HN user

nanocyber

102 karma
Posts0
Comments18
View on HN
No posts found.

If the article's evidence is the reality of Lightsail, it's clearly not a production platform. Amazon does state that the intent is really for developers to quickly spin up instances in which to experiment, and being able to use Amazon's unique Linux image that contains the latest AWS hooks makes for a good way to develop apps for later deployment to a fully-enabled AWS instance.

For quite a while, I've been trying to remind Americans that the NSA show is a distraction - NSA really is legally prohibited from performing surveillance of US Persons (hey, that mean corporations, too!)... the FBI, however... well that's what they're all about! With the FBI's recent strong anti-encryption views, this should come as no surprise, but what I AM honestly surprised about, probably due to that one shred of naivete and "hope" I have left, is that the Obama administration seems to be okay with all of this. As someone who was almost expelled for participating in a very vulgar and sophomoric underground high school newspaper (and in the end, assigned to the "punishment" of building robots at the local junior college after school), I can't help but wonder if today that same activity would have had all of my "selectors" (SSN, name, e-mails, phone numbers) assigned to a lifetime watchlist of potential terrorists, malcontents, and generally "un-American" types. I guarantee you, those lists already exist, they are growing, and they will last longer than the lives of those on them. When a teenager with a passion for the environment "grows up" and decides to protest less, and instead apply for a federal forest service job, that list will be the reason they are turned away. These lists PROMOTE separation, PROMOTE extreme thinking, and SUSTAIN anti-establishment views.

What could possibly go wrong? :D

I do think this is an interesting effort, and I've met Chris Lynch in his DDS capacity. It's terribly interesting to see a Senior Executive government employee with Silicon Valley cred, who wears hoodies/jeans/sneakers to meet Admirals and Generals, who are (in terms of rank equivalency) his peers. Literally the first time I've seen someone knuckle-bump an Admiral rather than shake his hand after a meeting.

I think there is some value in this culture-clash/disruption, but I also know of some government-employed very skillful hackers who resent the assumption that non-government hackers are by-default more skillful than them.

I thought this was an excellent write-up regarding how the iOS security platform (recent iPhone models) works from someone obviously in the know, as posted in the forums of Apple Insider. (Source: http://forums.appleinsider.com/discussion/191851)

" Apple uses a dedicated chip to store and process the encryption. They call this the Secure Enclave. The secure enclave stores a full 256-bit AES encryption key.

Within the secure enclave itself, you have the device's Unique ID (UID) . The only place this information is stored is within the secure enclave. It can't be queried or accessed from any other part of the device or OS. Within the phone's processor you also have the device's Group ID (GID). Both of these numbers combine to create 1/2 of the encryption key. These are numbers that are burned into the silicon, aren't accessible outside of the chips themselves, and aren't recorded anywhere once they are burned into the silicon. Apple doesn't keep records of these numbers. Since these two different pieces of hardware combine together to make 1/2 of the encryption key, you can't separate the secure enclave from it's paired processor.

The second half of the encryption key is generated using a random number generator chip. It creates entropy using the various sensors on the iPhone itself during boot (microphone, accelerometer, camera, etc.) This part of the key is stored within the Secure Enclave as well, where it resides and doesn't leave. This storage is tamper resistant and can't be accessed outside of the encryption system. Even if the UID and GID components of the encryption key are compromised on Apple's end, it still wouldn't be possible to decrypt an iPhone since that's only 1/2 of the key.

The secure enclave is part of an overall hardware based encryption system that completely encrypts all of the user storage. It will only decrypt content if provided with the unlock code. The unlock code itself is entangled with the device's UDID so that all attempts to decrypt the storage must be done on the device itself. You must have all 3 pieces present: The specific secure enclave, the specific processor of the iphone, and the flash memory that you are trying to decrypt. Basically, you can't pull the device apart to attack an individual piece of the encryption or get around parts of the encryption storage process. You can't run the decryption or brute forcing of the unlock code in an emulator. It requires that the actual hardware components are present and can only be done on the specific device itself.

