Edit: Found it. https://stallman.org/stallman-computing.html
"As for microwave ovens and other appliances, if updating software is not a normal part of use of the device, then it is not a computer. In that case, I think the user need not take cognizance of whether the device contains a processor and software, or is built some other way. However, if it has an "update firmware" button, that means installing different software is a normal part of use, so it is a computer."
Straight from the big GNU's mouth.
> there is no need to reject hardware with nonfree designs on principle.
http://www.wired.com/2015/03/need-free-digital-hardware-desi...
That's not to say that there isn't value in open hardware, and certainly it's not a bad idea to advocate for open designs. It's just not part of the FSF's mission.
I also think open hardware would be pretty neat, but software people who get really upset about layers they can't verify implemented on top of layers they can't verify sound pretty silly. Either you verify from the bottom or you can't verify at all.
Bugs and vulnerabilities are discovered every day in the layers that can be independently verified. Your argument extends to every single piece of software everywhere that runs on Intel and AMD microprocessors, for instance. It's foolish to say that an OpenSSL instance shouldn't be examined because the network interface it communicates over uses a proprietary firmware blob, or runs on Windows, for instance.
I agree that the freedom to verify the behavior of (what amounts to) firmware is not one of the Four Freedoms, but there is a non-zero value in being able to find bugs and help the manufacturer improve the product, as well as being able to use that information to inform a purchasing decision. Especially for something which could potentially be considered to provide organizational security.
So 'curl ... | sudo -' is just fine now because we can't verify from the bottom, so there's no sense in verifying what we're piping to sudo?
I see your point that we do need to implicitly trust the company at some level, but what's upsetting is we want to encourage the widest possible audience to be able to "look in" and with closed-source change they've stepped backwards by decreasing the number of people who can casually [or pointedly] audit their devices and software.
It is more closed to me now.
Honestly I thought they were a company that cared more about providing the security we need rather than making a profit off intellectual property. I thought they understood the niche community they were providing for.
I can't [implicitly] trust this - not after having had better in the past.
You are kidding, right? Right?
Because, in principle, what you have said amounts to, "Open-source doesn't matter. Closed-source is just as good. Security by obscurity is valid and sensible." Or by real-world analogy, "I'm not a locksmith, so there's no point in having locks on my doors."
So, please tell me you are kidding...
I do agree that we need open hardware, but in practice that usually isn't available.
Edit: They seem to have a pretty even mix of open source a closed source enterprise partnerships. https://www.yubico.com/support/partners/
And it sounds like you can't update the code. So you don't have a way of verifying what the actual device runs. So people complaining about trust here are somewhat misguided when they say they don't want to trust Yubi. Open sourcing would only help find non malicious bugs. Since it sounds non modular there's possibly all sorts of stuff mixed in making it hard to audit so they decided it wasn't worth it.
Dunno if that's right but that's what it sounds like.
On the other hand, keeping the code closed does garner a lot of distrust.
1. This isn't exactly true; Yubico as a whole might be trustworthy but that doesn't mean individuals within the company can't slip in something that looks benign but breaks security, and slips past the other developers. Such vulnerabilities are documented even in open-source code[1].
2. Even non-malicious bugs can have security implications.
the original neo let you decide of the key/write to the neo, etc.
Thus they did not "disable it because of hardware", it is a choice of their, which they had already made for a year or two anyway.
There is one, big, obvious government-shaped reason.
I think this is a lazy broken heuristic that ends up labeling all social criticism and all allegations (even if credible) as "crazy." It's very Soviet-- you are mentally ill if you disagree with the government.
The problem is that we have hard documentation that governments (including but not limited to the USA) have run actual named and funded programs and efforts with the explicit intent of sabotaging crypto available in the public market. It's not even a "theory." It's established historical fact.
Believing the queen of England is a shape shifting reptile or that we didn't go to the Moon is a woo-woo conspiracy theory. Believing in things with a hard paper trail is not, nor is entertaining the possibility that governments might be doing things that we know for a fact they have done in the past.
It's not only a Soviet phenomena; American politics has utilized a "paranoid style"[1] for a long time.
> sabotaging crypto
It seems like a lot of people are pretending that BULLRUN doesn't exist. Nobody wants to believe that a coworker might be a collaborator; that kind of thinking can easily erode trust and create paranoia even when it isn't warranted. Unfortunately, the program exists so it's foolish to ignore the probability that it is still working to weaken crypto. As PHK explain in "Operation Orchestra", encouraging weak crypto is much cheaper than breaking real crypto.
[1] https://en.wikipedia.org/wiki/The_Paranoid_Style_in_American...
Nefarious: government is, I contend, only that group of criminals we have collectively decided we would be better to regulate and pay off. I'm not saying this is a bad thing, we certainly need some regulation and law enforcement, etc.
Diabolically clever: the word means 'characteristic of the devil' - government is responsible for torturing people, killing people in pointless wars, etc.
Cartoonishly inept: for sure! you only have to go outside, pick up a news paper, browse a news website, to see how incompetent government can be.
But, we tend to speak of 'government' as some cohesive whole, which it most certainly is not. Is any one branch or agency of government all three of those things at all time? I don't think so. Some parts of government do a fine job of administering their responsibilities, some of the time. Probably. Maybe.
> Cartoonishly inept
Can you name one medium to large (resources and headcount) organization that has existed for 20 years that could not be called cartoonishly inept by its detractors?The simplest scenario isn't that YubiKey 4 went closed source to support a government backdoor. It's that it's entirely for business reasons as they've said. And then after a few years, a few more layers of middle management, a few interesting users, and a little more TLA focus, Yubikey 6 quietly gets subverted.
Tangentially - I was pretty close to buying a Yubikey Neo for its form factor, but it didn't seem like I could modify/reload the OpenPGP applet, and documentation was scant as to how configurable it was. I really want the thing to operate as semi trusted hardware - passphrase, etc. Smartcard tech is nifty, but it seems like a non-hardened chip would be more worthwhile for the ability to iterate features/UI.
tptacek's positions hold outsized influence here, so even after his public concession on Dual_EC_DRBG, it's still very unpopular to posit that nation states would ever backdoor products.
No reason to complain about downvotes, per the rules.
Even then you have to extract the firmware from the device then try to match it with your compiled binary. Seems like you might as well just reverse the binary and look for backdoors directly?