9 ms·
More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too
by zimmerfrei 3y ago
More interestingly, Cavium (now Marvell) also designed and manufactured the HSMs which are used by the top cloud providers (such as AWS, GCP, possibly Azure too), to hold the most critical private keys:
https://www.prnewswire.com/news-releases/caviums-liquidsecurity-hsm-enables-hybrid-cloud-users-to-synchronize-keys-between-aws-cloudhsm-and-private-clouds-300631079.html https://www.prnewswire.com/news-releases/caviums-liquidsecur...
- api 3y agoIs there anyone here who actually thought cloud provider HSMs were secure against the provider itself or whatever nation state(s) have jurisdiction over it? It would never occur to me to even suspect that. I assume that anything I do in the cloud is absolutely transparent to the cloud provider unless it's running homomorphic encryption, which is still too slow and limited to do much that is useful. I would trust them to be secure against the average "hacker" though, so they do serve some purpose. If your threat model includes nation states then you should not be trusting cloud providers at all.
- enkid 3y agoIf your threat model includes the nation state where you physical infrastructure is, you're hosed.
- api 3y agoLiterally hosed. There's a funny jargon term "rubber hose cryptography" that's used to refer to the cryptanalysis method where you beat someone with a rubber hose until they give you the key. It's 100% effective against all forms of cryptography including even post-quantum algorithms.
- dmayle 3y agoThat's actually not true. It can do nothing about M of N cryptography. (That's when a key is broken up such that there are N parts, and at least M (less than N) are required to decrypt. It doesn't matter how many rubber hoses you have, one person can fully divulge or give access to their key and it's still safe.
- jacquesm 3y agoSure, so you hit all of the people that have all of the pieces. Problem solved.
- saalweachter 3y agoOr you publicly announce you're hitting 1 of the N people with the rubber hose until M-1 of the other people send you their key fragments. It's not like these keys are shared among disinterested strangers who have no attachment to each other.
- worthless-trash 3y agoSomehow, somewhere you've just influenced a megacorp's internal crypto process.
- kyleplum 3y agoThat situation just requires a longer hose
- gabereiser 3y agoand more beatings.
- snoman 3y agoOr M hoses.
- hn_version_0023 3y agoI always giggle a little when really smart people forget thugs exist and do what they’re told. If that includes breaking the knees of M people to get what they’re after, then M pairs of knees are gonna get destroyed. This isn’t hard to understand, but it’s easy to forget our civilization hangs by a thread more often than any of us care to admit.
- 3y ago
- ipaddr 3y agoYou would be surprised that for a percent this would not work. Some even like it. Some have a deathwish and want to be a martyr. Some people blow themselves up to further a cause. Also put under heavy stress memories of keys cannot be recalled at times. It's probably slightly less effective than threatening to kill family members but probably more than threat of jail time. Either way you require someone alive and with mental awareness. The mind reading tools found in science fiction hasn't been developed yet.
- jacquesm 3y agoWe're talking about normal people, not psychopaths.
- l33t7332273 3y agoTerrorists are generally highly altruistic, not psychopaths. It’s a lot easier to blow yourself up(or to spread ideology which encourages it)for a cause that you believe is helping people, in particular _your_ people.
- jacquesm 3y agoThe terrorists that blow themselves up and that blow other people up are usually misguided brainwashed angry young men. It's nothing to do with ideology, everything to do with power. Or did you think blowing up schools full of girls is something people genuinely believe helps their people, to give just one example? Ordinary people just want to be left alone. Old guys wishing for more power will use anything to get it, including sacrificing the younger generations.
- l33t7332273 3y ago> did you think blowing up schools full of girls is something people genuinely believe helps their people It absolutely is something that they think helps their people, yes.
- aborsy 3y agoThis would not work well, because you can’t do it in a secret manner. Overuse of the rubber hose cryptography will become known, and there will be public backlash.
- eastbound 3y agoSeems like the NSA is threatening everyone of arrest (=state-organized violence) if they don’t secretly give them keys, and Snowden revealed it, and there is no public backlash.