The secure enclave also has hardware enforced time-delays and key-destruction. You can set the phone to wipe the encryption key (and all the data contained on the phone) after 10 failed attempts. If you have the data-wipe turned on, then the secure enclave will nuke the key that it stores after 10 failed attempts, effectively erasing all the data on the device. Whether the device-wipe feature is turned on or not, the secure enclave still has a hardware-enforced delay between attempts at entering the code: Attempts 1-4 have no delay, Attempt 5 has a delay of 1 minute. Attempt 6 has a delay of 5 minutes. Attempts 7 and 8 have a delay of 15 minutes. And attempts 9 or more have a delay of 1 hour. This delay is enforced by the secure enclave and can not be bypassed, even if you completely replace the operating system of the phone itself. If you have a 6-digit pin code, it will take, on average, nearly 6 years to brute-force the code. 4-digit pin will take almost a year. if you have an alpha-numeric password the amount of time required could extend beyond the heat-death of the universe. Key destruction is turned on by default.

Even if you pull the flash storage out of the device, image it, and attempt to get around key destruction that way it won't be successful. The key isn't stored in the flash itself, it's only stored within the secure enclave itself which you can't remove the storage from or image it.

Each boot, the secure enclave creates it's own temporary encryption key, based on it's own UID and random number generator with proper entropy, that it uses to store the full device encryption key in ram. Since the encryption key is also stored in ram encrypted, it can't simply be read out of the system memory by reading the RAM bus.

The only way I can possibly see to potentially unlock the phone without the unlock code is to use an electron microscope to read the encryption key from the secure enclave's own storage. This would take considerable time and expense (likely millions of dollars and several months) to accomplish. This also assumes that the secure enclave chip itself isn't built to be resistant to this kind of attack. The chip could be physically designed such that the very act of exposing the silicon to read it with an electron microscope could itself be destructive."

I used to use Uber quite regularly.

In the past year, I have had several drivers bring up, of their own volition, their dissatisfaction with the fact that tipping Uber drivers is uncommon. It is quite clearly stated in Uber's app and website that there is "no need to tip". I'm not a cheapskate, but I don't carry cash most of the time, and their veiled reminders/requests made me uncomfortable.

It probably sounds strange, but the ridiculous logo change on top of the changing driver culture have made me remove Uber from my transportation-method choices.

Fickle creature I am.

This is very cool, and in my opinion, a realization of how I feel the interwebs should be working anyway... voluntary distribution of bandwidth, freedom from large ISPs... enables high-capacity short-run network connections to thrive. Exciting!

With regard to states wishing to suppress this sort of activity, I do have concerns that a behavioral signature will emerge that will be fairly telling... I suspect it may not be difficult to crack down on users. Nonetheless, the concept has potential for many reasons.

I read the article again. The researchers simply seem to be saying that what seem like complex decisions can be made in simple organisms as long as the ability to increment a "counter" when a certain condition occurs is possible. The slot machine example actually requires a "counter" that can increase and decrease when opposing conditions occur. This seems very obvious...

The decision is still made by the human evaluator(s). (Presumably, to declare one slot machine the "easiest".)

Terrible headline.

Are they even suggesting that the bar is somehow affected by the output of (perhaps) coins from the slot machine... electromagnetic interactions? Or is the slot machine example simply a thought experiment? I suspect we may be attempting to process bad input here...

Exactly. As per my previous comment, the currency of merit being traded in the orator's meritocracy is only defined within the Ivy Leauge-al community. The currency of merit that SHOULD matter is based on the collective suffering of humanity.

Ship of Theseus 11 years ago

The answer depends on perspective and subjectivity. If I took the ship across the ocean last year, and now I take the fully-parts-replaced version this year, I'm still calling it by the same name. In my mind it is "same", unless I decide to get especially academic about it. It is both same and not-same. Meh. Not the most interesting of paradoxes. ;)

I was excited until I looked at the images included in the patent application and discovered that the space elevator is made out of paper towel tubes.