Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> the weak link is reduced to my ability to aduit it (combined with everyone else who's auditing it as well and might publish their findings).

And if the hardware itself has microcode that overrides your code?

> but this is ridiculous. Do you really think that the Yubikey folks have backdoored my copy of gcc?

Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious device that changed its behavior such that it now leaks information and does not provide actual security."

Because those kinds of attacks actually exist. Ultimately, what you're arguing for is the pleasure and moral superiority of being able to do that audit. Not only does that audit not give you many guarantees, but giving you the ability to do that audit opens you up to much more sinister attacks.



>And if the hardware itself has microcode that overrides your code?

Hard to defend against this, but it can be helped by using well understood architectures and letting us confirm that the microcode being run is the same microcode that the upstream CPU vendors are publishing.

>Actually, I think the first and foremest threat would be, "Could someone insert a yubikey into a malicious device that changed its behavior such that it now leaks information and does not provide actual security."

I'm not going to keep entertaining this discussion if you keep disregarding everything I've already said. I've already said I'm only asking for read-only access. In any case, defending against physical compromise is close to impossible anyway.


> if you keep disregarding everything I've already said. I've already said I'm only asking for read-only access.

And I've addressed that.

> In any case, defending against physical compromise is close to impossible anyway.

This is a non-statement. I think your religion is getting in the way of further discussion. Goodbye.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: