Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Open Source Hardware Hacking Privacy Security Hardware

The World's Most Secure Home Computer Reaches Crowdfunding Goal (pcworld.com) 126

"If the PC is tampered with, it will trigger an alert and erase the PC's encryption key, making the data totally inaccessible." Last month Design SHIFT began crowdfunding an elaborate "open source, physically secure personal computer" named ORWL (after George Orwell). "Having exceeded its $25,000 funding goal on Crowd Supply, the super-secure PC is in production," reports PC World, in an article shared by Slashdot reader ogcricket about the device which tries to anticipate every possible attack: The encryption key to the drive is stored on a security microcontroller instead of the drive... The ORWL's makers say the wire mesh itself is constantly monitored... Any attempts to trick, bypass, or short the wire mesh will cause the encryption key to be deleted. The unit's security processor also monitors movement, and a user can select a setting that will wipe or lock down the PC's data if it is moved to another location... The RAM is soldered to the motherboard and can't be easily removed to be read elsewhere...

Your ORWL unlocks by using a secure NFC and Bluetooth LE keyfob. Pressing it against the top of the ORWL and entering a password authenticates the user. Once the user has been authenticated, Bluetooth LE is then ensures that the user is always nearby. Walk away, and the ORWL will lock.

This discussion has been archived. No new comments can be posted.

The World's Most Secure Home Computer Reaches Crowdfunding Goal

Comments Filter:
  • by damn_registrars ( 1103043 ) <damn.registrars@gmail.com> on Saturday September 17, 2016 @12:39PM (#52907919) Homepage Journal
    They can't really expect to hold on to that title when they are willing to send it out with Windows 10 preinstalled.
    • Holy shit, they come with Windows 10? All the good will that the video I just saw generated in me, has been removed in one fell swoop. Screw Windows 10, screw Microsoft and screw any computer that comes with Windows 10 preinstalled.

      • To be fair, they offer it with multiple OS choices; Windows 10 just happens to be one of them. You can opt for a less-terribly-insecure OS if you want. I just find it comical that they present it as secure when Windows 10 is an option - particularly considering how many Windows users are always logging in as administrator (admittedly some without even realizing it).
        • I bet a Raspberry Pi with some obscure BSD mutation would be safer, and for much less money, too.
          • by archi1 ( 4713085 )
            does not compare in performances. This is much much more powerful. 4k video, Wifi AC dual band, full x86 compatibility, SSD drive... check the spec this is another level of performances. Product spec and datasheet are here : https://www.orwl.org/wiki/inde... [orwl.org]
            • Have you ever heard of the law of diminishing returns? What do you achieve with 40 GIPS in personal computing that you can't achieve with 10 GIPS? Now it would be nice to have, say, something A73-based with better IO, but hardly at the cost of making the system as baroque as the current PC world is. Security-wise, that's a disaster.
    • by lgw ( 121541 )

      Does Ubuntu still send your local searches back to the mothership? Do we know what other lines they've crossed? I only feel secure about the BSDs these days.

      Anyway, we know there is NSA gear to deal with this: unless the keyboard is inside a Faraday cage, they can log your keystrokes. Unless the monitor is inside a Faraday cage, and you have no windows (or Windows) they can see your monitor. And Bluetooth? Forget about it.

      If any TLA is actually worried about these, they'll be intercepted in shipment (o

      • by Orgasmatron ( 8103 ) on Saturday September 17, 2016 @04:03PM (#52908525)

        The headline is crap. The linked article is better, and the wiki [orwl.org] has more details. This is a physically secure computer, not generally. The goal is that when you unlock it, it should either be in the same state it was in when you locked it earlier, or it should be obvious to you that it is not.

        It has no ethernet or wifi (nor, for that matter any busses capable of reading memory by DMA), but you can add them with USB3, which gets disconnected when you lock it. The case is designed with very little room between the security shell and the glass or plastic case, making it very difficult to add things without you noticing. Opening the secure shell inside wipes the drive encryption keys, so you'll notice if someone does that. And when you first get it, you can open it up to inspect the insides to make sure that nothing was added before it gets to you.

        This would be ideal for running a small Certification Authority, for example. The signing key would be well protected inside the shell without you having to wear it on a USB stick around your neck for the rest of your life. Ditto a bitcoin wallet.

        But it isn't, nor was it intended to, let you run Windows fresh off the DVD while you browse porn sites in IE and download warez off of shady torrent sites without antivirus.

        • by lgw ( 121541 )

          Well, maybe I can buy their "99.9%" secure - it'll be safe from the neighbor's kid, I guess. Seems like they're trying to make something FIPS 140-2 level 3, but without certification it's just another homebrewed security device, and those have a very poor history of actual security.

          • We are planning for FIPS review and have gone through the 1st review process with Penumbra already. Collecting their inputs and tweaking the design.
            • by lgw ( 121541 )

              It will do wonders for credibility, as well as making it clear to the knowledgeable what the point of the device is.

        • I don't see how this would protect a bitcoin wallet since it would self destruct taking all of your money with it. I guess if you had redundant systems spread all over the place it would be ok but it's hard to maintain an offsite system and keep it powered and running perfectly.

          • Since bitcoin is irrevokable, it couldn't be the sole copy of any keys in use. You would still need to either print/burn copies of the keys generated inside it for secure storage, or you'd need to generate them elsewhere and import them.

            The advantage here is that you'd only need to do that once per tamper, instead of every time you wanted to use it.

            The keys to the root CA certificate in my other example might be like that too, or it might not, depending on how hard it is for you to push out new certs. A s

        • One thing I'm puzzled about is how they're going to build this for $25K in funding. I've worked on highly-secure computing devices and $25K was the down payment on the FIPS eval, not the development budget. OK, I realise FIPS is a waste of money so it doesn't make for a good benchmark, but you still can't get much engineering out of $25K, particularly not the specialised stuff they're doing.
          • You are correct, It will take much more that $25k to get all this done, it took much more than that to get to where we are today. We have working prototypes today that we use to finish the development. The Crowd Supply campaign for us is to get attention and get a number of devices into peoples hands, to play and develop on them before anyone else at a lower cost than retail later.
            • Oh cool, a developer. Do you have a means for people to submit what-about-X attack questions? Your Security section is a bit too incomplete for me :-). For example it looks like the tamper mesh only covers the two shells that surround the circuit board, what if I penetrate the side of the circuit board, inject PU foam under pressure to lock the switches, and then separate the halves? What if I use a targeted magnetic field to lock the switches? What if I use oil-well perforators to knock out the switch
        • To clarify, ORWL has WiFi and Bluetooth connectivity that is accessible to the OS, Ethernet you can get through RJ-45. There is NFC and another BT available only to the secure element for authentication purposes. Out of Box, you will need to go through 1st authorization process, that verifies that the device has not been tampered with and you receive what we sent. Exactly.
          • Sorry, I must've missed those on the specs. I see the wifi now, on the electrical design page, but still don't see ethernet.

        • Need to clarify! >>a setting that will wipe or lock down the PC's data if it is moved to another location... So, if there's a bug in the security program, or in the operating system, or in the sensors, it wipes your data. >> I think there is a misunderstanding in which events trigger a loss of all SSD data. any tampering with the device HW, like drilling the protective shell (not the glass), prying the shells off the PCB, freezing the pcb+components, the backup battery runs low on juice (after
        • by Reziac ( 43301 ) *

          Friend's dad worked for NASA and his offsite PC was the Cold War version of this gadget: a laptop with RAM but no HD, everything loaded from tape every day. Idea was if it got lost or stolen, there was no data left.

    • Does this computer have the option of PC-BS... er, TrueOS?
    • by Anonymous Coward

      What are you talking about?!?! Windows 10 is the MOST secure OS to date. If any hacker breaches your system he or she is bound to commit suicide within 2 minutes of using its ass ugly GUI.

    • You can select QubesOS too or Ubuntu.
    • They can't really expect to hold on to that title when they are willing to send it out with Windows 10 preinstalled.

      Agreed.

      Building the world's strongest front door is an exercise in futility when you leave the fucking Window open.

      Literally.

    • by mlts ( 1038732 )

      At least it can ship with Ubuntu by default. If W10 is needed, it can be run under VMWare, VirtualBox, or one's virtualization utility of choice. That way, Windows 10 can be run, but it is isolated from the hardware.

      As for options, I would go with the M7, 480GB SSD, and glass case. One can't argue with a beefier CPU (assuming cooling isn't an issue), and more disk space. The glass case is useful for tamper resistance.

      My only wish is if the device had a port for a Kensington lock slot, with some mechanis

  • Earthquake (Score:2, Funny)

    by fox171171 ( 1425329 )

    The unit's security processor also monitors movement, and a user can select a setting that will wipe or lock down the PC's data if it is moved to another location...

    Might want to set it to be fairly insensitive if you live in an area likely to have earthquakes.

  • What is the market for this?

    • by Anonymous Coward

      Up to DOS 6.22.

    • This is marketed to paranoid dummies who don't realize that they will irrevocably lose all their data if someone chills it with a spray can of freon. Or stick it in the office freezer.

      The microcontroller in the ORWL monitors temperatures and any drastic change can trigger an alert and nuke the encryption key.

      Or just microwave it. That should really go over well with the mesh screen. Also, powering down the USB ports isn't going to save the machine - a good wack of 120v will fry the port anyway, and again, the machine will go "omg - time to self destruct."

      • So anyone actually using this for real work will need a script backing up data every 10 second to somewhere... insecure. I remain uninspired by the product definition.

