4 ms·
It isn't clear to me how this system is secure. Very little is actually said on the website beyond using the word "secure" and the usage of the tool "ssh" (whi
by theonewolf 13y ago
It isn't clear to me how this system is secure. Very little is actually said on the website beyond using the word "secure" and the usage of the tool "ssh" (which could have been maliciously tampered with or man-in-the-middled).
How exactly is data stored? Is the data stored encrypted should a device be stolen? Is it easy to "revoke" trust from devices storing parts of one's data?
Again, very little on the security of the overall system is actually described.
I hope the authors posted this or are here?
- yarou 13y agoPerhaps you could read the paper instead of being spoonfed by somebody?
- theonewolf 13y agoI was at the conference where they presented this. I'm actually in charge of the conference website (Wolfgang Richter, http://sigops.org/sosp/sosp13/cfp.html#pc http://sigops.org/sosp/sosp13/cfp.html#pc). At the conference, and in the paper title/abstract, it did not seem that _security_ was a focal point, or even a point, of their design. I understand already that they protect the _integrity_ of data---but I feel like that should be a given for any modern file system anyways. I am more specifically interested about the security of the file system in general. How does it secure data in a distributed setting? Is there anything new and cool there?
- wmf 13y agoOri's internal storage is very similar to git, so it's difficult to modify history without being detected. I think that's the main security claim they're making.
- theonewolf 13y agoRight, but data integrity doesn't equate to security in my mind. If that's the main security claim, than I feel that much isn't new here or even "secure."
- wmf 13y agoIMO security is the least interesting part of Ori. I think efficient syncing is the key feature.
- jperras 13y agoIf you read the paper, the security they are referring to is most likely that their data model is similar to git, using Merkle trees to ensure the integrity of files and their histories: > Our data model, like that of Git, forms a Merkle tree in which the Commit forms the root of the tree pointing to the root Tree object and previous Commit object(s). The root Tree object points to Blobs and other Tree ob- jects that are recursively encapsulated by a single hash. Ori supports signed commit objects, by signing the seri- alized Commit object with a public key. The Commit ob- ject is then serialized again with the key embedded into it, thus forcing subsequent signatures to encapsulate the full history with signatures. To verify the signature we recompute the hash of the Commit object omitting the signature and then verify it against the public key. The filesystem they describe has a few other very interesting features that paint it as a possible replacement for something like Dropbox, or even a network filesystem like NFS. You should check it out.
- theonewolf 13y agoData integrity is just a small part of security. I wouldn't even call that security at all. I mean, we technically shouldn't trust our HDDs and should do data integrity checking at every level. I'm interested in what they mean here by security, and what things they support beyond the normal integrity features of most modern file systems (zfs, btrfs).