HNHacker News
TopNewBestAskShowJobs

talltower

92 karma · joined August 10, 2016

submissionscomments
talltower··on ORWL – The first open source, physically secure computer
We thought long and hard about the type of platform we want to use for this project. While the x86 platform has many shortcomings, it also provides a big ecosystem of OS and SW, as well as support. The fact that we have two subsystems, secure micro controller being in charge of supplying (and denying) power from the x86 gives us a lot of leverage and protection.
talltower··on ORWL – The first open source, physically secure computer
Yes, HSMs are very expensive and after talking to a few people in this industry we got the impression, some of the ORWL features are not present in HSMs. Like the ability to Geo-lock the device using the key (mounted in the ceiling). Waling away with the device will render it useless as the keyFOB is missing.
talltower··on ORWL – The first open source, physically secure computer
We currently have a Spec temperature of triggering a 'freezing event" at just above freezing Temperature 33-35F.
talltower··on ORWL – The first open source, physically secure computer
Thanks for the correction. I was not sure at the time.
talltower··on ORWL – The first open source, physically secure computer
The current Intel chipset we selected does only support RAM up to a max of 8GB. We heard the Qubes users loud and clear and the request for 16GB RAM. We will only be able to offer this in a next revision though.
talltower··on ORWL – The first open source, physically secure computer
We have built a list of hacks that we addressed and how. Please feel free to read up on all of these and more in our Product Description in the section "Potential attacks prevented" : https://www.orwl.org/wiki/index.php?title=File:ORWL_PRD_v0.6...
talltower··on ORWL – The first open source, physically secure computer
I respect your opinion on this. We sought to build hardware that is a significant step up from what is available on the market today in terms of access control and tamper protection. We also open source the BIOS and customize it the most we can afford to minimize the ME capability thanks to Eltan's help. Secure cannot be an absolute state, it can only be temporary... till the 1st one finds a way to get in. Execution of non-auditable code is what we deal with on nearly every machine on the market. We are minimizing this, while still staying compatible with peoples use models. We are as open and transparent as we can legally be. In our plan, this is only one step in the direction of taking back control of the machines we all are working on and want to trust completely. https://www.orwl.org/wiki/index.php?title=File:SowDESIGN-SHI...
talltower··on ORWL – The first open source, physically secure computer
Offline this SSD is protected with "AES 256-bit Encryption". Simple Brute force attempts would need WAY too long to make any sense. Does this answer your question?
talltower··on ORWL – The first open source, physically secure computer
Yes, physical access in most cases is a point of no GOOD return. That is why we emphasize so much on preventing this access. We have detailed the measures we have taken to prevent this here: https://www.orwl.org/wiki/index.php?title=File:ORWL_PRD_v0.6... Look at section: "ORWL Primary Key of Security or Root of Trust"
talltower··on ORWL – The first open source, physically secure computer
Yes, correct. We think we cover the cold boot vector. Here is a section from the product description. Security mesh physically protects DRAM from both freezing specific components and removal. Breaching the mesh will trigger reactive root key delete and system power down. Secure Microcontroller protects against chilling the full device - temps below -37℃ will trigger a tamper event, deleting root key and removing power from system. Link to the complete Product Description: https://www.orwl.org/wiki/index.php?title=File:ORWL_PRD_v0.6...
talltower··on ORWL – The first open source, physically secure computer
We are actually talking about this. Thanks for your interest.
talltower··on ORWL – The first open source, physically secure computer
Correction. The temperature monitor is INSIDE the secure shell.
talltower··on ORWL – The first open source, physically secure computer
The SSD encryption key will only be deleted in case of a tamper event, NOT when the unit is moved. Tamper events are: * freezing the unit * drilling the secure enclosure or other wise breaking the traces on it * prying the enclosure off the PCB So I don't think you have to be too worried about a false trigger of a key erasing.
talltower··on ORWL – The first open source, physically secure computer
Let me state a section of our product description here, detailing the way we are approaching the "Evil Maids" USB volume boot blocked at BIOS, BIOS access controlled by security key + PIN, Intel TPM is enabled, and we do not enter a passphrase to unlock encryption (unlike software based full disk encryption) In addition, attacks that don’t rely on booting to a USB device are protected by powering off the USB interface when the user keyfob is out of range More details here: https://www.orwl.org/wiki/index.php?title=Resources#Resource...
talltower··on ORWL – The first open source, physically secure computer
Thanks. We agree with your statement fully. We are raising the threshold of entry to your personal data substantially, but we are still far from perfection. We did a number of steps up in the security ladder. We are also taking steps to minimize ME abilities in ORWL. Our long term plan is to limit ME capabilities using the BIOS configuration. We just released the SOW of the 1st BIOS with Eltan on the WiKi. https://www.orwl.org/wiki/index.php?title=File%3ASowDESIGN-S... We are planning to investigate how to further limit ME capabilities with Eltan and we will update the SOW as we make progress. We also believe that the current secure micro controller implementation severely limit the ME capability through power management and the SSD key management.
talltower··on ORWL – The first open source, physically secure computer
ORWL will go in stand-by if the user is further than 10meters away from the device, if moved when away, it will shut down. If the hardware is tampered with, or chilled, the SSD encryption key is deleted within milliseconds. iPhone or any other consumer product at this point have less or no physical protection. The physical level of protection is taken from the payment industry standard and applied to the consumer device. The scanning of RAM content and possibilities of EM scanning, side channel attacks are all covered in the secure section of ORWL by the Maxim Secure controller. Nothing is impossible, but we tried to make it really really hard to get hold of the SSD encryption key and what we refer to as the Root of Trust. Qubes is really helpful with many other attack vectors.
talltower··on ORWL – The first open source, physically secure computer
Our long term plan is to limit ME capabilities using the BIOS configuration. We just released the SOW of the 1st BIOS with Eltan on the WiKi. https://www.orwl.org/wiki/index.php?title=File%3ASowDESIGN-S... We are planning to investigate how to further limit ME capabilities with Eltan and we will update the SOW as we make progress. We also believe that the current secure micro controller implementation severely limit the ME capability through power management and the SSD key management.
talltower··on The First Evil Maid-Proof Computer
This looks like an awesome product to protect sensitive data. Be it in the legal field, lawyers, ...