- amluto 3y agoHose-resistant cryptography is possible. Secret sharing comes to mind, or a system by which even the principals can only compromise a key slowly.
- vasco 3y agoI mean in the end everything is people just like Logan Roy said in Succession. Cryptography or any software protections are the same. It's a great quote that is very true: > "Oh, yes... The law? The law is people. And people is politics. And I can handle of people."
- outworlder 3y ago> If your threat model includes the nation state where you physical infrastructure is, you're hosed. True. But even if you trust your nation state 100%, having a backdoor means you now have to worry about it falling into the wrong hands.
- jacquesm 3y agoEven if you trust your nation state 100% having a backdoor means it has already fallen into the wrong hands. That's because 'nation state' is not synonymous with 'people running the nation state'.
- PeterStuer 3y agoAddendum: if your threat model includes any nation state that has significant ties to the nation state that hosts your physical or transit infrastructure, you're hosed.
- Obscurity4340 3y agoHow might this apply or what are the implications of Signal given its US jurisdiction?
- Natanael_L 3y agoSignal relies on the client program to not be compromised to keep conversations secret
- lmm 3y agoThe US authorities can make the same orders that they made with LavaBit (i.e. ordering them to produce a backdoored build and replace yours with it), and they can make them secretly. Given that Signal by design requires you to use it with auto-update enabled (and, notably, goes to some effort to take down ways of using it without auto-update), and has no real verification of those auto-updated builds, I would consider it foolish to rely on the secrecy of Signal if your threat model includes the US authorities or anyone who might be able to call in a favour with them.
- wildfire 3y agoHow odd. I have, and continue, to use Signal without auto-update enabled. I have been prompted, twice in three years to update though. Perhaps the requirement depends on your country?
- Obscurity4340 3y agoYa, does it do that thing banking apps do where it insists on the most recent version in order to even be usable? Otherwise, thats more of an iOS option that can be easily altered Settings < App Store < Automatic Downloads > App Updates
- jacquesm 3y agoLots of people believe that. They believe truthfully you can get to the level of AWS, MS, Google, Facebook or Apple whilst standing up to the nations that host those companies. I've walked into government employees in the hallways of tiny ISPs, I see no reason to believe at all that larger companies are any different except for when easier backdoors have been installed.
- luxuryballs 3y agoI always just tell people to lookup “Lavabit” to learn everything you need to know.
- byteknight 3y agoTo save others a goog: https://en.wikipedia.org/wiki/Lavabit https://en.wikipedia.org/wiki/Lavabit > Lavabit is an open-source encrypted webmail service, founded in 2004. The service suspended its operations on August 8, 2013 after the U.S. Federal Government ordered it to turn over its Secure Sockets Layer (SSL) private keys, in order to allow the government to spy on Edward Snowden's email
- rvba 3y ago> He also wrote that in addition to being denied a hearing about the warrant to obtain Lavabit's user information, he was held in contempt of court. The appellate court denied his appeal due to no objection, however, he wrote that because there had been no hearing, no objection could have been raised. His contempt of court charge was also upheld on the ground that it was not disputed; similarly, he was unable to dispute the charge because there had been no hearing to do it in. Land of the free...
- pyinstallwoes 3y agoThat’s scary
- BlueTemplar 3y ago
- numbsafari 3y agoI believe this is why the government of Singapore appears to fund a lot of work on homomorphic encryption. Even when you are a nation state, you still have to worry about other nation states.
- arter4 3y agoEspecially when you are a nation state.
- wsc981 3y agoI feel the same and Snowden kinda said as much regarding phones. To assume each phone is compromised by state level actors.
- TheRealDunkirk 3y agoI mean, there's a reason that the government was involved with setting up the first cell networks. No assumptions need to be involved. They ARE all compromised.
- RF_Savage 3y agoLawful intercept has always existed in phone networks. Just that one cannot use that in non-allied nations.
