https://www.prnewswire.com/news-releases/caviums-liquidsecur...
https://www.prnewswire.com/news-releases/caviums-liquidsecur...
Now I gotta take this to our security team and figure out what to do.
I'm sure a few others here would like to see their response as well.
I was a Linux Sysadmin for a decade. They initially hired me to work on the "BigData" support team
Then after hiring threw me into CI/CD instead. I told them I don't know python or ruby and would be a terrible fit
I asked if I can join the Linux team. EC2 is bread and butter, that's easy stuff
"Oh we're actually shutting that team down soon. I'll move you into containers instead"
Spoiler: they didn't "shut down" the Linux group
I'm pretty aware of how painful it can be to configure AWS well, IAM roles, the overly large eco-system that we won't need and unmitigated complexity to configure it all. It's not comforting to think Azure is worse yet.
The Azure Resource Manager system is much easier to use than the fragmented mess that is AWS.
The problem with Azure is that they’re still catching up to AWS. They have fewer products and the quality is worse.
Really basic issues will remain unaddressed for years.
It confused me when researching it.
The Intel Management Engine always runs as long as the motherboard is
receiving power, even when the computer is turned off. This issue can be
mitigated with deployment of a hardware device, which is able to disconnect
mains power.
Intel's main competitor AMD has incorporated the equivalent AMD Secure
Technology (formally called Platform Security Processor) in virtually all of
its post-2013 CPUs.
https://en.wikipedia.org/wiki/Intel_Management_Engine Ylian Saint-Hilaire, principal Engineer working on remote management software
including hardware manageability:
https://youtu.be/1seNMSamtxM?feature=sharedHardware wise nothing changed, it’s just even harder for the actual owner of the hardware to use the legitimate management features while presumably easier for whoever could illegitimately abuse them.
I mean, you are already in US-based cloud, so if NSA is interested, they will just request information directly, no backdoors needed.
(This is a good test for your security team, btw: if they say anything other that "we do nothing", you know its all security theater)
Ironically, the data we're securing is because of US government requirements. So if the government wants to spy on itself, who are we to say?
you wouldn’t be cynical if you didn’t care, or felt able to do anything about it.
It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful.
I would trust them to be secure against the average "hacker" though, so they do serve some purpose. If your threat model includes nation states then you should not be trusting cloud providers at all.
Also how Yahoo first refused but was forced to comply by the Foreign Intelligence Surveillance Court of Review.
https://www.electrospaces.net/2014/04/what-is-known-about-ns...
(Note that supposedly, "the companies prefer installing their own monitoring capabilities to their networks and servers, instead of allowing the FBI to plug in government-controlled equipment.")
The underlying architectures of our systems are not secure and much of the abstractions built on top of them make that insecurity worse, not better.
For nation state level issues, the solution likely isn’t technical, that is a game of whack-a-mole, it will take a nation deciding that digital intrusions are as or more dangerous than physical ones and to draw a line in the sand. The issue is every nation is doing it and doesn’t want to cut off their own access.
> Lavabit is an open-source encrypted webmail service, founded in 2004. The service suspended its operations on August 8, 2013 after the U.S. Federal Government ordered it to turn over its Secure Sockets Layer (SSL) private keys, in order to allow the government to spy on Edward Snowden's email
Land of the free...
At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy:
"Does your product make any thing, in any way, more secure?"
"Uh... Yes?"
"You son of a bitch. We're in. Roll it out everywhere. Now."
Not to mention they may be another Crypto AG.
Much more frequently than that if you lump 'anti virus software' in with security products.
They gave me a laptop with 8gb of ram. The laptop runs invisible security software that nominally takes 6~6.8gb.
We just got penetrated by two attackers in the last 40 days.
* that you know of
Welding your vault shut may make it harder for thieves to break in, but if your business model requires making deposits and withdrawals, it's somewhat less helpful.
For instance, Amazon has a staff of thousands or tens of thousands. To me, that means they can't possibly have a good grasp on internal security, that there's no way to know if and when data has been accessed improperly, et cetera. To others, the fact that they're a mega-huge company means they have security people, security processes and procedures, and they are therefore even more secure than smaller companies.
For one of the two groups, the generalized uncertainty of the small company is greater than the generalized uncertainty of the large. For the other, the size of the large makes certain things inevitable, where the security of smaller companies obviously depends on which companies we're talking about and the people involved. More often than not, people want to generalize about small companies but wouldn't apply the same criteria to larger companies like Amazon.
There's a huge emotional component in this, which I think salespeople excel at exploiting.
It fascinates me, even though it's a never-ending source of frustration.
True. But even if you trust your nation state 100%, having a backdoor means you now have to worry about it falling into the wrong hands.
It's probably slightly less effective than threatening to kill family members but probably more than threat of jail time.
Either way you require someone alive and with mental awareness. The mind reading tools found in science fiction hasn't been developed yet.
It’s a lot easier to blow yourself up(or to spread ideology which encourages it)for a cause that you believe is helping people, in particular _your_ people.
Ordinary people just want to be left alone. Old guys wishing for more power will use anything to get it, including sacrificing the younger generations.
It absolutely is something that they think helps their people, yes.
Beliefs stop when they are no longer about yourself but about how other people should live. Especially when those other people loudly protest that this is how you think they should be living. Killing them is just murder, not the spreading of ideas.
But hey, those human rights are just for decoration anyway.
I don’t understand why you said “no” before this; I believe this agreed with what I’m saying.
https://en.wikipedia.org/wiki/Psychopathy#Signs_and_symptoms
The 'traditional order of society' is a society run by psycho pathological individuals and benefits nobody except for those individuals.
But you already knew that, didn't you?
