12 ms·
The Myth of Consumer-Grade Security
- ttsda 7y agoI like the general argument that's being made in the article about encryption available to consumers being the same, and of the same importance as military encryption, but I've got to disagree with military electronics no longer being the bleeding edge. Especially in areas such as RF, optics and positioning, the military still has access to stuff the general market can only dream of.
- jascii 7y agoDo you have any examples of that? In my experience the military tends to be extremely conservative and prefers well-proven designs. For example: The RCA1802, a processor launched in 1972 is still being manufactured mostly because of its use in military applications (guidance system of the Tomahawk Cruise missile among others)
- SiempreViernes 7y agoThe military is always at the bleeding edge of military applications and form factors, I think that is what gets people confused. I mean the small cassegrain telescopes in missiles are probably bleeding edge for that size and weight for instance. However, I think this fact falls into "weird flex, but ok" category.
- wcunning 7y agoGorgon Stare springs immediately to mind. I certainly can't afford a multi-day in the air drone carrying a 30 lbs mutli-million megapixel wide camera [0]. [0]https://en.wikipedia.org/wiki/Gorgon_Stare https://en.wikipedia.org/wiki/Gorgon_Stare
- jascii 7y agoObviously the military has "toys" I cant afford, however, do you see any fundamental technologies in that imaging system that are not available to consumers? Even the quoted development cost of $15 Milion are not out of range for a well funded tech startup..
- Retric 7y agoIt’s not a single multi million mega pixel camera. “ARGUS is essentially 368 five-megapixel smartphone cameras clustered together” That’s a 1,840 megapixel (1.85 gigapixel) camera which is not that extreme and in line with several of these images: https://petapixel.com/tag/gigapixel/ https://petapixel.com/tag/gigapixel/ A lot of confusion comes because it’s a combination of multiple different cameras than capture wide angles, infrared, and a separate camera that can focus on areas of interest within the field of view. So, if the entire image was at maximum resolution you would get into insane territory, but that’s not how it works.
- nostrademons 7y agoFor a while the President was tweeting from a consumer-grade Android (!) phone, likely made by China, in the Oval Office. It makes me wonder how many groups pwned that phone and have access to critical national security information.
- mieseratte 7y ago> For a while the President was tweeting from a consumer-grade Android (!) phone, likely made by China, in the Oval Office. It makes me wonder how many groups pwned that phone and have access to critical national security information. You mentioned tweeting, was he doing NATSEC-relevant work from the phone or was he using an official device for those purposes?
- nostrademons 7y agoAs I understand it he wasn't doing NATSEC-relevant work from the phone, but on Android spyware can turn on the microphone and camera remotely. During the Cold War our adversaries would've given anything to slip a bug into the Oval Office; now every hacker group who can pwn an Android phone has one.
- isostatic 7y ago> During the Cold War our adversaries would've given anything to slip a bug into the Oval Office See https://en.m.wikipedia.org/wiki/The_Thing_(listening_device) https://en.m.wikipedia.org/wiki/The_Thing_(listening_device)
- bubblethink 7y ago>but on Android spyware can turn on the microphone and camera remotely. Seems like an unsubstantiated claim. Also, Android is a broad umbrella term where security varies widely across implementations and devices. Do you have any concrete information about reference Android devices (i.e., Pixels)
- opencl 7y ago
- RcouF1uZ4gsC 7y agoWhy can't we have both security as well as court ordered access. What would be the problems if we had 5 HSM that are airgapped and located at secure facilities. Encrypted applications (such as WhatsApp, Apple Messenger, etc) are required to submit/transmit escrow keys that are encrypted with the public keys of those 5 HSM's. After a valid court order, a law enforcement official has to physically go to one of the secure locations with those encrypted escrow keys which will then be decrypted by the HSM. This way, everyone can have secure communication, but still allow legitimate law enforcement searches when ordered by a judge.
- jjoonathan 7y agoThese people couldn't stop the OPM database -- blackmail on all of their sensitive personnel -- from getting hacked, and that's something they wanted to protect. Now imagine how good a job they would do of protecting something they resented, like the escrow mechanism in your proposal. Yeah.
- LocalPCGuy 7y agoAnd when one of those keys gets out? (Which will happen)
- RcouF1uZ4gsC 7y agoThe whole point of an HSM is that those keys cannot get out.
- w3rhn2j34oh5o 7y agoThe point, yes, but it is not the case in reality: 2015: https://cryptosense.com/blog/the-untold-story-of-pkcs11-hsm-vulnerabilities/ https://cryptosense.com/blog/the-untold-story-of-pkcs11-hsm-... 2017: https://cryptosense.com/blog/infineon-rsa-key-generation-bug-how-the-attack-works-and-what-to-do/ https://cryptosense.com/blog/infineon-rsa-key-generation-bug... 2019: https://cryptosense.com/blog/how-ledger-hacked-an-hsm/ https://cryptosense.com/blog/how-ledger-hacked-an-hsm/ Stop trying to build scenarios where key escrow solutions are technically sound. They are not. This is an intractable problem that is not solved by these half cocked technical measures. Key escrow cannot by definition be secure, and wasting time trying to invent solutions just confuses the matter, weakens security and leaves us all vulnerable. Basically, Sssssssh, or the politicians might actually believe this fantasy.
