← Back to context

Comment by octoberfranklin

13 hours ago

There will always be an arms race between safe-crackers and safe-builders.

This is dismissive and glib. And it's the wrong lesson.

You wouldn't say this about symmetric cryptography. AES-encrypted ciphertexts from 25 years ago are still secure today, and nothing on the horizon is likely to change that. No arms race.

The "arms race" exists because the security model for trusted hardware is intrinsically flawed. If the attacker has physical posession of the device, your security is transient and at the mercy of the arms race. So stop doing this! Trusted hardware also has extremely negative externalities on the whole computing ecosystem.

(*) or 45 years, if you exclude cryptosystems (56bit single-DES) used only because of silly export laws.

I tend to agree that there are issues in the realm of hardware token based security but they largely lie in the failure modes, with substantially increased difficulty of recovery.

For the average user these approaches make data loss MUCH more likely simply because you need a corporate IT department level of competency to consistently avoid data loss with them.

The glib exaggeration of this is that in not being permitted to manage and back up your own keys you actually create the situation where you have to hire someone to extract your keys for you and break into the device you own because of the failings of the technology!

> This is dismissive and glib.

As is your comment.

> And it's the wrong lesson.

It's only the wrong lesson if you believe that making it more difficult for governments to seize and decrypt their own citizens' mobile phones with impunity is not a valid goal.

> the security model for trusted hardware is intrinsically flawed.

It's only intrinsically flawed if you expect absolute perfection.

The fact that some math-based protections may be theoretically better than physical protections does not obviate the utility of physical protections, whether we are discussing computers or phones, or houses or cars.

It has been accepted since before any of us were born that there is no such thing as perfect physical security. Even your putative perfect cryptographic security still relies on the physical security of the plant holding the keys.

  • If you think trusted computing is a defense against nation-state attackers, we inhabit totally different realities.

    • > If you think trusted computing is a defense against nation-state attackers, we inhabit totally different realities.

      I have no idea how or why you would think I think this, since what I wrote was exactly the opposite of this, e.g. "It's only intrinsically flawed if you expect absolute perfection" and "It has been accepted since before any of us were born that there is no such thing as perfect physical security."

      In any case, if you think that every piece of information that ordinary humans want to protect is worth it for nation-states to waste their million-dollar attacks on, we inhabit totally different realities.

      And yet, there are many pieces of information that ordinary humans want to protect that many nation states would easily throw thousands of dollars at.

      In other words, the fundamentals behind security are the same as it ever was.