4 ms·
Isn't it a question of where you put your trust? For the software solution you have to trust the computer and its file encryption utilities. For the hardware so
by steerablesafe 6y ago
Isn't it a question of where you put your trust? For the software solution you have to trust the computer and its file encryption utilities. For the hardware solution you have to trust the USB stick.
Although one could assert that data coming from an untrusted computer might be already compromised. It might not be the case for an air gapped system.
Or you can trust different aspects of the computer at a different level. You can trust it for its normal functions but maybe it doesn't get regular updates for file encryption utilities and USB mass storage drivers. Sometimes you still need to fetch data from it using trusted USB devices.
Threat models can be complicated, also it makes sense to apply defense in depth.
- marcan_42 6y agoIf your software is compromised it can already read or write it whatever it wants off of an IronKey, or fire off a passphrase change request behind the scenes and replace your passphrase with an insecure one to render the physical device insecure, at which point it is equivalent to a $27 USB stick. Perhaps in an enterprise setting with physical controls and air gaps you might be able to have a device require a different admin PIN to change the passphrase, avoiding the latter scenario of data exfiltration, but then the device has to be explicitly designed with this in mind to avoid any other exfiltration channels for the true PIN and I don't think IronKeys claim to do this (I don't even know if they support such a split admin PIN). And besides, you probably have bigger problems if your air gapped computer is compromised anyway. Really, IronKeys and their ilk cater to corporate and government bureaucracy use cases that have long since been divorced from true trustable security. They are instead a mountain of complexity, and the more complex a system, the less likely it is to be secure. The thing about software is that you can audit it yourself - it's quite easy to read through the entire source code of a trivial but secure file encryption app and convince yourself that the algorithms match published and industry standard implementations, and that they match test vectors, and that it interoperates with another instance on another machine, or send the files off to someone else to double check. You cannot audit an IronKey yourself. But yeah, sure, defense in depth is a thing, and if you use an IronKey and software encryption (with different passphrases!) then you probably end up with better security, or at least not worse :-)
- praestigiare 6y agoMore to the point, for the software solution, you have to trust the user to actually do the encryption and to use a strong passphrase.
- steerablesafe 6y agoThis is an other good point. Not to mention secure key exchanges between users when necessary.
- jmnicolas 6y agoThen use both: put encrypted files on the encrypted drive.