TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Titan in depth: Security in plaintext

129 pointsby nealmuellerover 7 years ago

9 comments

danielvfover 7 years ago
Beyond the secure boot, this is really cool<p>&quot;...Titan cryptographically associates the log messages with successive values of a secure monotonic counter maintained by Titan, and signs these associations with its private key. This binding of log messages with secure monotonic counter values ensures that audit logs cannot be altered or deleted without detection, even by insiders with root access to the relevant machine.&quot;
评论 #15096876 未加载
sbarreover 7 years ago
Pardon my ignorance in hardware matters, but I would assume Google gets these manufactured via a third-party.<p>What would be the process for verifying that the chip itself has not been compromised during manufacture?<p>Is this a hardware + software verification combo, so a tainted chip would not be recognized as valid by the software - so you&#x27;d need to compromise both to bypass?
评论 #15093546 未加载
评论 #15093462 未加载
bluegate010over 7 years ago
Hey HN, I&#x27;m one of the engineers on the team behind Titan, feel free to AMA.
评论 #15095120 未加载
评论 #15094775 未加载
评论 #15094319 未加载
评论 #15097564 未加载
评论 #15097231 未加载
评论 #15110727 未加载
评论 #15094264 未加载
bobbypageover 7 years ago
I wonder how this type of security hardware compares to other clouds (AWS, Azure, etc...)? Do they have something comparable?
评论 #15094819 未加载
pcuniteover 7 years ago
The red circuit board&#x2F;chip image in the article is not of the actual chip. May I see it?<p>The caption reads, &quot;Photograph of Titan up-close on a printed circuit board&quot;, which is unfortunately untrue:<p><a href="https:&#x2F;&#x2F;1.bp.blogspot.com&#x2F;-027iovJ94yk&#x2F;WZ8ZDw4MNvI&#x2F;AAAAAAAAEUM&#x2F;LHjr4KnsLjw-L5owy2RJinEC2VqdIbECACLcBGAs&#x2F;s1600&#x2F;titan-1.png" rel="nofollow">https:&#x2F;&#x2F;1.bp.blogspot.com&#x2F;-027iovJ94yk&#x2F;WZ8ZDw4MNvI&#x2F;AAAAAAAAE...</a>
评论 #15094400 未加载
评论 #15094467 未加载
colllectorofover 7 years ago
I&#x27;ve heard about this chip, but I still don&#x27;t get what specific scenarios it&#x27;s designed to prevent compared to &quot;traditional&quot; secure boot. The article lists a lot of things Titan does without going into what practical benefits all of those features offer compared to the current industry practices.
评论 #15125269 未加载
egberts1over 7 years ago
Oh. This chip is a fail, security-wise.
评论 #15093885 未加载
评论 #15093901 未加载
Simon_saysover 7 years ago
What does any of this matter against National Security Letters? There&#x27;s no place safe in the US.
评论 #15096854 未加载
pmlnrover 7 years ago
News like this make me sad. google is becoming a government agency-like customised fortress from the cold war, and general computing gets phased out, just like Cory Doctorow said.[^1] Technologically, it&#x27;s fantastic, but I do not welcome the philosophy it&#x27;s bringing.<p>[^1]: <a href="https:&#x2F;&#x2F;techcrunch.com&#x2F;2015&#x2F;04&#x2F;18&#x2F;on-the-war-on-general-purpose-computing&#x2F;" rel="nofollow">https:&#x2F;&#x2F;techcrunch.com&#x2F;2015&#x2F;04&#x2F;18&#x2F;on-the-war-on-general-purp...</a>
评论 #15096872 未加载