Titan in depth: Security in plaintext
cloudplatform.googleblog.com
cloudplatform.googleblog.com
"...Titan cryptographically associates the log messages with successive values of a secure monotonic counter maintained by Titan, and signs these associations with its private key. This binding of log messages with secure monotonic counter values ensures that audit logs cannot be altered or deleted without detection, even by insiders with root access to the relevant machine."
What would be the process for verifying that the chip itself has not been compromised during manufacture?
Is this a hardware + software verification combo, so a tainted chip would not be recognized as valid by the software - so you'd need to compromise both to bypass?
There are various extra design and production steps I'd go through for crypto verification and test, but it would be difficult to fake a chip if they allow verification after SMT on the PCB. After that, physical access and fairly sophisticated methods could bypass it, but you're already trusting TehGoog... so NoSuchAgency shouldn't be your concern.
Which is focused on attacking an FPGA, however the general idea of injecting hard to detect hardware via the tools themselves is a real problem.
sharps.org/wp-content/uploads/BECKER-CHES.pdf
EDIT: example company that does this: http://velocityelec.com/
I am curious about a couple of things:
Assuming you use Intel chips, how do you manage to trust the firmware/ME from them? Do you write your own BIOS to ensure that it is safe? Or do you use ARM/PowerPC/other ISA and have an entirely open source stack?
Does the Titan assume no phyiscal access? And if you do assume someone could steal the chip/try to reverse engineer the chip, do you have anything in it to stop an adversery? I would wonder if there would be a private/nation state agency would want access to certain secrets so bad that they would try to alter it physically, rather then through root access.
Edit: See [0] where Titan was first briefly introduced earlier this year, for an image of it attached to one of our custom networking cards.
[0] https://www.blog.google/topics/google-cloud/bolstering-secur...
https://twitter.com/jbeda/status/715373975182807040
Will you convince Niels to publish a paper?
re: Niels paper, out of my control.
Can I serve a different firmware image after the verification goes through and the PCH starts loading the flash? :)
your name reminds to IBM. Is Titan your internal weapon against the NSA?
"Neither Amazon.com nor Microsoft - which hold 41 percent and 13 percent of cloud market share, respectively, according to Synergy Research Group - have said if they have similar features."
The caption reads, "Photograph of Titan up-close on a printed circuit board", which is unfortunately untrue:
https://1.bp.blogspot.com/-027iovJ94yk/WZ8ZDw4MNvI/AAAAAAAAE...
Why earrings? See the Titan announce video[0].
In addition, traditional secure boot doesn't give us a hardware root of trust, nor does it enable tamper-evident logging.
National Security Letters can be challenged in court. You fight legal attacks with legal defenses. You fight technical attacks with technical defenses. Although swapping them does give rise to some interesting techniques. Legally challenging technical attacks can be tricky due to jurisdiction, but it would be cool if Google could at least try suing the countries that attacked them. Technical defenses against legal attacks can also sometimes work, by building systems where the company themselves don't have access, such as E2E crypto.
[^1]: https://techcrunch.com/2015/04/18/on-the-war-on-general-purp...
But Titan doesn't really have that problem. Google owns the computers, and Google can make the computers do what they want because they have the signing keys.
If Titan-controlled devices were sold to consumers with no way to disable it, that would be a problem.