- TheRealDunkirk 3y agoYou’re missing the point. It was designed to be transparent to interception efforts up front, so you can’t tell if you’re being surveilled, lawfully or not.
- RF_Savage 3y agoFor analog Gen0 and Gen1 networks I'd make the claim that it was just as much about technical limitations of the era. But for 2G export crypto it definitely was about keeping it weak enough to break on demand.
- bowmessage 3y agoSee the Cryptographic Control Over Data Access [0] section here for one answer to this problem. [0] https://cloud.google.com/blog/products/identity-security/new-sovereign-controls-for-gcp-via-assured-workloads https://cloud.google.com/blog/products/identity-security/new...
- BlueTemplar 3y agoThat's nice, but the only reasons that public clients would use a well known bad actor from a rogue state is laziness / incompetence.
- ipaddr 3y agoThe cloud act ensures this
- dclowd9901 3y agoI think there’s such a thing as plausible deniability here. We didn’t know for certain so we weren’t culpable, but now that it’s public record, we really have to do something about it or risk liability with our customer data.
- lokar 3y agoCloud HSM services have always been understood as a convenience with limited real world security, without even considering nation state threats.
- TheRealDunkirk 3y ago> If your threat model includes... At my Fortune 250, our threat model apparently includes -- rather conveniently and coincidentally -- everything! Well, everything they make an off-the-shelf product for, anyway. It makes new purchasing decisions easy: "Does your product make any thing, in any way, more secure?" "Uh... Yes?" "You son of a bitch. We're in. Roll it out everywhere. Now."
- Macha 3y agoAhh, I've been there. I'm sure no concern is given for usability of the result. Welding your vault shut may make it harder for thieves to break in, but if your business model requires making deposits and withdrawals, it's somewhat less helpful.
- lazide 3y agoLuckily, all but tiny portion of security products have a door you can open if you ask support nicely enough you didn’t know about before. So you can still get your stuff after you weld the door shut.
- calgoo 3y agoAnd then when there is a security issue you ask them share the log files from all their spyware and suddenly half the stuff needed is not there because we did not get that module.
- lazide 3y agoOr ‘oh, that feature hasn’t been rolled out yet, expect it in 6 quarters.’.
- hiatus 3y agoThere's no thought given to if the cost to secure the thing outweighs the risk of exposure?
- deleted 3y ago[deleted]
- amenghra 3y agoYou don't need to think about this in a binary fashion. You can split your trust across multiple entities. Different clouds, different countries, or a mix of cloud and data centers you own.
- johnklos 3y agoIt's interesting to consider the people who, with the very same set of facts, come to completely opposite conclusions about security. For instance, Amazon has a staff of thousands or tens of thousands. To me, that means they can't possibly have a good grasp on internal security, that there's no way to know if and when data has been accessed improperly, et cetera. To others, the fact that they're a mega-huge company means they have security people, security processes and procedures, and they are therefore even more secure than smaller companies. For one of the two groups, the generalized uncertainty of the small company is greater than the generalized uncertainty of the large. For the other, the size of the large makes certain things inevitable, where the security of smaller companies obviously depends on which companies we're talking about and the people involved. More often than not, people want to generalize about small companies but wouldn't apply the same criteria to larger companies like Amazon. There's a huge emotional component in this, which I think salespeople excel at exploiting. It fascinates me, even though it's a never-ending source of frustration.
- joezydeco 3y agoAyup. We use AWS CloudHSM to hold our private signing keys for deploying field upgrades to our hardware. And when we break the CI scripts I see Cavium in the AWS logs. Now I gotta take this to our security team and figure out what to do.
- supriyo-biswas 3y agoI'd be surprised if you get anything more than generic statements about how they take security very seriously and they are open to suggestions, but avoid addressing the mentioned concerns directly (and this applies to all cloud providers out there, not just AWS). I'm sure a few others here would like to see their response as well.
