10.15.20

A FIDO/FIDO2 False Sense of Security for Premium Prices

Posted in Deception, Free/Libre Software, Google, Microsoft, Security at 10:09 am by Dr. Roy Schestowitz

Military-grade nonsense that is proprietary and untrustworthy (monopolised by the likes of Google and Microsoft)

Manifestation against missileSummary: From the attack on software freedom (including Richard Stallman and other leaders/luminaries) we’ve seen a shift to attacks on privacy itself, e.g. auditable encryption; today we discuss the troubling developments in the FIDO/FIDO2 space

THE ESSENCE of Free/libre software is control, liberty, autonomy, independence, security, decentralisation and sometimes privacy too. Those are all just words that convey concepts in English. It’s better understood in the absence of those things (when one lacks or loses freedom). As RMS puts it, to paraphrase a bit, either the user controls the program or the program is an instrument by which some corporation (or government) controls the user. It’s really that simple. To alleviate that unjust leverage of power (developers or developers’ employer) over computer users we need freedom-respecting software that is audited by many and forked if mischief occurs. This helps ensure that the public interest is prioritised, not the bottom line of some business/es. That does not mean that no business can exist; many businesses are based around distributing and supporting Free software. Perfectly moral and ethical business practices are compatible with the Four Freedoms.

“Earlier this year there was a major incident, which saw millions of rogue certificates being issued by Let’s Encrypt…”With all that in mind, we’ve grown cynical if not deeply concerned about the Linux Foundation. The institution itself is a misnomer (it promotes operating systems other than Linux), its biggest players (leadership) are monopolistic proprietary software companies, it advocates mass surveillance, and it works for Microsoft (which in turn works to undermine Linux).

Earlier this year there was a major incident, which saw millions of rogue certificates being issued by Let’s Encrypt, which is connected to the Linux Foundation and hosted/coded on Microsoft servers. These certificates were later revoked, but there was no transparency about what had happened. Can we trust one CA to manage so many certificates? Look at its backers and sponsors. These certificates aren’t free; if they seem to be free, it’s because someone foots the bill to gain something, such as the US government receiving back door access to undermine encryption (by access to private keys or similar). They’re already done that even inside Switzerland, covertly of course! So do we trust Let’s Encrypt? Not really, even less so after that incident. There was never clarity and now even an explanation of what was done, who the culprit was and so on.

But this article isn’t about Let’s Encrypt. It’s about FIDO2. The patterns may be similar, at least some salient points. “I don’t know if you’ve been keeping up with the developments in hardware security tokens,” one reader told us this week, “but I have been very alarmed with the developments that are happening with regards to FIDO2. I feel like this is another attempt to stomp out competition just like TLS CAs did before Let’s Encrypt was a thing.”

“We use GnuPG a great deal here in Techrights. Most of our messages are encrypted.”The reader is a bit of an expert in that domain. Also remember how the founder of Ubuntu originally amassed his wealth. “Right now,” the reader noted, “companies that make products like Yubikey and Titan Security Key are selling obscenely overpriced hardware just because it has a “FIDO2 Certified” logo on it. I feel like hardware security tokens are going to end up in the same situation that happened with TLS CAs where a few bodies monopolise the system and dictate who gets to be a “trusted provider”. A FIDO2 certification costs about $6500 USD, last time I checked. As someone that uses GnuPG and its open ecosystem of hardware, it pains me to see the monopolisation and profiteering that’s happening around the security space.”

We use GnuPG a great deal here in Techrights. Most of our messages are encrypted.

“I hope you can share this message with the right people,” our reader appealed, “to combat the monopolisation and anti-competitive attempts by organisations like FIDO Alliance. There’s nothing open about the FIDO Alliance. The firmware for most of those devices are closed-source and the only reason people are duped into buying them is because of the “FIDO2 Certified” seal on those products. I feel like this is a turning point in cybersecurity history and we need to kill this attempt at monopolisation before we end up with the tragedy that happened with TLS CAs.”

“A mechanism for trust among parties, e.g. encryption, is crucial in a free and democratic society.”How many billions of dollars were washed down the drain because of these? And we ended up with “trusted” CAs that are mostly in bed with the world’s biggest spying operation. Which means they might be worse than useless…

“We decide who to trust with our OpenPGP certificates,” our reader noted. “We don’t let other bodies make that decision for us. Let’s work together to make sure we nip this FIDO nonsense in the bud. We’ve got the platforms and people. The WebAuthn W3C steering members are stuffed with Google, Microsoft, and (surprise) Yubico people. I’m almost certain that they’re using embedded cryptography MCUs in their closed proprietary products and then making a eye-watering profit margin.”

Notice that their stuff is controlled partly by Microsoft and the NSA (in GitHub). So they clearly do not value or grasp basic security.

Our reader noted: “The OpenSK project on GitHub (by Google, I believe) uses an overpriced board and there’s a nice disclaimer at the bottom that OpenSK is not FIDO certified (this is blatant FUD). They aren’t even using the embedded crypto MCUs on the Nordic chip. They have gone with the excuse that their software-driven crypto is “research quality” code. OpenSK is a blatant attempt to spread FUD about uncertified FIDO hardware. Yubico are in on it as well.