1. Not everybody shares your values.
2. People who don't share your values are not necessarily brainwashed.
3. People may do things that are irrational under your system of values, but rational under their own.
And BTW, there is no a single fighting force in the world that doesn't have old men persuading young men to sign up and risk throwing away their lives. There's not a whole lot of difference between regular soldiers persuaded to participate in a forlorn hope or banzai charge attacking a defended position and a suicide bomber or kamikaze.
I think it clearly is.
This isn’t hard to understand, but it’s easy to forget our civilization hangs by a thread more often than any of us care to admit.
can't torture us all!
(Including a system of people.)
Even nation state adversaries don’t have infinite resources to allocate for all opponents.
Why do you think governments are demanding those services give them access to quickly remove "misinformation"?
Which is a much much higher bar to clear for any would be rubber hose attackers.
Bob, Jon, and Tom have pieces of the key. Bob and Jon are in the US and arrested over and commanded by a court to give up the key. Tom is the holdout. The US will issue an international arrest warrant, and now Tom can never safely fly again or the plane will be diverted to the nearest US friendly airport where they will be extradited. So, yea, "safe" is very situational here.
That's the actual weak link to attack.
It's not like these keys are shared among disinterested strangers who have no attachment to each other.
> "Oh, yes... The law? The law is people. And people is politics. And I can handle of people."
mixing the two implicates humans for the errors of machines
edit:
unless failure to disable autocorrect is counted as a user error
I have been prompted, twice in three years to update though.
Perhaps the requirement depends on your country?
Otherwise, thats more of an iOS option that can be easily altered
Settings < App Store < Automatic Downloads > App Updates
It's not stored very securely either. I wouldn't doubt that three letter agencies have an attack that lets them access the data, but even if they didn't they can just brute force a pin to get whatever they need.
https://community.signalusers.org/t/proper-secure-value-secu...
Even when you are a nation state, you still have to worry about other nation states.
But for 2G export crypto it definitely was about keeping it weak enough to break on demand.
[0] https://cloud.google.com/blog/products/identity-security/new...
Narrative control and information modeling is so powerful it’s scary.
If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.
Also, the Cavium one was the fastest one on the market the last time I looked at this. Thales, Safenet and IBM also had them..
I find the levels bizarre. Chromebooks are highly exposed to physical attack. Keys in the cloud are not nearly as exposed. Yet people seem okay with level 1 for chromebooks but apparently want level 3 in the cloud?
I’d rather see a level 1 or level 2 auditable cloud solution, with at least source available.
Yes: https://www.ibm.com/docs/en/cryptocards?topic=4768-overview
If I wanted to store an important long term key in a secure facility, I would worry, first and foremost, about software attacks, attacks doable over a network, malicious firmware attacks, and maybe passively observed side channel attacks. Physical attacks would be a rather distant second.
The adversary will show up and badge in just like everyone else. They might have worked there for 20 years, or they might be an outside repair person or external consultant.
They will definitely fit in. They're supposed to be there.
It will be the most normal thing in the world. And you may never know their real purpose.
Now if someone evil-maid attacks the HSM itself, that’s a different story. Any good HSM should resist this, especially one found in a portable device. And this is because you can steal an entire important corporate laptop or other portable device without necessarily raising an quick alarm, whereas I have trouble imagining someone walking off with the HSM out of an IBM mainframe or with an AWS HSM without the loss being noticed immediately.
(To be fair, in the mainframe case, some crusty corporations seem to have a remarkable ability to fail to notice obvious crypto problems like their public facing certificates expiring. But a loss of an entire HSM from a secure large cloud datacenter will, at the very least, immediately trigger “elevated failure rates” or whatever they like to call it…)
It depends who is the attacker. There are countries (western democracies) where the police regularly "visits" datacenters.
And tech support is horrible, incompetent.
And low power alarms may well be a variation on that theme. Glitching the power supply has been a tool in the arsenal of reverse engineers for a long time so that sort of sensitivity may well make sense. Voltage spikes and drops can be very short, short enough for you not to see them on a DVM but on a memory scope with a trigger value set much lower than you might expect they'd show up with alarming regularity in some hardware that I've worked on. And that explained some pretty weird instability issues. Good power is rare enough that really sensitive hardware usually has power conditioning circuitry right up close to the consumer.
No. I said I've been in touch with technical support, and the manuals, docs, and their support is clear. It should not be wiping, it has a backuo battery too.
We've spent hours and hours testing, to validate the issue, and cause.
They likely have a firmware bug, or bad board design. And we've seen this from cards from different batches, bought years apart.
Their support is incompetent, and I say that with 30+ years of dealing with, and providing tech support. They fail to read tickets, and even spend (supposedly) weeks running tests, while ignoring vital data in tickets, and conveyed in support calls.
They. Are. Incompetent.
In terms of "issues with power", no. Not over dozens of servers, in different datacentres, and even just with the card at rest, out of server, on battery.
Understand, their job is to provide stable. HSM cards are useless, if they randomly wipe when in use, while under power "just cause".
I find it weird that you're playing devil's advocate here, describing how hard this is, this is an enterprise grade card, and people have been making reliable, and safe HSMs for decades.
The problem is 100% them, their desogn.
And even more so, their incompetent tech support.
Did I mention their tech support is incompetent?
I'm not so much playing devils advocate as that I'm aware how hard making such devices is and the difference between 'user error' and 'incompetent staff/faulty product' can be hard to distinguish in a comment.
https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-faq-bas...
HSMs are mainly for compliance, where a customer needs to check a regulatory box, because some rules says you must use a HSM. The more standard it is, the easier it is to demonstrate to the auditor that you've checked the box.
https://www.marvell.com/company/newsroom/marvell-enables-ent...
Also, not great, hope the hyperscalers can diversify this.