7 ms·
For many years I've just viewed all of my devices as possibly compromised. It's one of the reasons I've been very down on cryptocurrencies in general. I don't a
by pontifier 2y ago
For many years I've just viewed all of my devices as possibly compromised. It's one of the reasons I've been very down on cryptocurrencies in general. I don't actually see USB as something that can maintain a true, robust airgap, because the amount of data transferred is not inspectable.
In my view, the best use of an airgapped machine would be for storage of extremely dense and sensitive information such as cryptographic keys. Signing or encryption should be accomplished through an inspectable data channel requiring manual interaction such as QR codes. When every bit in and out of a machine serves a purpose, it's much less likely to leak.
Example: show a qr code to a camera on the airgapped machine and get a qr code on the screen containing the signature of the data presented to it. There is very little room for nefarious code execution or data transmission.
- Terr_ 2y agoI'm imagining a "secure slate" you can carry between the computers, a tiny tablet with a camera, e-ink display, and replaceable batteries. It does nothing but snap a picture of a QR code and then (if error checking is OK) reproduces it on its own durable display. Add a write-protection switch that doubles as a cover on the camera-lens, and have it auto-blank when not in use. So you'd snapshot its QR code, hand-carry the slate to air-gapped Computer B, press a button to wake it up, brandish the "copied" QR code in front of B's camera, etc. Maybe even take one and (with careful labeling) put it into a safe, depending on how long you plan to store it. You could do something similar with a camera and thermal-paper printer, but then the physical artifact needs to be reliably destroyed by manual effort, as opposed to auto-erasure.
- itishappy 2y agoIt'd only take about 1000 QR codes to install vim!
- Terr_ 2y agoExcept low-bandwidth here is a feature, not a bug. ... Plus one more QR code to quit vi(m) when it's accidentally launched.
- therein 2y agoNot a small number even for BBQr. https://github.com/coinkite/BBQr https://github.com/coinkite/BBQr
- vlovich123 2y agoYour air gapped machine would be generating the QR codes not ingesting them.
- zmgsabst 2y agoThere’s scanners at 100+ pages per minute and you can fit a (half) dozen maxed out QRs per page. I’m okay with it taking a minute or two to install software on a high security system, eg, the root cryptography for our military radios. …maybe I should get into the business of “paper drives”.
- pontifier 2y agoFor longer term storage use an analog camera to take pictures of the QR codes, then develop the film and store them in an airtight climate controlled vault. Bonus points if the film is designed to be very stable after developing. Maybe platinum prints with lots of error correction.
- thinkmassive 2y agoHere’s some similar devices that already exist: https://seedsigner.com/ https://seedsigner.com/ https://foundation.xyz/passport/ https://foundation.xyz/passport/ https://store.blockstream.com/products/blockstream-jade-hardware-wallet-1 https://store.blockstream.com/products/blockstream-jade-hard...
- rblatz 2y agoWhy not just use a Polaroid camera?
- Terr_ 2y agoWell, the context is a facility where security must be so tight that you're air-gapping computers in the first place, so a lot of the same reasons nobody would be permitted to bring their personal film-camera into the place either: You don't want to make it easy for people to take pictures of arbitrary things (faces, documents, whiteboards) and you don't want to always be searching everyone's underwear for instant-photos or film-canisters. In contrast, a worker can sign-out a hardened device, and when they return it on the way out you can be reasonably sure they couldn't have easily made copies. Plus the scanner won't capture arbitrary pictures in the first place, and it can be set to auto-wipe after X minutes of inactivity. If you give people 10 unexposed sheets and require them to return a total of 10 used/unused on the way out, that's susceptible to them smuggling in an unexposed sheet, and you're back to underwear searches again.
- miki123211 2y agoWith appropriate encryption between the two machines, the slate could even be a simple smartphone. It doesn't matter whether the smartphone is internet-connected or not, as the slate's contents wouldn't be of any use without hacking one of the machines, and if you could do that, you wouldn't need to hack the slate in the first place.
- throwing_away 2y agoI think you're describing WalletConnect without knowing it exists.
- avodonosov 2y agoIsn't it easier to just type in what you need?
- surfsvammel 2y agoWhy would a QR be more safe from containing malware than another medium like USB drive? Is it just that the amount of data it holds is more constrained?
