Slashdot Log In
IBM Hardwires Encryption Into Chips
Posted by
samzenpus
on Mon Apr 10, 2006 11:09 AM
from the it's-in-the-chip dept.
from the it's-in-the-chip dept.
zenwarrior writes "Reported by CNET, a new chip technology termed Secure Blue by IBM will keep users' data encrypted and secured at virtually every moment on essentially anything in which the chip can be used. Data is even encrypted in RAM, leaving display for users' viewing as almost the last place it isn't encrypted. This has to be considered decidedly anti-Homeland Defense by the current administration. If so, when will we see it if ever?"
Related Stories
[+]
IT: Counterfeit Chips Raise New Terror, Hacking Fears 173 comments
mattnyc99 writes "We've seen overtures by computer manufacturers to build in chip security before, but now Popular Mechanics takes a long look at growing worries over counterfeit chips, from the military and FAA to the Department of Energy and top universities. While there's still never been a fake-chip sabotage or info hack on America by foreign countries or rogue groups, this article suggests just how easy it would be for chips embedded with time-release cripple coding to steal data or bring down a critical network - and how that's got Homeland shaking in its boots (but not Bruce Schneier). While PopMech has an accompanying story on the possible end of cheap gadget manufacturing in China as inflation rates soar there, it's the global hardware business in general that has DoD officials freaking out over chips."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Clipper Chip??? (Score:5, Insightful)
Re:Clipper Chip??? (Score:2)
The poster made the political comment with absolutely no backing at all. I wouldn't be surprised if IBM was not allowed to export this to Iran, but again, nothing new. And you don't have much justification that Clinton would have tried to do anything.
Re:Clipper Chip??? (Score:3, Informative)
Re:Clipper Chip??? (Score:3, Interesting)
The fact that the entire system is encrypted, with the exception of the output device and in-CPU communication, electronic wiretapping can be made inpractable. Yes the crypto can be broken, but if the crypto holds up for either the statute of limitations &&|| the perps lifetime then you might as well not wiretapped at all.
Yes you can still get at teh output device, but if that device is a digital earphone (or better yet a bone conduction transducer) that decrypts
Re:Clipper Chip??? (Score:3, Insightful)
I know partisans want to do nothing but win elections, get the bribes and power. But we need politicians who can also run the country. And people who can communicate with them to ensure they represent us.
When Democrats have some power, even when balanced by a Republican other branch, the only bad
Re:Said (Score:3, Insightful)
Only if you don't know what Republicans are.
The Clinton administration was enthusiastically "Pro-Choice" and Anti-Second Amendment, quite the opposite of the Republicans. Clinton also passed a middle(and upper)-class tax hike. Once again, not very Republican of him.
LK
Re:Said (Score:3, Insightful)
I think the OP's point was that GWB doesn't hold the patent on evil. This is something to be mindful of. The next guy, democrat or republican, could easily be just as evil. If you just assume "Hey, it's not Bush! Our problems have gone away!", well then you're in a we
Re:Said (Score:3, Insightful)
this kind of protectionism has nothing to do with being left or right. it has more to do with the oposing forces represented by populism (do things that apeal to the public. screw common sense) and pragmatism (do sensible things that
When will we see it, if ever? (Score:5, Insightful)
Re:When will we see it, if ever? (Score:5, Insightful)
Parent
Pretty cool (Score:5, Insightful)
Regardless it is very interesting that they say this technology can be used on any chip and not just powerPC's, also is the encrypted data tied to the chip or the system, how would this effect SMP systems, or virtual partitions?
Re:Pretty cool (Score:5, Funny)
Now let's lean back and see how long it takes for the Inquirer to pick this up...
Parent
Re:Pretty cool (Score:2, Interesting)
From TFA:
(emphasis added by me)
It would seem to me that the highlighted phrases above would set some sort of bound on how sophisticated this encryption can b
Re:Pretty cool (Score:4, Informative)
Parent
Re:Pretty cool (Score:2)
Re:Pretty cool (Score:4, Interesting)
Even if the Feds do pass a law requiring backdoors for devices, the law could be circumvented by doing the encryption in software. Not as convenient for the end-user perhaps, but millions of people around the world do that every day thanks to the various implementations of public-key (RSA) schemes.
Software trapdoors trump hardware backdoors.
