5 ms·
The hiding of the malicious code in arm processors of ssds and in the BIOS seem like this is mainly targeted at people running their own hardware. Does this me
by gnur 6y ago
The hiding of the malicious code in arm processors of ssds and in the BIOS seem like this is mainly targeted at people running their own hardware.
Does this mean running in a public cloud might actually be more secure?
Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?
- sbierwagen 6y agoWhy on Earth would public cloud be more secure? If the NSA has dedicated rack space in AT&T switching facilities, what makes you think they don't have offices at Microsoft, Amazon, Cloudflare, etc? https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A
- luckylion 6y ago> Does this mean running in a public cloud might actually be more secure? If that public Cloud is from an American company: obviously no. And whether you prefer some Chinese intelligence service having access to your data probably depends on what you want to do.
- nix23 6y agoNot just because of Intelligence services but also because of the CLOUD Act / Data Residency.
- jauer 6y ago> Does this mean running in a public cloud might actually be more secure? Yes with two conditions: 1. your public cloud is run by an Amazon, Google, Microsoft-type company (FANMAG) 2. You trust the company to lean on rule of law. 1. Very few providers have the capability and desire to put the work into supply chain security, things like OpenTitan, etc. 2. They might hand over your data in response to warrant, but their systems are designed to prevent covert extraction of data. The company should have a track-record of pushing back against overly broad warrants.
- raxxorrax 6y agoIn practical terms this is wrong in my opinion. You want the small provider that flies under the radar. If there are ambitions to compromise the hardware supply chain, it is a bit late to act. But it is logistically impossible or at least very unlikely to compromise every provider. But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system spies on you if you can control its network traffic and construct crypt generation from basic arithmetic functions of the system in question.
- jauer 6y agoSmall providers often don't have the resources or skills to properly cover their bases and get hit by random BS. They may not be targeted today, but they will get hit by random badness. Example of shared hosting providers not patching postfix fast enough or having a support person that chmodded the wrong thing on shared hosting server, customer with old wordpress install that was exploited to drop a webshell, etc. > But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system spies on you Do you have any references? I'd like to read more. If this were generally true, attempts to make trusted enclaves like Intel SGX (though flawed) would not need to exist.
- heavyset_go 6y ago> Does this mean running in a public cloud might actually be more secure? No, because cloud providers are one subpeona, court order or warrant away from surveillance and exfiltration of your data without your knowledge. If the DHS deems you a threat, then all proceedings can happen through secret courts and you'll be none the wiser to it happening, and you'll get a gag order on top of it.