5 ms·
I think links like this are really helpful. Too offer I suffer from the (common on HN) mindset of, "I know nothing about this field, but I'm intelligent enough
by jphoward 6y ago
I think links like this are really helpful. Too offer I suffer from the (common on HN) mindset of, "I know nothing about this field, but I'm intelligent enough to know this is stupid". Posts like this are not only interesting, but give me a small dose of humility.
- garmaine 6y agoI don't know, this is my field and the post is pretty stupid. Hardware encryption is trivial to do, even in a small form-factor, low-power device like USB storage. A 60x price differential is completely unreasonable. This is rent-seeking on market segmentation. Certain government agencies and contractors are prohibited by law from using a bog standard USB storage device, and require this FIPS certified thing instead. The manufacturers know this. They also have budget to pay, when they are forced to.
- swebs 6y agoDid you read the top answer? Level 3 compliance doesn't sound trivial at all.
- fabian2k 6y agoThe price seems reasonable for the kind of effort that compliance requires. Though if you are not bound by this very particular security level, it probably doesn't make sense to use this instead of strong cryptography alone. If the encryption is strong enough, you don't need the fancy intrusion detection.
- andai 6y agoSay, if encryption isn't done on the device itself, then it wouldn't need to be tamper proof would it?
- solarkraft 6y agoYeah. To my untrained eye it looks like FIPS-140 was designed for devices handling unencrypted data (anything with computation) where physical security matters and this USB stick is just a by-product of a blanket requirement that it's used.
- toyg 6y agoIsn't that a good thing? Anything implemented in software puts some burden on the user's side ("are you using the right OS with the right program and the right options in the right way? Just one misstep and it's all for naught"). Offloading more of that cognitive load and operational risk onto dedicated hardware is surely a good thing (if uneconomical) in practice.
- Nullabillity 6y agoThe USB host still has access to both the plaintext and key (once authenticated), so they both need to be fully trusted anyway. This garbage just adds yet another link to the critical chain. Oh, and now you have full plain text access over the (unencrypted and unauthenticated) USB bus. Hope you put as much effort into vetting your USB hubs!
- toyg 6y agoWhen I was writing that post, I had actually added a second paragraph, that basically said "I hope there were some standard mechanisms for the hardware to refuse mounting without a password or some other verification system". I eventually deleted it because there might well be something of the sort already, in the bowels of TPM specs and similar. There is no reason, imho, why we shouldn't strive to "encrypt all the things", including buses, so that data is guaranteed to be available only to fully-trusted chains. This should obviously be configurable by administrators, with destruction guarantees when options are relaxed. This will not be for everyone (and yes, it will likely always be weak against the $5-wrench attack), but for people who really need it (like deployed troops, whose default opsec practices are typically too lax to be left to humans).
- garmaine 6y agoThe top answer writes enthusiastically about how difficult it is, but without providing any real details. The crazy epoxy stuff he writes about is not specified in the FIPS requirements but rather a lazy hack some people do when they want to run non-FIPS certified consumer hardware. Remarkably he even hypothesizes the solution that they almost certainly are using here, without realizing how trivial it is: > Guess: maybe there are tiny wires in the casing and an "intrusion detection" chip with its own battery that is never powered off so that it can monitor for breakage of the wires and trigger a wipe? This is very likely what they are doing. And it's both simple and cheap to manufacture and implement at scale. Basically the inner-side of the metal casing is conductive and etched to be a big wire looping around the device, forming a circuit. Any attempt to drill or decase it will break the circuit and trigger a wipe. The wipe itself is done by a small 16-bit microcontroller powered off a watch battery or large capacitor. All the parts cost less than a dollar, and the case etching machine is something a company like Kingston would have on hand for other purposes. At my last job we had to roll our own physical security solution for protecting keys because the off-the-shelf FIPS level 3 stuff was so brain-dead stupid and easy to defeat that it didn't meat our security needs.
- manigandham 6y agoHow would you defeat that if it's supposed to be so easy?
- garmaine 6y agoMany options. Drill through the conductive portion of the USB connector itself, which obviously can't be part of the circuit. Put it in a cryogenic freezer to kill the electronics without wiping the static ram. Evesdrop on the USB connection itself which leaks EM radiation like a sieve. User power analysis to extract the key since a device in this form factor is typically not using constant-power components. That's just off the top of my head.