- joezydeco 3y agoWe've had other issues with our CloudHSM instance, especially with the PKCS1.5 deprecation on January 1. And their support has been pretty dismal. Not expecting much from them at this point.
- baz00 3y agoAWS support is pretty fucking terrible generally. We’re a very high rolling enterprise customer and it’s pretty obvious that some of their shit is being managed by two guys in a shed somewhere who don’t talk to each other.
- BlueTemplar 3y ago[flagged]
- milesward 3y agoNot Google..
- zimmerfrei 3y agoCertainly Google (and Oracle and AWS): https://www.marvell.com/company/newsroom/marvell-enables-enterprise-data-center-and-private-cloud-security-with-innovative-liquidsecurity-network-hsm.html https://www.marvell.com/company/newsroom/marvell-enables-ent...
- progbits 3y agoI'm not saying you are wrong but I can make a website which claims some cloud provider uses my hardware too. Their website is irrelevant. Do we have a Google (or AWS/...) page regarding this?
- iancarroll 3y ago> Note: Currently, all Cloud HSM devices are manufactured by Marvell (formerly Cavium). "Cavium" and "HSM manufacturer" are currently interchangeable in this topic. https://cloud.google.com/kms/docs/attest-key https://cloud.google.com/kms/docs/attest-key
- progbits 3y agoThanks. Also, not great, hope the hyperscalers can diversify this.
- amluto 3y ago…which is really weird. At least Google and Microsoft are quite outspoken about their in-house secure element technology. If nothing else, at Google/Amazon scale, I’d be concerned about a third-party HSM losing data.
- tgsovlerkhgsel 3y agoIn-house stuff is for security. HSMs are mainly for compliance, where a customer needs to check a regulatory box, because some rules says you must use a HSM. The more standard it is, the easier it is to demonstrate to the auditor that you've checked the box.
- jhallenworld 3y agoIt's not surprising because who wants to make their own FIPS 140-2 level 3 compliant key store device? Also, the Cavium one was the fastest one on the market the last time I looked at this. Thales, Safenet and IBM also had them..
- amluto 3y agoGoogle? Titan appears to meet FIPS 140-2 level 1. I find the levels bizarre. Chromebooks are highly exposed to physical attack. Keys in the cloud are not nearly as exposed. Yet people seem okay with level 1 for chromebooks but apparently want level 3 in the cloud? I’d rather see a level 1 or level 2 auditable cloud solution, with at least source available.
- fireflash38 3y agoLevel 1 is pretty easy to meet IIRC. It's 2-4 that are hard, with pretty much no Level 4 certified ones on market I believe?
- jhallenworld 3y agoThe IBM one for z was level 4 I think.. Yes: https://www.ibm.com/docs/en/cryptocards?topic=4768-overview https://www.ibm.com/docs/en/cryptocards?topic=4768-overview
- pyinstallwoes 3y agoThis breeds the familiar scenario where a group will start saying the link between the two is so clear that there must be a connection. Then you’ll get another group calling the first group conspiracy theorists, and say it’s just a coincidence of probability. Narrative control and information modeling is so powerful it’s scary.
- jacquesm 3y agoPost Snowden the first group has some formidable ammunition.
- pyinstallwoes 3y agoNow apply that to every other "conspiracy.."
- jacquesm 3y agoThat's not how this works. Plenty of conspiracies are just that: idiots pretending they have special knowledge or that believe that behind everything that doesn't quite mesh with their worldview there is someone pulling invisible strings. Those people have a mental issue. The big trick is to be able to tell the two apart, not to categorically assume that because some conspiracies that had a whole bunch of evidence to go with them turned out to be true that all conspiracies, even those that have no evidence to go with them are true as well. That's just faulty logic.
- sdiupIGPWEfh 3y agoNow get yourself some half-decent psyops and contaminate the first group with supporting voices that emphasize weaker evidence, use poor logic, name-drop socially questionable sources, and go out of their way to sound ridiculous.
- pyinstallwoes 3y agoBingo
- deleted 3y ago[deleted]