Why is Google selling potentially compromised Chinese security keys?
zdnet.com
zdnet.com
All this will eventually lead to a point where the CCP has to appease its citizens for the crashing economy. Either it will choose to subdue its own people - either with more police state, lockdowns, or jailing, and do so for the next 10-20 years while the bad debts slowly gets resolved (ala Japan), or it will choose to redirect its focus abroad (ala Germany 1930) and starts to aggressively expanding and taking over countries as puppet states (which it is already doing now with various African states and Southeast countries) or use its growing military to attack nearby countries (Taiwan, Vietnam)
That makes the (cyber)defenses against China even more important today. Thus we have US/Australia banning Huawei and ZTE, and Japan is thinking about banning them as well from the network. The free, democratic countries of the world are starting to realize how dangerous giving China backdoors into the networks is.
We need to monitor all our security breaches that exposes us to Chinese cyber espionages, so we can prevent theft of important technologies.
Western countries are actually starting to imitate that system, because it allows for a somewhat peaceful submission of society at low living standards.
Exactly how does a Feitian key differ from a Google one? Where is the SoC produced? How secure is the enclave equivalent and that bit which produces the private key? What is the chain of trust?
I don't trust the UK or US governments, but why on earth would I trust China?
Uh, German data protection laws, yadda yadda - they didn't stop the police from raiding several activist non profit organizations a couple of months ago, with no repercussions.
The "US jurisdiction"-line is just tiresome and weak. Show me the country that guards user data that isn't part of 5 eyes and where attempts of the state to gain access to said data is actually penalized.
How exactly do you expect anyone to backdoor these devices?
For U2F, the first thing that comes to mind is timing channels, or perhaps building in a radio and letting anyone nearby use the key as if it were theirs.
If I we're the paranoid type, I'd avoid bluetooth security keys all together. NFC should be fine for use with a mobile phone, and while there are attacks that let you read NFC from a few meters away, if you credibly think you have an adversary who can identify you in public, and has this type of specialized hardware, you're dealing with someone who would have a much easier time just throwing you in the back of a van to extract whatever they wanted out of you.
https://pwnaccelerator.github.io/2018/webusb-yubico-disclosu...
https://www.imperialviolet.org/2017/10/08/securitykeytest.ht...
The second one is (more) interesting, IMHO. The entries on how most of the keys have some defect or other are worth reading, since mostly nobody is looking at this stuff.
The relevant paragraph on Feitian:
Feitian ePass
ASN.1 DER is designed to be a “distinguished” encoding, i.e. there should be a unique serialisation for a given value and all other representations are invalid. As such, numbers are supposed to be encoded minimally, with no leading zeros (unless necessary to make a number positive). Feitian doesn't get that right with this security key: numbers that start with 9 leading zero bits have an invalid zero byte at the beginning. Presumably, numbers starting with 17 zero bits have two invalid zero bytes at the beginning and so on, but I wasn't able to press the button enough times to get such an example. Thus something like one in 256 signatures produced by this security key are invalid.
Also, the final eight bytes of the key handle seem to be superfluous: you can change them to whatever value you like and the security key doesn't care. That is not immediately a problem, but it does beg the question: if they're not being used, what are they?
Lastly, the padding data in USB packets isn't zeroed. However, it's obviously just the previous contents of the transmit buffer, so there's nothing sensitive getting leaked.
I don't see anything in the U2F FIDO spec that can prevent that.
People in the UK are sent directly to a chinese online store which means at that point Google has no control over anything anymore.