Bitcoin Forum
May 02, 2024, 02:29:33 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: “We cannot trust” Intel and Via’s chip-based crypto, FreeBSD developers say  (Read 1720 times)
Wilikon (OP)
Legendary
*
Offline Offline

Activity: 1176
Merit: 1001


minds.com/Wilikon


View Profile
December 14, 2013, 02:35:53 AM
 #1

http://arstechnica.com/security/2013/12/we-cannot-trust-intel-and-vias-chip-based-crypto-freebsd-developers-say/


Developers of the FreeBSD operating system will no longer allow users to trust processors manufactured by Intel and Via Technologies as the sole source of random numbers needed to generate cryptographic keys that can't easily be cracked by government spies and other adversaries.

The change, which will be effective in the upcoming FreeBSD version 10.0, comes three months after secret documents leaked by former National Security Agency (NSA) subcontractor Edward Snowden said the US spy agency was able to decode vast swaths of the Internet's encrypted traffic. Among other ways, The New York Times, Pro Publica, and The Guardian reported in September, the NSA and its British counterpart defeat encryption technologies by working with chipmakers to insert backdoors, or cryptographic weaknesses, in their products.

The revelations are having a direct effect on the way FreeBSD will use hardware-based random number generators to seed the data used to ensure cryptographic systems can't be easily broken by adversaries. Specifically, "RDRAND" and "Padlock"—RNGs provided by Intel and Via respectively—will no longer be the sources FreeBSD uses to directly feed random numbers into the /dev/random engine used to generate random data in Unix-based operating systems. Instead, it will be possible to use the pseudo random output of RDRAND and Padlock to seed /dev/random only after it has passed through a separate RNG algorithm known as "Yarrow." Yarrow, in turn, will add further entropy to the data to ensure intentional backdoors, or unpatched weaknesses, in the hardware generators can't be used by adversaries to predict their output.

"For 10, we are going to backtrack and remove RDRAND and Padlock backends and feed them into Yarrow instead of delivering their output directly to /dev/random," FreeBSD developers said. "It will still be possible to access hardware random number generators, that is, RDRAND, Padlock etc., directly by inline assembly or by using OpenSSL from userland, if required, but we cannot trust them any more."

In separate meeting minutes, developers specifically invoked Snowden's name when discussing the change.

"Edward Snowdon [sic] -- v. high probability of backdoors in some (HW) RNGs," the notes read, referring to hardware RNGs. Then, alluding to the Dual EC_DRBG RNG forged by the National Institute of Standards and Technology and said to contain an NSA-engineered backdoor, the notes read: "Including elliptic curve generator included in NIST. rdrand in ivbridge not implemented by Intel... Cannot trust HW RNGs to provide good entropy directly. (rdrand implemented in microcode. Intel will add opcode to go directly to HW.) This means partial revert of some work on rdrand and padlock."

RNGs are one of the most important ingredients in any secure cryptographic system. They are akin to the dice shakers used in board games that ensure the full range of randomness is contained in each roll. If adversaries can reduce the amount of entropy an RNG produces or devise a way to predict some of its output, they can frequently devise ways to crack the keys needed to decrypt an otherwise unreadable message. A weakness in the /dev/random engine found in Google's Android operating system, for instance, was the root cause of a critical exploit that recently allowed thieves to pilfer bitcoins out of a user's digital wallet. RDRAND is the source of random data provided by Ivy Bridge and later versions of Intel processors. Padlock seeds random data in chips made by Via.

While the FreeBSD developers discussing the change cited allegations of backdoors raised in documents leaked by Snowden, the move would have been a good idea even if those weaknesses never came to light. Adding additional sources of randomness to RDRAND, Padlock, and other RNGs will not reduce their entropy and may make the keys they help generate harder to crack. Relying on multiple sources of randomness is a good practice and possibly could have helped prevent recently discovered crippling weaknesses in Taiwan's secure digital ID system.
"This isn't the kind of software where we can leave so many unresolved bugs that we need a tracker for them." -- Satoshi
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
pedrog
Legendary
*
Offline Offline