Parent
Re:Pretty cool (Score:3, Informative)
not so much anymore. there might be some cases, but it's not a blanket policy anymore. the PGP case pretty much killed that
DRM (Score:5, Insightful)
Re:DRM (Score:5, Insightful)
Hmmm, doesn't Apple use DRM in its iTunes music and in OS X?
Parent
Re:DRM (Score:2, Insightful)
Since when? (Score:4, Insightful)
I'm sorry, what? According to wide report, as of the new Intel macs, Apple is in fact using draconian hardware chips that prevent you from having control over your computer [masternewmedia.org], and is reportedly using these specifically to keep you from running OS X on unauthorized hardware. (Though, hilariously enough, that's according to wide report. There is no hard evidence I've seen one way or the other that these chips are or aren't even in the new macs to begin with! All reports of TPM in the Intel macs are based on sort of circumstantial evidence from reports of the developer betas of the Intel macs. Since the actual release of the Intel macs, everyone has gone silent on the subject, and Google doesn't turn up any attempts I can find to take apart the Intel macs and the kernel to see whether TPM is in there. Apparently though the slashdot and tech blogger crowd were angry and opposed to Palladium/TPM for three or five years nonstop since it was announced, they just fell silent once they saw how shiny the new iMacs are.)
You are of course correct that they aren't, of course, using these chips for iTunes or the iPod. Yet. But if the chips are in the machines, they could start using them for such purposes at any time. The iTunes DRM already subtly changes with each iTunes version (the jHymn backup utility still doesn't work with the iTunes 6.0 DRM).
Though all of my computers since I was six years old have been Apples, if it's true that Apple is using TPM in their machines now, it would seem I'm going to be using Linux from now on. I was rather annoyed at the prospect of having to suffer a hardware platform transition (again) to begin with, but I can at least understand the reasoning behind that. But I'm absolutely not willing to pay for a computer if there's this ticking TPM time bomb buried in it that means, if someday the OS vendor changes their mind, a single OS update could sweep through and my computer would no longer be mine.
Parent
New Macs do have TPMs (Score:3, Interesting)
Re:DRM (Score:4, Insightful)
Parent
Re:DRM (Score:3, Funny)
Re:DRM (Score:5, Insightful)
They know damned well that until our brains can decode encrypted digital video and audio, they can't stop copying. It must be converted to analog before we can use it, and while they can hamper things, there's absolutely no way to stop microphones and camcorders. It's for the sole purpose of extracting as much profit from everyone as possible. The anti-piracy makes a decent cover, but in reality it's one of the largest anti-competitive schemes in recent history.
Parent
Or Sponsored by DHS? (Score:5, Insightful)
"This has to be considered decidedly anti-Homeland Defense by the current administration."
Unless they designed the backdoor to be inserted....
Re:Or Sponsored by DHS? (Score:5, Insightful)
Can you? If anything about the government-installed backdoor ever became public knowledge, IBM would be facing all kinds of lawsuits from anyone who ever bought that chip, would probably have to refund or replace every copy of the chip they ever sold, and it would be a long, long time before anyone would seriously consider buying a "secure" chip from IBM again.
I like a crypto-fascist conspiracy as much as the next guy, but wouldn't that be an awfully big marketing risk for IBM to take?
Parent
Re:Or Sponsored by DHS? (Score:4, Insightful)
They are certainly among the best in the field, and yes they did improve DES. However, that doesn't change the fact that many published encryption schemes like GOST (Russian), Rijendael (European, better known as AES) were developed outside the US. Very many cryptographers have taken a whack at both those and US algorithms, and they seem to hold. To think that the NSA has solvers for all of these and the rest of the world can't find solvers for any of them, is putting too much faith in the NSA. It seems quite obvious at this point that secure encryption does exist. Of course, there's always the chance the NSA has broken some of these algorithms, which they aren't very likely to talk about. But I strongly doubt they've cracked all of them. And as far as brute force go, it wasn't too long since 40 bits was the limit, now 128bit is everywhere. I strongly doubt their breaking capability rose with 2^88 in that time, I think it's more a case of the cat being out of the bag.
Parent
Re:Or Sponsored by DHS? (Score:3, Insightful)
Remember also that the NSA is concerned with practical mission concerns and not just the theoretical side of cryptography. In the real world the weakness is rarely in the algorithm chosen, but rather in bungled key management, social engineering, or other physical security concerns which serve as the weak link in the chain. The NSA would not bother brute forcing your key if they could log your keystrokes from a van parked somewhere in the neighbor
Homeland Security Vrs RIAA (Score:5, Funny)
Anti-Homeland Defense, maybe, but avoiding data leakage will make it very attractive to RIAA / MPAA and other copyright protection lobby groups.
