Edit: heh, that's funny, you edited your comment as I was replying? Now we just need someone to build it for us :)
Edit: heh, that's funny, you edited your comment as I was replying? Now we just need someone to build it for us :)
When Bitcoin hardware wallets were first getting developed, I wondered why people didn't just start with open, barebones commodity hardware like you've described. Well, I suppose one reason may be that it may not exist, but it seems like it should be pretty cheap to pay some low-end Android manufacturer to remove a few features from their design. Or maybe you even buy "normal" hardware and strip out radios. At some level, the wallet manufacturers are all trusting someone, as I don't think any have designed their own low-level components. Anyway, maybe I will revisit that idea to see if a suitable locked-down, easy-to-hack, super-cheap device is available, as I agree that cutting all unnecessary comms is a good idea.
You're very very unlikely going to want to type a truly secure (= long) password over and over and over, which you'd need to do in a situation where the browser's password manager is turned off, and/or a website disables password caching anyway.
The Palm m5xx series could solve this problem: it had full USB, and I once read of an Palm app (like any other) that bridged the m5xx's SD slot to behave like a block device over USB, ie it turned the Palm into a USB SD card reader. That means there's a raw USB SDK out there, and adding HID keyboard support wouldn't be too hard (no kernel driver development etc).
Getting passwords into the device would be nontrivial; Palm keyboards are proprietary to the series they were made for, with a few arbitrary connector updates thrown in for good measure (think iPhone docking connector saga). If the password is irritating enough to repeatedly type on a full keyboard, it would take you a good 5 minutes (and a punching bag, for afterwards) to get it into the PDA, Graffiti and custom keyboards taken into account.
I think it would work out though: if the only way to get data out of the device is to tap something on its screen, that should be enough of a brick wall to dissuade would-be attackers.
I guess I'm responding to this so enthusiastically because it's about Palm :P - I unfortunately never owned one of these awesome little things, but I'd love something of similar capabilities built using today's tech. With modern advances in power consumption, like MemoryLCD, micropower CPUs, short-range bluetooth, etc, the result would probably last literally weeks. It'd be enormous fun to hack on, too, and carve out a little niche for itself. :)
I wonder if I should Ask HN if this would be a good idea.
3. Ask HN ask HN: Should I ask HN if a Palm Pilot keyboard would be a good password manager?
1 point by i336_ 1 minute ago | flag | past | web | discussAlso, to clarify - and I should've qualified what I meant, but tiredness is such an unhelpful thing at times - this is a genuinely interesting-sounding idea (as I noted to the other reply at this comment depth), but the paragraph at the bottom was kind of an independent thing.
I've always wanted to tinker around with a handheld, reasonably nice-looking device with similar specs to a Palm. Sort of like the TI watch (http://processors.wiki.ti.com/index.php/EZ430-Chronos), but a PDA equivalent.
Although... I just started thinking about the possibility of using a microcontroller that had a tiny bit of internal, non-reprogrammable ROM, so I could implement a secure stage-0 loader... lol
In other news, I just placed an order for the parts for my prototype, so I'll be putting that together this weekend. Fun thing: If done correctly, it should work with most android phones, as they do understand usb hid keyboards. As a result, final design may end up with a very small lithium battery to allow it to run when connected to a phone that doesn't offer much power. I'll put a blog somewhere and post an update to https://twitter.com/andy_leap as I work on it.
The firmware that's written to the chip is padded out to (sizeof(flash)-X) with cryptographicly secure random bytes, where X is the size of a crypto signature block, which you use to sign the firmware. When you plug the thing into a computer without the sd card inserted(I plan on storing the password vault on an sd card, correctly encrypted), it dumps all of the flash via keyboard. Pipe that into a program that verifies the signature, via whatever means, and you can ensure the firmware has not been tampered short of hardware modification in the form of adding more flash memory/eeprom, as to do so would require compressing the existing code/cryptgraphically secure padding, as you would need to dump the original out to pass the verification. If you want to be even more secure, you can even replace the existing signature with your own, therefore ensuring that people can't change the version without access to your private key.
I suppose if you can do full USB, you can probably get data in somehow.