https://softwareengineering.stackexchange.com/a/145633
>Also answers by the zlib guy
https://stackoverflow.com/a/20765054
https://stackoverflow.com/users/1180620/mark-adler
>the nagle algorithm guy
GP has months (at least) of comments, and they're not vacuous. (Unless they're all copied from elsewhere too, but there aren't replies identifying that, and I'm not going to dig into it. :))
I'm sure some of my own comments could also be misconstrued as 'fake comments' applying to virtually any submission!
This is rent-seeking on market segmentation. Certain government agencies and contractors are prohibited by law from using a bog standard USB storage device, and require this FIPS certified thing instead. The manufacturers know this. They also have budget to pay, when they are forced to.
This garbage just adds yet another link to the critical chain.
Oh, and now you have full plain text access over the (unencrypted and unauthenticated) USB bus. Hope you put as much effort into vetting your USB hubs!
There is no reason, imho, why we shouldn't strive to "encrypt all the things", including buses, so that data is guaranteed to be available only to fully-trusted chains. This should obviously be configurable by administrators, with destruction guarantees when options are relaxed. This will not be for everyone (and yes, it will likely always be weak against the $5-wrench attack), but for people who really need it (like deployed troops, whose default opsec practices are typically too lax to be left to humans).
Remarkably he even hypothesizes the solution that they almost certainly are using here, without realizing how trivial it is:
> Guess: maybe there are tiny wires in the casing and an "intrusion detection" chip with its own battery that is never powered off so that it can monitor for breakage of the wires and trigger a wipe?
This is very likely what they are doing. And it's both simple and cheap to manufacture and implement at scale. Basically the inner-side of the metal casing is conductive and etched to be a big wire looping around the device, forming a circuit. Any attempt to drill or decase it will break the circuit and trigger a wipe. The wipe itself is done by a small 16-bit microcontroller powered off a watch battery or large capacitor. All the parts cost less than a dollar, and the case etching machine is something a company like Kingston would have on hand for other purposes.
At my last job we had to roll our own physical security solution for protecting keys because the off-the-shelf FIPS level 3 stuff was so brain-dead stupid and easy to defeat that it didn't meat our security needs.
That's just off the top of my head.
But to your point, at Level 3 it most likely means any normal attempt to open the case or rewrite the firmware would irretrievably destroy the device or wipe the encryption keys.
Flash freezing a device or drilling is likely to have this effect since some of the epoxy housing should be made to crack and sever specific connection triggering the wipe before all of the heat is conducted away from the inner components. Same for using solvents, acids, or radiation which may be more of a Level 4 compliance.
As for the power constant components (whether they are at L3 or L4), they may or may not be used. It may very well be part of the asking price.
Apple's T2 chip is FIPS 140-2 compliant and you can be certain a lot of money was invested in making it secure yet it was still jailbroken.
* Vials of fluoroantimonic acid affixed to the device with slabs of C4 and high voltage tripwires?
Have you considered contacting NIST to get certified? You could get in on the action.
In my experience with the government, a waiver is probably possible though. But none of our customers were demanding FIPS certification.
Now, that same device is also NSA Type-1 ... which is not an official cert and damn near impossible. Took me and my sales lead 8 months just to find a military officer willing to sponsor.
We already met FIPS 2, it took some reworking for FIPS 3, and Type 1 actually isn't too bad, it's the networking your way into the NSA (and a sponsor) and them giving you the time of day. Many of our Customer contacts LOVED the product, but were not appropriate sponsors and their intros just always went cold.
The best part of the story is when we finally got a phone number to someones desk at the NSA and I just cold called it. "Hello...", "Hi [my intro]", "[silence]"... lol
Having been involved in the FIPS-140 certification process I know first hand it is both slow and expensive.
It is fair to say that the general consumer version shouldn't shoulder the burden of this cost, and the market for this product is small.
Therefore, the 'unreasonable' price likely isn't that ridiculous.
This is nothing new. So why hasn't another manufacturer done at much cheaper prices in those these years?
As for encrypting: Hiding pictures from your wife is a lot different than hiding corporate or state secrets from Russia and China.