5 ms·
> MCST’s proprietary C/C++ compiler and bootloader will be provided only as binary, because we do not have access to the source code of this part. Buy a “secur
by ddol 6y ago
> MCST’s proprietary C/C++ compiler and bootloader will be provided only as binary, because we do not have access to the source code of this part.
Buy a “security focused” computer where the compiler is not open source, and the CPU/ICs have not been decapped, imaged and analysed from a manufacturer with ties to the Russian government? No thank you.
I would not be surprised if there is a hardware Trojan in this machine.
- tyingq 6y agoI'd put it in the same category as using Yandex as your email provider. That is, probably somewhat safer from "5 eyes", but open to Russia. There's probably people for who that's a valid, useful setup.
- richardwhiuk 6y agoPeople who work for the Russian government?
- tyingq 6y agoPeople doing things that they don't want the FBI/IRS/etc to see, but don't care if Russia sees is probably a broader set than that.
- ardy42 6y ago> People doing things that they don't want the FBI/IRS/etc to see, but don't care if Russia sees is probably a broader set than that. If you want to avoid eavesdropping, it's probably best to avoid email altogether and use something designed for that purpose (like Signal). I don't see how you would get the effect you describe by using Yandex unless you did something like only ever emailing other Yandex accounts.
- hollerith 6y agoJust because someone used Yandex as a hyperbolic analogy doesn't mean we're talking about Yandex.
- ardy42 6y ago> Just because someone used Yandex as a hyperbolic analogy doesn't mean we're talking about Yandex. But my point is that email itself is an insecure technology, and not even Phil Zimmerman bothers with PGP [1]. If you want to avoid something like 5 Eyes eavesdropping with a Russian/Chinese/etc. email provider, at a minimum you probably won't be able to email anyone with a 5 Eyes-based email account, and even if you do that some fraction of your mails may still get hoovered up in transit somewhere else. Sticking to only emailing accounts on the same provider seems like the most "secure" implementation of this idea, but even that is suspect. The PRC hacked Gmail ten years ago, and it's not unreasonable to assume the NSA could have an APT in Yandex. IMHO, this equipment really only helps with security concerns unique to the Russian government itself. Regular people in other countries have better options for their use-cases. [1] https://www.vice.com/en/article/vvbw9a/even-the-inventor-of-pgp-doesnt-use-pgp https://www.vice.com/en/article/vvbw9a/even-the-inventor-of-... [2] https://en.wikipedia.org/wiki/Operation_Aurora https://en.wikipedia.org/wiki/Operation_Aurora
- tyingq 6y agoAssume you have a shady company that has to use email for some things. Having your email provider being unlikely to comply with a US subpoena could have value.
- erinnh 6y agoPeople living inside the 5 eyes. Its arguably harder for Countries outside your own/those that are in good standing with yours to affect your life. While your own/allied Countries will be able to do more with the information that you potential give it. Not that Im saying to get one of these or not. Just an idea why it might be interesting to prefer to give information to one country instead of another. (if you have the choice)
- marcinzm 6y ago>Its arguably harder for Countries outside your own/those that are in good standing with yours to affect your life. Given full access to your email they can do a lot of things that would cost you your job and potentially lead to criminal charges. Given that these governments are actively performing cyber crimes in your nation of residence why wouldn't they use you (and your credentials) as a stepping stone? The risk is low but so is the risk of your own government going after you. Neither is zero.
- SpaceRaccoon 6y agoWould you the same about foreigners who use American services? Does it warrant losing their jobs and criminal charges in their respective countries?
- richardwhiuk 6y agoYeah - not sure why this is viewed as a security bonus.
- patentatt 6y agoAnd it has built-in GPS, what could go wrong?
- zeckalpha 6y agoSurprised it isn’t GLONASS
- drno123 6y agoConsidering that Russian military financing is way smaller than that od US, and considering that Russia involves itself only in affairs of few neighbouring countries, I have more problems about NSA reading my email (GMail, Hotmail etc), than anyone in Russia reading it.
- varjag 6y agoThe USA is a neighbouring country.
- AsyncAwait 6y agoTo Afghanistan? Iraq? Iran? Venezuela?
- varjag 6y agoTo Russia. Synchronize.
- AsyncAwait 6y ago> Russia involves itself only in affairs of few neighboring countries Was presumably meant in reference to neighboring countries where Russia involves itself to the point where it would be wiser for a citizen of such a country to store their data in the West. The U.S. is not a country fitting this definition by any stretch.
- varjag 6y agoThe USA is Russia's chosen archenemy (regardless what half of Americans think), with most of Russian intelligence, military and diplomatic effort focused on confronting it. Even when Russia screws over its smaller neighbours they always explain it away as countering America. But even if it wasn't this whole argument is the good old "I don't have anything to hide" re-stated but for foreign powers. It goes fine until you end up with your piss tape.
- iuguy 6y agoLike say, a hidden computer running inside the system that you can't deactivate and have no access to? That kind of a hardware trojan?
- buran77 6y agoYou have to love the uninformed nationalism when these topics come up. I feel this [0] image perfectly illustrates it. It's not just that plenty of people simply have no idea what they're using as we speak (they will just judge based on some nationalistic sense of value) but some will keep touting "the principle" because it makes it easier to rationalize while actually being perfectly OK with the black box definitely spying them for "home team" rather then the black box that may be spying them for "away team". Not referring to any particular black box here. [0] https://pics.me.me/our-blessed-homeland-their-barbarous-wastes-our-glorious-leader-their-30162740.png https://pics.me.me/our-blessed-homeland-their-barbarous-wast...
- orbital-decay 6y agoThe security here means it's been made by the Russian government to be used by the Russian government. The supply chain is domestic and supposed to be more resistant to a potential adversary, so the resulting hardware is usable in sensitive (natsec) matters. That's why the author wasn't able to obtain one before: they simply never bothered releasing it for non-government use.
- FullyFunctional 6y agoRight. I think Bunnie has very good arguments for how you should approach "security focused" hardware (see, https://youtu.be/w8BA6_9HCzk https://youtu.be/w8BA6_9HCzk) and this clearly isn't it. AFAICT, this has much less documentation than the Itanium, so even from a tinker's perspective, this is really uninteresting.