Activity: 2786
Merit: 1031



View Profile
December 14, 2013, 02:54:26 AM
 #2

Fuck yeah FOSS!!!11

pand70
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile
December 14, 2013, 03:31:18 AM
 #3

I wonder how hard is for engineers to tear a chip apart and find out if indeed there is some backdoor of any kind  Huh

Wilikon (OP)
Legendary
*
Offline Offline

Activity: 1176
Merit: 1001


minds.com/Wilikon


View Profile
December 14, 2013, 04:00:22 AM
 #4

I wonder how hard is for engineers to tear a chip apart and find out if indeed there is some backdoor of any kind  Huh

I don't know how you can check for back doors on a chip but google is not taking any chances (for other goals) http://www.forbes.com/sites/timworstall/2013/12/13/google-could-design-its-own-chips-based-on-the-arm-architecture/
stompix
Legendary
*
Offline Offline

Activity: 2884
Merit: 6283


Blackjack.fun


View Profile
December 14, 2013, 05:30:14 AM
 #5

There are some real concerns about this stuff , but since the Snowden episode , also lots and lots of paranoia.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Wilikon (OP)
Legendary
*
Offline Offline

Activity: 1176
Merit: 1001


minds.com/Wilikon


View Profile
December 14, 2013, 06:01:52 AM
 #6

There are some real concerns about this stuff , but since the Snowden episode , also lots and lots of paranoia.

So you mean all those documents stolen from the nsa are paranoia and made up things?
stompix
Legendary
*
Offline Offline

Activity: 2884
Merit: 6283


Blackjack.fun


View Profile
December 14, 2013, 06:13:17 AM
 #7

There are some real concerns about this stuff , but since the Snowden episode , also lots and lots of paranoia.

So you mean all those documents stolen from the nsa are paranoia and made up things?

Not all , but most of them are miss interpreted , let's  have some big news , NSA is spying your microwave Smiley

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
pand70
Sr. Member
****
Offline Offline

Activity: 476
Merit: 250



View Profile
December 14, 2013, 07:10:50 AM
 #8

I wonder how hard is for engineers to tear a chip apart and find out if indeed there is some backdoor of any kind  Huh

I don't know how you can check for back doors on a chip but google is not taking any chances (for other goals) http://www.forbes.com/sites/timworstall/2013/12/13/google-could-design-its-own-chips-based-on-the-arm-architecture/

Yes but i don't think that google thinks to enter the cpu business because of the possible rnd problems. On top of that even if they design their own chip they are not going to produce them themselves. As the article states it will be probably samsung or some other company.

Wilikon (OP)
Legendary
*
Offline Offline

Activity: 1176
Merit: 1001


minds.com/Wilikon


View Profile
December 15, 2013, 12:53:31 AM
 #9

There are some real concerns about this stuff , but since the Snowden episode , also lots and lots of paranoia.

So you mean all those documents stolen from the nsa are paranoia and made up things?

Not all , but most of them are miss interpreted , let's  have some big news , NSA is spying your microwave Smiley

How about the NSA giving amnesty to Snowden? Would this be big news?

Snowden still has 1.7 million docs. NSA considering amnesty.
http://www.cbsnews.com/news/nsa-leaders-split-on-giving-amnesty-to-snowden/
peta4e
Hero Member
*****
Offline Offline

Activity: 672
Merit: 500



View Profile
December 15, 2013, 11:33:48 AM
 #10

This not surprising shit from Intel/VIA for me. Congrats to the FreeBSD team : ))
cryptasm
Legendary
*
Offline Offline

Activity: 997
Merit: 1002


Gamdom.com


View Profile WWW
December 15, 2013, 03:18:27 PM
 #11

Not all , but most of them are miss interpreted , let's  have some big news , NSA is spying your microwave Smiley
I like the fact that only 1% of the Snowden files have been released so far, plenty more revelations on the way  Grin
zedicus
Legendary
*
Offline Offline

Activity: 966
Merit: 1004

CryptoTalk.Org - Get Paid for every Post!


View Profile WWW
December 16, 2013, 04:21:55 AM
 #12

FreeBSD!

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!