- mikequinlan 2y agoThe USB protocol gives the drive access to all (physical) memory on the machine. QR codes only encode text (usually a URL but it can be any text).
- gruez 2y ago>The USB protocol gives the drive access to all (physical) memory on the machine Source? Unless you're using something like usb 4 (ie. thunderbolt) usb devices don't have DMA access.
- dumbo-octopus 2y agoWhat about direct DMA access to the memory?
- vlovich123 2y agoIOMMU typically controls access so that the peripheral only has access to memory the OS allows it to have.
- vlovich123 2y agoEven thunderbolt wouldn’t have arbitrary dma access unless your machine is lacking iommu
- appendix-rock 2y agoNo it doesn’t.
- bigiain 2y agoYes. But using USB devices has a practically infinitely greater attack surface that parsing data embedded in a QR Code. It's not like yo have to read QR Codes and go "echo $QRData | sudo bash" "BadUSB is a computer security attack using USB devices that are programmed with malicious software.[2] For example, USB flash drives can contain a programmable Intel 8051 microcontroller, which can be reprogrammed, turning a USB flash drive into a malicious device.[3] This attack works by programming the fake USB flash drive to emulate a keyboard. Once it is plugged into a computer, it is automatically recognized and allowed to interact with the computer. It can than then initiate a series of keystrokes which open a command window and issue commands to download malware. " -- https://en.wikipedia.org/wiki/BadUSB https://en.wikipedia.org/wiki/BadUSB
- Jun8 2y agoThis is interesting. Another use for such a secure machine would be to enter text, eg highly controversial blog entries or erotic stories. Then any common computer or phone with a camera can be used to transfer the text using 2D barcodes. This would be a bit slow: say a barcode. If we assume a single barcode can hold 1500 characters (text twice as long as your comment), a blog entry may need 4-5 barcodes. Not undoable. Such a machine would not have a camera, WiFi, BT, or any input or output mechanism of any kind.
- darklion 2y agoI’m struggling to understand why controversial blog entries and erotic fiction need a secure machine.
- appendix-rock 2y agoI mean, this thread has itself very clearly turned into some crypto-fetishist fan fiction, completely departed from reality. I guess it’s just what came to mind.
- bigiain 2y agoOn the other hand, "recreational paranoia" is a fun hobby. But perhaps we are just saying the same thing, and I just prefer my way of saying it over admitting to yours...
- A4ET8a8uTh0 2y agoOk, that was the first time I heard the phrase ( recreational paranoia ) and I am now lost in a sea of links. Can you elaborate on it? It sounds fascinating to me from context alone.
- Jun8 2y agoYou nailed the term I didn’t know I was looking for, that’s exactly it! As a fantasy I’ve thought about creating a secret identity and have researched how to keep it absolutely safe. This is very hard and you can spend quite a bit of time designing ever elaborate schemes.
- closeparen 2y agoThis is probably a decent use case for plain old serial. Interface via application defined TTY. On the other hand no matter the transport you’re probably going to get owned by well known vulnerabilities in any software processing data from the internet-connected side, if you’re using the air gap as an excuse to avoid patching or otherwise caring about secure coding practices.
- Lonestar1440 2y ago"Patching" is the fundamental reason airgapping isn't a sound solution, IMO. If you're a TLA you can probably find some secure, verifiable, write-only way to transfer patches to your air gapped machines. But for any normal person/organization; you'll very likely end up less secure due to how hard this is.
- closeparen 2y agoYou can use DVD-Rs to load a WSUS server for Windows or a package mirror for Linux, I’d just be surprised if many airgapped operators were keeping on top of this.
- notesinthefield 2y agoThis exactly how its done in many high security gapped environments. Once you get in a rhythm its not hard.
- vlovich123 2y agoThen you’re still at the mercy of the TTY application being secure. Having to go through the analog hole makes it much more difficult. As for patching, you would ensure a secure root of trust and only allow read-only media to deliver said updates as another sibling points out Air gapping is still valuable but it’s still hard to impossible. For example, stuxnet was delivered by an insider. So good physical security and monitoring is also needed to prevent against insider threats.
