TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Building a Titan: Better security through a tiny chip

149 pointsby bluegate010over 6 years ago

14 comments

tetrepover 6 years ago
&gt; Finally, in the interest of transparency, the Titan M firmware source code will be publicly available soon. While Google holds the root keys necessary to sign Titan M firmware, it will be possible to reproduce binary builds based on the public source for the purpose of binary transparency.<p>and<p>&gt; Transparency around every step of the design process — from logic gates to boot code to the applications — gives us confidence in the defenses we&#x27;re providing for our users. We know what&#x27;s inside, how it got there, how it works, and who can make changes.<p>This should be a boon for security researchers! I&#x27;m really looking forward to what comes out of fuzzing that whole subsystem. I imagine attacks against the secure enclave would be a lot easier to perform (and ideally, report to Apple) if it was feasible to attack it with pure software.
评论 #18245750 未加载
评论 #18246832 未加载
paulgerhardtover 6 years ago
I recently bought a few Titan products (the security key) - I was pretty bummed to find out that it had none of the features claimed by the Titan family.<p>No Side Channel Attack resistance.<p>No fuses to attest supply chain provenance or lifecycle.<p>No direct connections for FIDO hardening.<p>Apprantly the Titan keys given to Google employees were different than the Titan keys sold to the public. Themselves different from the Titan M used in Servers and Phones and now Chromebooks. None of this would matter so much other than the fact that products <i>sole purpose is to establish a secure chain of trust</i> and starts out the gate broken with ambiguous or misleading claims.<p>This is frustrating because the Titan M is an absolutely brilliant device, with some real advancements to normalize embedded security, including an SPI interposer to monitor communications (a real leap forward) - and should not at all be conflated with a generic, whitelabeled, non-hsm product that makes no claims whatsoever.
评论 #18244942 未加载
BooneJSover 6 years ago
Google has 3 Titans.<p>1) Titan for GCP servers: <a href="https:&#x2F;&#x2F;cloud.google.com&#x2F;blog&#x2F;products&#x2F;gcp&#x2F;titan-in-depth-security-in-plaintext" rel="nofollow">https:&#x2F;&#x2F;cloud.google.com&#x2F;blog&#x2F;products&#x2F;gcp&#x2F;titan-in-depth-se...</a> (custom hardware, custom software)<p>2) Security key: <a href="https:&#x2F;&#x2F;cloud.google.com&#x2F;titan-security-key&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cloud.google.com&#x2F;titan-security-key&#x2F;</a> (&quot;built with a hardware chip that includes firmware engineered by Google&quot; - seemingly stock hardware, custom software)<p>3) Titan M mobile: (TFA, custom hardware&#x2F;software like #1 but for mobile)
krnover 6 years ago
How does the latest Google&#x27;s hardware compare to the latest Apple&#x27;s hardware in terms of security? Can Pixel and Pixelbook now be recommended to journalists[1] as reasonable alternatives to iPhone and iPad, or are Apple&#x27;s products still much better in this regard?<p>[1] <a href="https:&#x2F;&#x2F;techsolidarity.org&#x2F;resources&#x2F;basic_security.htm" rel="nofollow">https:&#x2F;&#x2F;techsolidarity.org&#x2F;resources&#x2F;basic_security.htm</a>
评论 #18243481 未加载
评论 #18245692 未加载
philip1209over 6 years ago
So the new Pixel includes U2F hardware in the device? That&#x27;s cool - apparently, the flagship Chromebook has dormant U2F hardware, too.<p>Unfortunately, some providers (mainly Twitter) poorly implemented U2F by only allowing one device per account.
评论 #18245077 未加载
tptacekover 6 years ago
Is it made clear anywhere how memory for the Titan enclave works, and whether they&#x27;ve done something similar to Apple with encrypted memory busses?
评论 #18244097 未加载
评论 #18242652 未加载
sigmarover 6 years ago
&gt;Last, but not least, to prevent tampering, Titan M is built with insider attack resistance. The firmware on Titan M will never be updated unless you have entered your passcode, meaning bad actors cannot bypass your lock screen to update the firmware to a malicious version.<p>very explicit threat-modeling with the FBI in mind
评论 #18246029 未加载
amlutoover 6 years ago
I hope Google sells these chips with a breakout board. Even better if you could order them with custom root signing keys
评论 #18246841 未加载
sbr464over 6 years ago
I&#x27;ve been using the Titan, my main feature request is to require a delay on pressing the large button to activate the beacon. Any time I pull it out of my pocket or bump it, it lights up and starts broadcasting. Yubico had this problem, there are images online of random keys showing up in tweets&#x2F;social status updates etc. I just got their new usb-c nano, and they added a delay that helps out when you accidentally bump it.
评论 #18242544 未加载
评论 #18244283 未加载
评论 #18242386 未加载
monocasaover 6 years ago
&gt; For example, packing as many security features into Titan M&#x27;s 64 Kbytes of RAM required all firmware to execute exclusively off the stack.<p>Do what now?<p>Edit: seriously what does that sentence mean? Executing off the stack is super dangerous. Even on an M3 you can (and should) setup the MPU to have a non executable stack.
评论 #18243358 未加载
评论 #18244415 未加载
jor-elover 6 years ago
Can someone throw some light on why Google is not using ARM Trustzone technology? Many current Android OEMs are using it, particularly Samsung KNOX is security mechanism all built around trustzone technology.<p>What advantages does these Titan chips offer over the existing trustzone technology.
评论 #18249015 未加载
mtgxover 6 years ago
&gt; Titan M&#x27;s CPU is an ARM Cortex-M3 microprocessor specially hardened against side-channel attacks and augmented with defensive features to detect and respond to abnormal conditions.<p>It would be nice to see this being replaced by an an open-source RISC-V processor in the future, too.
评论 #18245119 未加载
评论 #18243736 未加载
评论 #18246850 未加载
alphabettsyover 6 years ago
Security, but without privacy?
yarrelover 6 years ago
...that&#x27;s made in China.<p><a href="https:&#x2F;&#x2F;motherboard.vice.com&#x2F;en_us&#x2F;article&#x2F;mb4zy3&#x2F;transparency-google-titan-security-keys-china" rel="nofollow">https:&#x2F;&#x2F;motherboard.vice.com&#x2F;en_us&#x2F;article&#x2F;mb4zy3&#x2F;transparen...</a>
评论 #18247057 未加载
评论 #18245711 未加载