3 ms·
OTOH, it allows you to implement secure vaults for your personal and most important data. It all depends on how access to these privileged interfaces is manage
by eecc 2y ago
OTOH, it allows you to implement secure vaults for your personal and most important data.
It all depends on how access to these privileged interfaces is managed.
- ulrikrasmussen 2y agoYes, the technology is not inherently evil, but some applications of it are. We shouldn't put bans on the tech, but we should put bans on usages of it which takes away personal freedom. Using it to implement secure vaults for your personal data is a way to actually improve personal security, and I can get behind that. Using it to prevent software from even running on your device claims to improve personal security, but actually it is mainly about asserting control over you. Yes, it improves security as a side effect, but it does so by taking away your freedom.
- nonrandomstring 2y ago> a way to actually improve personal security, I'm not sure this is true. I've studied trust models in some depth now and I think that cryptographic enclaves are at best an analgesic and sedative. Don't fall for any myth of symmetrical technology that can be used "for evil or good". The purpose of this technology is to assert logical ownership over computation under remote physical control of another. That would serve your interests and rights iff you purchase a cloud computing resource you want to make secure in an untrustworthy data-centre. Sadly "security" gets used as a bare noun. One must always ask three questions: - security for who? - security against who or what? - security to what end? DRM is a generally a net loss to security of the physical machine owner, since it is a way to hide code and functionality within the perimeter of ownership and control. It's no worse than blobs or treacherous silicon, but any security conscious operator should avoid or remove it. It is opaque "security" for vendors/content-publishers, and "security" against the owner and operator.
- ulrikrasmussen 2y agoI think it makes sense in very narrow use cases such as hardware security modules for key management, giving the user a somewhat strong guarantee that there is a one-to-one correspondence between control of the key and physical ownership of the HSM. This is an example where limitations of what you can do with the hardware is the primary feature of the hardware and the reason the user acquired it in the first place. It is analogous to physical locks being hard to pick by design. Any use of enclaves for DRM are unethical though, and solutions such as Play Integrity API is a commingling of security guarantees and totalitarian control over the user. Instead of proving to a service provider (such as your bank) that your whole phone is running a verified software and hardware stack, it suffices to communicate with a HSM with which you verify that the transaction to be authorized (1) comes from your bank, and (2) has a description which aligns with what you expect. The HSM can be built into the phone or be an external device with a small screen, but it should never ever enforce how you use the rest of the phone, it should only solve the narrow security issue of authorizing critical transactions.
- miki123211 2y ago> cryptographic enclaves are at best an analgesic and sedative Cryptographic enclaves let you securely use passwords that are otherwise very easy to break. For example, a random 4-digit pin can be broken in seconds, minutes at most, even with really strong PKDF functions. With a cryptographic enclave that destroys your key after 10 unsuccessful attempts, attackers only have a 0.1% chance of breaking that PIN. This is an acceptable security level for many users. In theory, better security than that is possible by using a complex passphrase. In practice, the passphrase ends up being "exampleDotOrgWinter25!", which is still very easy to brute force. For many users, that random 4-digit PIN plus an enclave will end up being more secure than the long and complex password.
- nonrandomstring 2y agoLocal-only memory (say readable only from a certain CPU security ring and securely erasable in an atomic operation) is a useful tool for methods such as you describe. What I'm shooting at is private memory under cryptographic control of a remote networked entity. I should more properly have said "remotely secured enclave" or something like that. I think in this area it's hard to be precise amidst confusion about who does the encryption, who generates and keeps the private keys, and what power that affords them.
- josephcsible 2y ago> Yes, the technology is not inherently evil, but some applications of it are. We shouldn't put bans on the tech, but we should put bans on usages of it which takes away personal freedom. IMO, any technology that can be used to take control of devices away from their owners is inherently evil and should be banned outright, even if there are other uses of it that would be legitimate.
- surajrmal 2y agoNot a single device you own gives you full control. If you have a wifi or LTE modem attached to your device, chances are it runs some firmware you cannot override for legal reasons as you would be at risk of breaking some laws by doing so. It feels like folks draw the line based on what runs on the primary CPU (in particular the kernel), but this is strangely arbitrary. There are all sorts of technologies that will slowly make this appear to work while simply shrinking what you are capable of doing from the kernel you run (eg trustzone, hypervisors you don't control, etc). From the perspective of hardware makers this is just more firmware which everyone is already seemingly okay with. There are too many (non drm even) forces in the industry pushing us in this direction as it solves seemingly real problems (anti-cheat in games, ensuring your bank credentials and biometric data cannot be stolen, work accounts cannot be compromised, etc). There is simply too much risk and therefore money to be lost by giving users control over these things.
- josephcsible 2y ago> chances are it runs some firmware you cannot override for legal reasons as you would be at risk of breaking some laws by doing so. I don't want things I own to try to enforce laws against me. > There is simply too much risk and therefore money to be lost by giving users control over these things. I know the megacorps will never want to give us control of our stuff. I'm saying that I wish they had to.
- luma 2y agoI could also have it show me one set of data on my secured machine, but a completely different filesystem + data if stolen and run on some other system, or booted under duress, etc. This seems like a neat feature for some weird use cases.
- Gigachad 2y agoWhy would that be implemented by the SSD rather than the OS? I can't see any realistic reasoning for this but DRM.
- miki123211 2y agoTo prevent disk cloning. A typical attack scenario here would be something like: 1. You leave your laptop in a hotel room. 2. Criminals / police break in and clone the drive. 3. They install a (physical) keylogger between your keyboard and the rest of the computer. 4. You return, turn the computer on and enter your password, which the keylogger transmits to your attackers. They now have both the drive contents and the password needed to decrypt them. You can mitigate this by using a TPM and storing the key there instead of deriving it from the password, but even then, an attacker is able to clone the drive first and get the key later. With this feature on, you can't clone the drive until you get that key.
- Gigachad 2y agoThis seems like such a contrived scenario. If the police want your info, they just request it from all the tech companies. If they want something on your laptop, they will just arrest you and have you unlock it. They aren't action movie style disassembling your laptop and installing a key logger on the keyboard ribbon cable. They would need a custom one for every laptop and you could hardly fit something with wireless capabilities in there. When the $5 wrench works fine.
- eecc 2y agoBut if the data is encrypted in the drive they can't either, unless the tech company has deployed a backdoor in their trusted software stack. In this scenario you're somewhat more protected, because the attack vector is just the vendor backdoor rather than the panoply of RCE infesting modern systems, and one would hope that access to the backdoor is closely regulated by laws and judicial oversight. It all goes out of the window (pun intended) when your foe is a soverein actor but let's be honest, all we really want is a decent lock for our front-door.