      • by Jeremi ( 14640 )

        Aw, c'mon, you're not being nearly cynical enough. This is actually an NSA/KGB/TLA/Illuminati honeypot -- they fund this, market it, see who buys one, then they know who to watch in the future. If they can sneak some actual backdoors into it, so much the better, but even if they don't, it's served its purpose.

  • The VIC-20 in a box in my garage.
    And yes, it actually still works.
    • No one should need more than 5k RAM.

      • by AJWM ( 19027 )

        Well, 3.5k if you were using BASIC.

        But you could get an expansion memory cartridge (fit the same slot as the game cartridge). I got an 8 k one and soldered in 4 more 2k (static) RAM chips to bring it up to 16k. Luxury!

        • I'm a young whippersnapper so the C-64 is what I had 1st. I wondered what the actual available RAM was on those things. My Commodore had 38k available using BASIC. I always felt like the VIC-20 guys got screwed over by not waiting on the C-64 but no one can tell the future.

  • by the_humeister ( 922869 ) on Saturday September 17, 2016 @01:14PM (#52907993)

    It's using Intel's Skylake processor. That requires a chipset that has IME on it, unless they were able to strike a deal with Intel and make their own chipset without IME, which is not likely.

    • by Anonymous Coward

      While all the *PHYSICAL* technical measures are excellent, they make a gross presumption about the security of the electronics inside. Electronics which are running firmware which due to the lack of public scrutiny and method of replacement could easily be used to backdoor this device and exfiltrate the security keys and/or believed secure data from the device whether or not the device was authenticated, or be used to disable the aforementioned security measures before they could inactive the contents of th

    • by ffkom ( 3519199 )
      Indeed, using Intel CPUs and MicroSoft software, you can be sure that your data is "secure" only in the sense of being backed up by all kinds of government agencies using the backdoors built into these CPUs and Windows.
      • by AHuxley ( 892839 )
        Thats why projects like the Lemote Yeeloong laptop got interest. Been understood down to the hardware level was very important e.g. building on a a free software boot loader.
        Free software laptops (Dec 18, 2009)
        https://www.fsf.org/bulletin/2... [fsf.org]
    • by AmiMoJo ( 196126 )

      The IME can only be accessed via Ethernet or USB. It doesn't have the former and the latter is physically disabled (data lines disconnected) when the machine is locked. So there is no way to exploit the IME externally.

      Software security is your own problem and outside the scope of what they are doing, but no one is forcing you to connect it to the network.

  • by Striek ( 1811980 ) on Saturday September 17, 2016 @01:16PM (#52908001)

    It's an interesting concept, but it goes too far... it would be trivially easy to have this thing delete the encryption key - just shake it around a bit and it, and all its data, become useless. The risk of data loss when using this "secure" computer would be so high, even by accident, that you'd need a backup close by somewhere.

    So anytime someone is seen with a computer this secure, just target their backups instead. Considering the relatively high likelihood of accidntal erasure, they're sure to have them.

    Besides, although the data stored on this is extremely secure, it isn't very available. It's opens up a huge attack surface by making it far to easy to destroy the data on this thing, limiting its effectiveness and market considerably.

    • by Striek ( 1811980 )

      And hell, you don't even need an evil maid to ruin your day. You turn that setting on, and then a maid picks the thing up to dust the desk. Poof!

    • So anytime someone is seen with a computer this secure, just target their backups instead. Considering the relatively high likelihood of accidntal erasure, they're sure to have them.

      The classic example is the bank with impenetrable security. Just kidnap the manager's daughter and you have free access everywhere in the bank. There's always another way.

    • I have used this computer for weeks without any problems whatsoever. I wouldn't worry one bit about data loss. Mark my wor#$Ã(+#NO CARRIER

    • I think there is a misunderstanding in which events trigger a loss of all SSD data. any tampering with the device HW, like drilling the protective shell (not the glass), prying the shells off the PCB, freezing the pcb+components, the backup battery runs low on juice (after ~6months without power connection) If the device is moved while the KeyFOB is out of range, the device will shut down but not wipe your data. It's nothing but a forced shut down.
  • by Anonymous Coward

    the nfc controller, the bluetooth controller. that is assuming nothing is plugged into it. and don't even get me started on intel chips.

    How is physical security important, when the device is practically made out of NDA's, undocumented API's and chips with un-auditable encrypted firmware?

  • So I can brick your drive by attempting to connect via bluetooth? Cool!
  • This computer is SO SECURE that if you make one tiny mistake, like walking away from it, it will be secure FROM YOU! You can't move it. You can't move from it. If you screw up just once a tiny bit, then you are definitely screwed. I'm all for a good dose of paranoia to keep you vigilant and all that, but I'd be scared to use this thing.