- 2y ago
- bsbsjsusj 2y agoPunchcards would be better. QR relies on machine vision. The camera would be running its own code. That said, cameras are more of a commodity. QR and typing: see TOTP tokens!
- dboreham 2y agoPaper tape is more pocketable.
- marcus0x62 2y agoThe Soviets had a strong typewriter implant game[0]. They might have to revive some of their old tradecraft to either deliver implants via the card punches, or monitor what is being sent over the air gap. 0 - https://spectrum.ieee.org/the-crazy-story-of-how-soviet-russia-bugged-an-american-embassys-typewriters https://spectrum.ieee.org/the-crazy-story-of-how-soviet-russ...
- NooneAtAll3 2y ago> For many years I've just viewed all of my devices as possibly compromised. so you consider that someone may be reading and possibly modifying data on any computer/phone you own, okay > It's one of the reasons I've been very down on cryptocurrencies in general but you are willing to have form of money that is only accessible via said computer/phone that someone can read and use as if he was you? how does it work? how's this not a contradiction?
- normie3000 2y agoAre you interpreting "down on cryptocurrencies" to mean "in favour of cryptocurrencies"? I think GP meant the opposite.
- Thorrez 2y agoIt's confusing how "I'm down for that" has an opposite meaning from "I'm down on that".
- pontifier 2y agoI considered saying bearish. Maybe I could have been clearer. I have a low opinion about the usefulness of cryptocurrencies because true security is so difficult. It's basically impossible, even if you don't make any mistakes. I really enjoy this kind of stuff, and loved reading about the z-cash ceremony. I'm not going to those lengths to protect my secrets, so I feel it's better if I don't hold a lot of wealth in such a fragile way. I used to like it, but now I don't. It's still neat, but it's too prone to costly mistakes.
- mdp2021 2y agoThey try to make default banking activity on those devices many of us consider possibly compromised...
- normie3000 2y agoSo bearish is negative? What about hawkish?
- magicalhippo 2y agoHow about a USB "MITM" device that presents itself as a serial port to the OS when the user connects a USB storage device. The user would then use a terminal emulator to connect to something like a BBS[1] where they could browse files, and download or upload files to the connected USB storage device using XMODEM[2] like in the good old days. edit: It could of course also filter the files, for example not list any executable files, and prevent transfer of executable files based on scanning their contents. The MITM device would be implemented using a microcontroller with signed firmware, and careful design to prevent a connected USB device to do shenanigans like voltage glitching. This would include using isolated DC-DC and isolated data lines ala like this[3]. The MITM would only interact with the storage device class. If the connected device presents itself as more, say a keyboard, it would just ignore those. The user must be prevented from bypassing the MITM device, though this could be done through physical means. [1]: https://en.wikipedia.org/wiki/Bulletin_board_system https://en.wikipedia.org/wiki/Bulletin_board_system [2]: https://en.wikipedia.org/wiki/XMODEM https://en.wikipedia.org/wiki/XMODEM [3]: https://ez.analog.com/ez-blogs/b/engineerzone-spotlight/posts/you-can-build-your-own-isolated-usb-cable https://ez.analog.com/ez-blogs/b/engineerzone-spotlight/post...
- pontifier 2y agoI like it. Seems like it might be useful for mice and keyboards as well. Have a few ports on it: This device can only be a mouse -> USB This device can only be a keyboard -> USB Then it filters everything coming in to ensure that it matches the desired type of activity. For USB drives, I'm tempted to say it should read the USB drive once, and copy all information to internal storage in order to prevent data being sent to the usb via timed or coordinated reads. This would allow a truly read only thumbdrive.
- divan 2y agoBack in a day I've made proof of concept of animated QR codes using fountain codes - txqr. [1] Since then I received a bunch of requests to make into an actual cross-platform app, but never could find the time for this hobby project. I guess I should revive this project and make an usable open-source app. https://divan.dev/posts/animatedqr/ https://divan.dev/posts/animatedqr/
- lozf 2y agoVery nice! Please count this as one more request for it.
- conradev 2y agobunnie is trying to solve this sort of problem with Precursor: https://www.bunniestudios.com/blog/2020/introducing-precursor/ https://www.bunniestudios.com/blog/2020/introducing-precurso... Any device without a screen is somewhat useless here, especially for crypto, because you want to see what you are signing before you sign it.