[117458] in Cypherpunks
Re: Project: Hardening Crypto Against Big Brother's "BlackBag"
daemon@ATHENA.MIT.EDU (Sunder)
Fri Sep 3 13:34:18 1999
Message-ID: <37CFF1DD.D848CDB1@brainlink.com>
Date: Fri, 03 Sep 1999 12:05:49 -0400
From: Sunder <sunder@brainlink.com>
MIME-Version: 1.0
To: pgut001@cs.auckland.ac.nz
CC: cypherpunks@cyberpass.net
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Reply-To: Sunder <sunder@brainlink.com>
Peter Gutmann wrote:
>
> The whole thing should be ready for prime time in a couple of months, all the
> source will be publicly available as usual so you can build the whole thing
> yourself. If anyone's interested in working on this, let me know - the
> "crypto in a physically isolated black box" bit is pretty much done, what's
> needed is someone to set up an appropriately configured and stripped-down
> Linux or *BSD kernel to run on the hardware (I know about projects like
> PicoBSD, but they don't quite fit the bill, and I don't really have the time
> to spend ages tweaking the config to get it just right).
>
> In case anyone's still reading, there's a paper and some slides on the general
> architecture (although there wasn't room to go into specific details like the
> paragraph above) available from my home page,
> http://www.cs.auckland.ac.nz/~pgut001/, at the end of the stuff under
> "Analysis and Design of Security Systems".
That's great and all, but there's still a big problem. If the PC is using
this device to do crypto (I don't care what the datalink/physical layers are
and thether the device to the PC), then the PC being something you can't
totally watch all the time becomes a point of contention as it receives the
data in the clear.
A simple {datalink layer} sniffer whether implemented in hardware or software
will be able to gain access to both the encrypted and freshly plaintexted
streams. A keyboard sniffer will still be able to get at your typed emails,
and a video sniffer will still be able to read what you read.
You still need to harden the host machine somewhat. Now to make things
hardware bug resitant, you could force yet another layer of encryption between
the PC and the device, so off the shelf spookware hardware sniffers won't
work, but if you cannot prevent hardware attacks, you can't ensure that your
OS is truly secure.
(I suppose you could add a keyboard interface to the crypto device and reroute
keyboard through that, but you'd have to carry your keyboard with you at all
times too.) :)
IMHO, there are too many holes in this. What's needed is a small, powerful,
almost handheld PC that never leaves your sight...
--
---------------------------- Kaos Keraunos Kybernetos --------------------
+ ^ + Sunder "The real aim of current policy is to /|\
\|/ sunder@brainlink.com ensure the continued effectiveness of /\|/\
<--*--> -------------------- OF US information warfare assets against\/|\/
/|\ You're on the air. individuals,businesses and governments \|/
+ v + Say 'Hi' to Echelon in Europe and elsewhere" -- Ross Anderson
---------------------------- http://www.sunder.net -----------------------
"The day that Microsoft makes a product that doesn't suck is the same day
they start making vacuum cleaners."