[Cryptography] Dumb idea: open-source hardware USB key for crypto

Bill Frantz frantz at pwpconsult.com
Mon Jan 13 22:08:52 EST 2014


On 1/13/14 at 11:51 PM, iang at iang.org (ianG) wrote:

>Don't lose your stick!

I think about how my car keys work. I have two cars, one with a 
RF dongle, and one without. The one with the RF dongle is 
clearly less secure than the one without. The RF dongle + the 
key are two ways to get into the car. If you find a lost key 
with the dongle, just walk thru the parking lot and push the 
buttons -- the car will announce itself.

OTOH, the only way into the one without a dongle is to find the 
car and open the lock. Either car is at risk from a MIT/Cal Tech 
student who knows lock picking.

I think this analysis makes a good metaphor for the design of a 
USB dongle.

Cheers - Bill

-------------------------------------------------------------------------
Bill Frantz        | Airline peanut bag: "Produced  | Periwinkle
(408)356-8506      | in a facility that processes   | 16345 
Englewood Ave
www.pwpconsult.com | peanuts and other nuts." - Duh | Los Gatos, 
CA 95032



More information about the cryptography mailing list