by lysergia on 1/17/23, 4:32 PM with 38 comments
by kfreds on 1/17/23, 7:36 PM
That's the gist of it.
If you think this is interesting I can highly recommend you check out Sigsum - our transparency log design for signed checksums. We've been developing it for a few years and will most likely toggle it version 1 this spring. Here's its threat model:
Sigsum is designed to be secure against a powerful attacker that controls:
- The signer’s secret key and infrastructure - The log’s secret key and infrastructure - A threshold of so-called witnesses that cosign the log
Another project that started at Mullvad VPN and is now its own company is Tillitis. Its first product is an open source hardware USB device with unconditional measured boot and key derivation inspired by DICE. Everything from source code to Verilog and KiCad files are on GitHub. Enjoy!
Cheers, Fredrik Stromberg
(Disclosure: I cofounded Mullvad VPN, invented System Transparency, co-designed Sigsum, co-designed TKey, and cofounded Tillitis)
by morsecodist on 1/17/23, 6:01 PM
by crazygringo on 1/17/23, 5:46 PM
It makes me curious if there are any other real-world use cases for diskless. Are there any customers who would benefit from such a configuration from major cloud providers? E.g. a diskless EC2 instance type that ran off of a RAM disk?
by latchkey on 1/17/23, 7:10 PM
This generally works well, but I'd say there are about 0-20 blades that crash a day due to some sort of memory corruption issues.
Due to the fact that I was operating remotely from the hardware, I never really got a chance to resolve it... also... just a simple reboot would fix it (and the blades booted in ~60 seconds, so it wasn't a huge issue).
So, on large enough scale... this can be an issue to consider.
by siliconc0w on 1/17/23, 6:34 PM
by ignoramous on 1/17/23, 8:49 PM
I don't know what the threat model is, but if it involves nation states confiscating servers, then diskless is of limited help: https://en.wikipedia.org/wiki/Cold_boot_attack
> If the computer is powered off, moved or confiscated, there is no data to retrieve.
Oh wait...
by Mave83 on 1/17/23, 6:34 PM
It provides so many benefits and eases the server management greatly.
by zppln on 1/17/23, 5:56 PM
by Semaphor on 1/17/23, 7:13 PM
by l2silver on 1/17/23, 8:56 PM
by patrakov on 1/17/23, 6:28 PM
by RVRX on 1/17/23, 5:51 PM
[1] https://www.amazon.com/Mullvad-VPN-Devices-Protect-Security/...
by warinukraine on 1/17/23, 5:53 PM
However, what makes them great and unique is that they're ideologically motivated, so of course they're not selling shares.