    • by mark-t ( 151149 )
      Indeed... because of all of the precautions it employs in the so-called interests to "protect" your data, it seems like the only thing this would be good for having on it is content that you don't care if you lose... and if that is the case, it is unlikely anyone else would be interested in trying to attack it in the first place.
    • He range before the device locks is about 30 feet. (10m) plenty to move around.
  • by Xenna ( 37238 ) on Saturday September 17, 2016 @01:58PM (#52908133)

    The world's most secure bomb:

    https://en.wikipedia.org/wiki/... [wikipedia.org]

    A virtually tamper-proof bomb used to extort $3 million from a casino. It could not be moved. The FBI tried to disable it with a shaped charge but failed and blew up the hotel.

    • by mark-t ( 151149 )
      Wow.... I hadn't heard of that before. Did insurance cover the damages, or was the owner basically fucked?
      • by Xenna ( 37238 )

        I don't know really, but I think a business would normally be insured against damage from fires or explosions, but probably not against extortion damage.

        So perhaps the choice to let the FBI guys have a try was actually a sound business decision ;-)

  • Why not have a power only port?

    and no e-net with only 2 usb ports?

  • from the C;inton Foundation

  • I'm not a huge xkcd fan, but I can't believe no one has brought up this one [xkcd.com] - it's quite literally the first thing I thought of while reading the description of this silly computer.

    The context is pretty much identical.

    • Nice try but, I have to say that's a fairly poor XKCD and a mediocre invocation.

      XKCD didn't invent the concept of the rubber hose cryptographic attack (or wrench variant) and he rather bungles the joke by the RSA reference. No one uses RSA for full disk encryption. He's also overlooking the multiple cryptographic solutions (most famously, the overrated but noob-friendly Truecrypt) that used multiple nested containers so that (if you set it up properly) the attacker can't know whether you've decrypted t
  • The other side of corporate espionage is denying a company access to its own databases, research, customer lists, ledgers and everything else that is required to keep a company going.

    While this device is very good at preventing other people fromgetting that data, it's the worst design possible for preserving it in the face of adversity. All that a bad person would have to do to put you out of business, if you relied on this device, is to say "Boo!" and all your data disappears.

    Of course, if you have a b

  • Realistically all one would need is a 3.5" hard drive with the guts replaced by Thermite. Installed above the storage medium and RAM and wired to a pressure switch so when the PC is lifted it ignites, it's hard to see how this can be countered unless the ne'er-do-wells know about it ahead of time. And it's cheap.
    • I would like to see your fire insurance claim after you admitted to bringing a bomb into your house.

      Pyrotechnics look impressive in bad films, but in real life? hardly.

      • Thermite isn't explosive on its own, it's just a high temperature redox reaction. Arson would probably stick in court if it were law enforcement attempting to seize it, along with at a minimum destruction of evidence and some type of assault charge. But the data is destroyed and it's low cost and low tech. Putting the whole thing in a fireproof enclosure (a safe, concrete/center blocks, etc) and it lowers the odds of torching the average house; depending on the person and the data that might be an acceptabl
  • I know I will likely take a lot of flak for this, but what is the real, practical use for a device like this? I'm not even trying to be sarcastic, can somebody please explain it to me?

    Buying one of these will do little more besides possibly get you put on some sort of watch list, if the NSA even cares enough about you to do so. Just simply carry your private data on a flash drive that stays on your person, and only plug it into a special system that is offline, running a live OS with no data saved to the ha

    • by archi1 ( 4713085 )
      Carrying a flash drive is really not safe and certainly not protected from reading later. Even if tampered. The point of ORWL is to provide dual factor authentication as well as tamper proof. So YOU only can access the data and always know the computer is 'safe' to use, including FW, BIOS and other HW element have not been modified without your knowledge
  • Having good system security is already possible. It just requires good software and good security practices.

    First get some really good encryption software that can be trusted (no, Microsoft's (aka 'Apple should have weak encryption and build in back doors') BitLocker is *not* trustworthy). BestCrypt or DriveCrypt Plus Pack both seem reliable and better still neither are based in United States.

    Good security practices includes having a kill key that will wipe the internal memory where the key is kept, which

  • If you imagine that the RAM can't be desoldered and powered at the same time, boy are you a sucker. Although, that's not how I'd do it. I'd paint all the contacts with that conductive epoxy that only conducts once you smash it, and jump off the top.

    What is needed is encrypted RAM, and if you don't have that, you're not secure. Sorry!

    • by archi1 ( 4713085 )
      Encrypted RAM is a question of OS. It really depends of how you configure the machine. The active shield on ORWL will prevent you to get to the RAM. As soon as the mesh is broken or the device opened, the PC is shut down and the SSD key is lost.
  • Chalk and black board in a sealed room Erase when done.

Top Ten Things Overheard At The ANSI C Draft Committee Meetings: (1) Gee, I wish we hadn't backed down on 'noalias'.

Working...