So Maybe we get to see what happens when the RIAA face off against the Department for Homeland Security and the CIA - that would be one I would like to see (Maybe we should just watch them fight them nuke them both from orbit - only way to be sure).
Re:Homeland Security Vrs RIAA (Score:3, Insightful)
Besides which, I'm pretty sure the RIAA and the MPAA will get behind this, and they've got Congress in their pocket.
Re:Homeland Security Vrs RIAA (Score:2)
Or even better, I'm just
Re:Homeland Security Vrs RIAA (Score:2)
Well, the obvious one being that installing a pinhole camera, keystroke logger, or parking a tempest van outside would be infinitely cheaper and easier.
The second one being your brain, and a rubber-hose: http://iq.org/~proff/rubberhose.org/current/src/do c/review.html [iq.org]
Re:Homeland Security Vrs RIAA (Score:2)
Re:Homeland Security Vrs RIAA (Score:3, Insightful)
These outfits are the same side of the same coin, so there will be no "face off." They're all in cahoots together and you can rely on the fact that the RIAA or any other *AA will fall all over themselves attempting to give the DHS or whomever, any little thing their hearts desire, including whatever keys to whatever algorithm they may be interested in at any given time. It's YOU AND I who are on the
A chain is only as strong as its weakest link (Score:4, Insightful)
Re:A chain is only as strong as its weakest link (Score:2)
Re:A chain is only as strong as its weakest link (Score:4, Interesting)
All of this encryption is done in hardware. I was considering, for my next laptop purchase, getting one with a MiniPCI slot that could have a crypto accelerator inserted (even a cheap one can handle over 300MB/s throughput, which is faster than my hard disk can do). Having this on-chip or even on the motherboard would be a huge incentive for me.
Parent
Ok, what are we talking about? (Score:3, Interesting)
Re:Ok, what are we talking about? (Score:2)
Re:Ok, what are we talking about? (Score:3, Informative)
What, you mean like back when they were developing DES, and they got visited by the NSA? It went something like this (totally made-up, aside from the fact that the basic scenario happened):
Re:Ok, what are we talking about? (Score:3, Insightful)
And repairing those computers? (Score:4, Interesting)
Maybe negative, but in a different way (Score:4, Insightful)
Re:Maybe negative, but in a different way (Score:2)
Not just terrorists, but any foreign government really. Saddam & Osama both would have benefited from hardware level heavy duty encryption, as the U.S. has gotten computers from both of 'em that were completely unencrypted, yet contained sensitive information.
Don't know about cnet (Score:2, Informative)
This isn't meant to protect you from the gov't (Score:2, Insightful)
One small step for IBM, one giant leap for DRM...
However, there's still hope: making tamper proof hardware is very difficult. Making hardware that's not vulnerable to side
no back door? (Score:3, Interesting)
Well, unless I can varify the code or make the chip from a copy of it's mask myself - I am pretty much taking it on faith from IBM that it is secure from the eyes of the government. (no offense IBM, but I prefer the security of open review) Untill independent sources can take the chip and put it under an electron microscope and say: Yes it's designed secure - then it's pretty much not secure. An if it's firmware that can be re-programmed, then it is especially not secure if the governments hands get on it anywhere in the distribution chain.
No processor overhead. (Score:5, Funny)
Double ROT26.
Woo. That's gonna be TOUGH to crack!
Keys too or only algorithms? (Score:5, Insightful)
Apparently what they're putting in the chips is, at least, encryption/decryption routines. Aside from the obvious questions (what happens when you want to change algorithms?), the important question is whether they're including digital keys as well.
The single factor that makes "trusted computing" evil is that there's a digital key (the "attestation" or "endorsement" key) baked into the TPM which the owner of the machine is prevented from accessing or changing. If all the keys were accessible to the owner, it would be a purely beneficial technology. With the anti-owner feature, it becomes an engine of DRM, censorship, and vendor lock-in on a vast scale, and at a fundamental level absolutely prevents security and privacy for the computer owner.
So the question is which category this IBM tech falls into. And that in turn depends on whether digital keys will be baked into the processor, or whether it's only a set of routines that any software can use under the owner's control.