3 ms·
I’m not convinced there aren’t binary blobs in the precursor at key locations which can sabotage both being free and open, as well as having a potential securit
by throwaway654329 4y ago
I’m not convinced there aren’t binary blobs in the precursor at key locations which can sabotage both being free and open, as well as having a potential security impact. To be fair: non-free hardware and/or non-free software are not really claimed. The claim is somehow inspectability which is poorly defined. Who is inspecting it? I trust bunnie and Sean, but they can’t do everything. They need support and help to succeed.
For example: The Wi-Fi chip is isolated because it is very much non-free. I don’t see much of a security claim here and there is a limited transparency claim. The claim is that it is isolated and if it is misbehaving, it won’t be able to harm the overall system other than perhaps denying service. I am curious if it has randomized MAC addresses and I am equally curious if radio fingerprinting is considered as part of the threat model for identification reasons. I would also like to know if DPA is considered in the threat model of the chip being malicious - @bunnie?
The Spartan 7 is well analyzed and as a result the claim is that it is practically secure. This is reasonable BUT while necessary, it is not sufficient analysis. The analysts entirely sidesteps project BULLRUN style sabotage. For such a project to resist state level attackers, I would wager one attack on this FPGA is pressuring Xilinx, and another would be by performing a software supply chain,
Trusting your compiler is a problem we face, and imagine if Xous was only buildable with a non-free compiler? I don’t think anyone would accept this and yet with FPGAs, that’s the current state of things. With all due respect ( and bunnie/Sean deserve a lot of respect!): it is irresponsible to encourage the use of and to claim this is secure unless the authors have audited the non free software in some meaningful way, and they additionally also know bay the thing they audited is the same as what users use.
We know what Xilinx claims. We also know what large-scale adversaries are up to. We should assume at least one bad actor from the top four intel agencies are working to sabotage them. There are other adversaries to consider and there are a LOT of them, well funded, and highly motivated.
It just makes sense and we KNOW this is ongoing at nearly every level. Making it free software won’t stop such sabotage but it will make it much more likely to find such sabotage. What’s the plan to discover such sabotage with the current tool chain? Currently I see none, and this is unreasonable given the claims of security. They should really flesh this out, and spark the discussion.
With all of that said, it’s so close to perfect. The project needs support and my criticisms here are not intended to say anything other than how tough the problems are for such a device.
Buy one or two! Help free the FPGA tool chain. Help develop useful post-quantum cryptography implementations (eg CSIDH) to build on the great Curve25519 work that has already been done. This project is important and if it was twice the price to get a fully free FPGA, it would be worth it. I would also like a tiny camera module to scan and exchange air gapped data with QR codes, or a small modem like communication protocol with the audio port. Could easily do IR for example. So many great opportunities here, and just a few gaps to close, even if they are big ones. It’s still better with these problems than nearly all other options, hands down.