- buran77 6y agoI see you're now confusing "raising the bar for a successful hack" with "must be guaranteed impenetrable". One can invest a lot into obtaining a successful hack so we might as well not even try to protect it? Let that sink in before your next comment. Standing against your own point is that your HN account password is not posted in your profile even if it could be obtained with the famous $5 wrench. But to your point, at Level 3 it most likely means any normal attempt to open the case or rewrite the firmware would irretrievably destroy the device or wipe the encryption keys. Flash freezing a device or drilling is likely to have this effect since some of the epoxy housing should be made to crack and sever specific connection triggering the wipe before all of the heat is conducted away from the inner components. Same for using solvents, acids, or radiation which may be more of a Level 4 compliance. As for the power constant components (whether they are at L3 or L4), they may or may not be used. It may very well be part of the asking price. Apple's T2 chip is FIPS 140-2 compliant and you can be certain a lot of money was invested in making it secure yet it was still jailbroken.
- spacecad3t 6y agoIm a product manager who took a device through level 3 and yes, it is not trivial. Now, that same device is also NSA Type-1 ... which is not an official cert and damn near impossible. Took me and my sales lead 8 months just to find a military officer willing to sponsor.
- fbnlsr 6y agoI'd love to read about that device of yours and how you managed to get such a certification.
- spacecadet 6y agoIt started with possible Customers saying they couldn't close out larger orders and grant "in field" operation without FIPS and Type 1. We already met FIPS 2, it took some reworking for FIPS 3, and Type 1 actually isn't too bad, it's the networking your way into the NSA (and a sponsor) and them giving you the time of day. Many of our Customer contacts LOVED the product, but were not appropriate sponsors and their intros just always went cold. The best part of the story is when we finally got a phone number to someones desk at the NSA and I just cold called it. "Hello...", "Hi [my intro]", "[silence]"... lol
- jmnicolas 6y agoSo in your experience is the price for this USB drive justified?
- spacecadet 6y agoDepends on the needs of the Customer... Our Customers required FIPS and Type 1 and our pricing research suggested we could also tack on a premium for the product.
- Daviey 6y agoThe cost based on sum-of-parts, does seem to be unreasonable... but few products are measured based on their ingredients alone. Having been involved in the FIPS-140 certification process I know first hand it is both slow and expensive. It is fair to say that the general consumer version shouldn't shoulder the burden of this cost, and the market for this product is small. Therefore, the 'unreasonable' price likely isn't that ridiculous.
- onetimemanytime 6y ago>>Certain government agencies and contractors are prohibited by law from using a bog standard USB storage device, and require this FIPS certified thing instead. The manufacturers know this. This is nothing new. So why hasn't another manufacturer done at much cheaper prices in those these years? As for encrypting: Hiding pictures from your wife is a lot different than hiding corporate or state secrets from Russia and China.
- AniseAbyss 6y agoI'm sure they have but the US military only buys from the US so that cuts out most manufacturers.
- sarthakjshetty 6y agoBot much? https://news.ycombinator.com/item?id=25196874 https://news.ycombinator.com/item?id=25196874
- deleted 6y ago[deleted]
- OJFord 6y agoActually I think maybe GP was sincere, and that one (your link) copied it. GP has months (at least) of comments, and they're not vacuous. (Unless they're all copied from elsewhere too, but there aren't replies identifying that, and I'm not going to dig into it. :))
- 93po 6y agoIt's not sincere. It's clearly worded that it could work for virtually any sort of content on HN
- OJFord 6y agoLook at their other comments. I'm sure some of my own comments could also be misconstrued as 'fake comments' applying to virtually any submission!
- read_if_gay_ 6y agoI don’t think so. Not everything linked here seems stupid at first glance, and the comment clearly says that this does.
- tspiteri 6y agoYou're replying to a comment with item id 25196754, and your link has item id 25196874, which comes later.
- joshxyz 6y agoReminds me of the first time I saw that stackoverflow page comparing hash algorithms (from crc32 md5 xxhash to sha) thru patterns it generated onto an image. Also answers by the zlib guy, the nagle algorithm guy. Explanations like those just blow my mind.
- programbreeding 6y ago>stackoverflow page comparing hash algorithms (from crc32 md5 xxhash to sha) thru patterns it generated onto an image. https://softwareengineering.stackexchange.com/a/145633 https://softwareengineering.stackexchange.com/a/145633 >Also answers by the zlib guy https://stackoverflow.com/a/20765054 https://stackoverflow.com/a/20765054 https://stackoverflow.com/users/1180620/mark-adler https://stackoverflow.com/users/1180620/mark-adler >the nagle algorithm guy https://news.ycombinator.com/user?id=Animats https://news.ycombinator.com/user?id=Animats