroahhartman/posts/WK6ZLEhfQo5 https://plus.google.com/+gregkroahhartman/posts/WK6ZLEhfQo5 Is it open source? "Yubico has replaced all open-source components that made yubikey NEOs so awesome with proprietary closed-source code in Yubikey 4s"
- lisper 9y agoAn even lower cost (and open-source) alternative: https://sc4.us/hsm https://sc4.us/hsm The SC4-HSM also includes dedicated I/O (a display and two buttons) which makes it more secure than the Yubikey. Disclosure: this is my product.