- dredmorbius 7y agoIn the 1960s, the ecological notion that "there is no 'away' to throw things" finally became widespread regards pollution, first stated by Barry Commoner. In the 2010s, the informational notion that "there is no 'other' informatics ecosystem" on which security, privacy, or surveillance practices and principles apply is slowly dawning.
- dredmorbius 7y agoThinking this through a bit further ... ... largely as a consequence of several factors: interconnectedness, device development costs, functional flexibility, and winner-take-all market-capture dynamics. Interconnectedness means that even if your secure, classified, compartmentalised, encrypted, logged information begins or exists on bespoke kit, there's extraodinarily good odds that it will transit or reside on other systems either on its way there or after being created. Networks are complex, with many components, and ensuring all kit is fully certified and cleared is all but impossible. The costs of developing new devices is both falling (Moore's Law) and rising (hardware, firmware, driver, and software design is all rapidly rising in complexity). In virtually all cases, it is tremendously cheaper to begin with COTS (common off-the-shelf) hardware or software than to do a ground-up, greenfield, clean development. And where classified development exists, keeping up with improvements in consumer-grade kit is either impossible or remarkably expensive. This claim rests on publicly available information, and it may well be that there are some exceptions. A few datapoints at least point to the likely costs. The Xen hypervisor has an advantage over vmware in that, by serving as a "shim" over the Linux kernel, it inherets the full class of Linux-supported devices. VMWare at least though the early 2010s was reliant on its own device development and featured a highly restricted HCL (hardware compatibility list). The list of publicly-known top-500 supercomputers consists entirely of Linux-based systems. There is no public investment in either proprietary or bespoke supercomputer operating systems. Any classified work would have limited leverage from publicly-available development. Numerous of the publicly known supercomputers are engaged in highly-sensitive classified work. Evidence suggests limited, or exceptionally expensive, alternatives, if any. Functional flexibility: what is still being called a "phone" is in fact a general purpose computer. And, for what it's worth, general-purpose surveillance-capitalism, state-surveillance, and ATP-surveillance platform, but I digress. A slim glass-fronted slab provides voice comms, text comms, email, camera, calendar, notekeeping, Web access, geolocation, mapping, directions, e-book access, and a myrad of applications (though many of highly dubious utility). Both Android and iOS offer commandline access, though of varying completeness, reliability, and utility. (Termux now offers over 1,200 packages, Apple's iOS project remains fairly nascent.) This includes multiple development environments and potential well beyond the limitations of native Android and iOS platforms (already quite extensive). A single "do everything" tool, that's sufficient for most of those tasks, will replace special-purpose bespoke tools in practice. It's an inevitable Desire Path (https://en.wikipedia.org/wiki/Desire_path https://en.wikipedia.org/wiki/Desire_path). As a practical matter, workforce, corps, or agent discipline will be broken, and such devices will be used. Winner-take-all market dynamics arise from several mechanisms, most especially positive-feedback network-effect loops of manufacture, development, sales and supply channels, developer ecosystems, and marketshare. Which means that not only will consumer-grade devices dominate, but a very small number of device or platform variants will dominate. Even highly-capitalised and capable firms experience frequent failure in attempting to dislodge established incumbents: Microsoft Mobile, in devices, Google+, in social networks, Intel's Itanium, in CPU design, Apple in cloud services, Amazon's Fire Phone. My point isn't that these are devices, but that they're the biggest players in the tech world taking on an entrenched contender and failing spectacularly. Niche security projects are effectively playing in this field. They do not have to compete in the market with commercial offerings, but they do have to compete for talent, mindshare, tools, skillsets, and concepts. And they will all but certainly have to either interoperate with, or take into consideration the functions and features of consumer-grade kit. Upshot: the worlds aren't separate, closed secure systems development competes poorly, and effective practice will blur all boundaries regardless. There is no 'other' informatics ecosystem. We've got to make the one we've got healthy.
- notinpersia 7y agoSee this, too. Happy to share code/implementation details. https://docs.google.com/presentation/d/1f2k6fsIkDmIS1WyJAT0lXQmDuHIPeo9GDKfP1FY2rVc https://docs.google.com/presentation/d/1f2k6fsIkDmIS1WyJAT0l...
- jammygit 7y ago> Through the mid-1990s, there was a difference between military-grade encryption and consumer-grade encryption. Laws regulated encryption as a munition and limited what could legally be exported only to key lengths that were easily breakable. That changed with the rise of Internet commerce, because the needs of commercial applications more closely mirrored the needs of the military. The case seems to be that the government and military has almost no special product offerings, so they use consumer tech. Therefore, weakening consumer tech weakens the government and military. This is not a robust argument imo. The stronger argument is about how a whole economy would spring up that would fill office building after office building with full time hackers trying to dox, blackmail, mitm, or steal from every non-banking, non-crypto-approved communication in the world. The interned would eventually just die off as a communications platform as the public completely lost trust in it (though not politicians - they would be approved to use the secure channels and would not understand the issue) edit: typo & wording fix
- m3kw9 7y agoConsumer grade security is impede them just long enough till the cops arrive