“We might be the first site to touch this subject, but there’s more on the way for sure.”“Nitrokey has a FIDO2 product and I think it’s uncertified by the looks of things. I know Nitrokey people are very closely linked to GnuPG devs because I’ve been around GnuPG dev a lot recently. I’m pretty sure the folks at Nitrokey see the dangers of monopolisation but they’re keeping it quiet (probably in fear of the media pull Google et al have). I would also prefer remaining anonymous, thanks for allowing that…”

A mechanism for trust among parties, e.g. encryption, is crucial in a free and democratic society. Those who undermine the encryption basically maintain keys to the castle. They’ve long attempted to put back doors (or back door access, e.g. via third parties) to everything. Sometimes the media describes that as “weakening” encryption, but that actually means breaking; weak means broken.

We might be the first site to touch this subject, but there’s more on the way for sure. “Wanted you to be the first to throw a punch though,” our reader noted, “because people in the community trust you on these things.”

But there’s lots more on the way. Stay tuned.

Share in other sites/networks: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Reddit
  • email

This post is also available in Gemini over at:

gemini://gemini.techrights.org/2020/10/15/fido-false-sense-of-security/

If you liked this post, consider subscribing to the RSS feed or join us now at the IRC channels.

Pages that cross-reference this one

What Else is New


  1. Links 10/4/2021: Linux on M1, Wine 6.6, ClamAV 0.103.2

    Links for the day



  2. Lunduke: On Mob Justice in the Tech Industry

    A new video from the former Microsofter who fears the phenomenon that’s adopted by companies like IBM



  3. IRC Proceedings: Friday, April 09, 2021

    IRC logs for Friday, April 09, 2021



  4. EPOLeaks on Misleading the Bundestag — Appendix (Benoît Battistelli's Vichy Syndrome): Georges Henri Léon Battistelli and Charles Robert Battistelli

    Local copies with evidence of or something concrete about Benoît Battistelli’s connection to unsavoury — and by today’s standards outright fascistic — politics



  5. IBM Doubles Down on Masters Being an Acceptable Word in the Context of Technology

    3 days after this post which disproves IBM's stance or shows its double standards it once again says “Masters” in its official blog (won’t that offend and alienate some people as they insist?)



  6. Hate Letter Against Richard Matthew Stallman (RMS) Backfired So Spectacularly That Signers Asked to Revoke Their Own Signatures and the List Was Then Frozen Permanently (Updated)

    "An open letter in support of Richard Matthew Stallman being reinstated by the Free Software Foundation" tops 6,100 signatures (graph generated just moments ago)



  7. EPOLeaks on Misleading the Bundestag -- Part 11: The BMJV's Tweedledee: Dr Christoph Ernst

    The right-hand man of António Campinos plays a role similar to that of Herr Lutz before him



  8. Links 9/4/2021: Tanglet 1.6.0 and HPVM 1.0

    Links for the day



  9. The Libel Against Richard Stallman Did Not Age Well

    Almost 2 years down the line libel about the founder of the FSF remains online, uncorrected (in sites funded by Microsoft and IBM)



  10. The Letter in Support of the FSF and Richard Stallman is Backed by the International Community, Not American Monopolies and Nationalistic Elements

    Free software is for everybody to use, internationally, it is not the asset of a bunch of current and old monopolists (connected to the US military) that also control the media; the nature of the signatures says that out loud



  11. Gemini Over IPFS (Decentralised Web, Accessed Over Gemini Protocol)

    The Gemini protocol (gemini://) can already be used to fetch (at the back end) and present objects from a P2P-like network; we're currently exploring practical use cases and possibilities



  12. News Sites That Talk About Patents Have Become Shameless Self-Promotion 'Plugs' by Law Firms (and Sometimes Outright 'Spam' for Litigation)

    The sources of news about patent affairs have dried up; sites that actually used to investigate and report facts have since then shut down or defected to the Public Relations/marketing industry



  13. Links 9/4/2021: Kubernetes 1.21 and FFmpeg 4.4 Released

    Links for the day



  14. IRC Proceedings: Thursday, April 08, 2021

    IRC logs for Thursday, April 08, 2021



  15. [Meme] Self-styled Judges

    To suit a recurring theme at the EPO we hereby present Roland Lutz, a self-styled judge



  16. EPOLeaks on Misleading the Bundestag -- Part 10: A Faithful Lapdog Despised and Reviled by EPO Staff

    "In any event, the "Nazi" jibes directed against Lutz seem to have triggered Battistelli who decided to take revenge on his perceived enemies inside the EPO by smearing them as “Nazis”."



  17. Links 8/4/2021: GnuPG 2.3.0, Xen 4.15, Xfdashboard 0.9.2

    Links for the day



  18. The Hate Letter Which Backfired

    The FSF is more closely aligned with its founder's vision, his antagonists have left or are leaving, and that old hate letter turned out to be a loud minority (made to appear louder by biased media) emboldened by a gish gallop of lies



  19. IRC Proceedings: Wednesday, April 07, 2021

    IRC logs for Wednesday, April 07, 2021



  20. IBM: We Can Say It... You Cannot

    Blog posts such as this new one help show the hypocrisy or the double standards of IBM, looking to control speech while attacking people's (software) freedom/civil liberties and profiting from atomic bombs



  21. The Collapse of Microsoft Windows

    Although the corporate media keeps insisting that Microsoft is doing well, government (or military) bailouts keep the company afloat while its desperate attempts to remain relevant (as the common carrier languishes) merit a debate



  22. Links 8/4/2021: Mesa 21.0.2, GNU Releases, and Stable Kernels

    Links for the day



  23. Petition in Support of FSF's Decision to Put Its Founder in the Board Doubles Size of Hate Letter Propped Up by Corporate Media (Partly Funded by Monopolies)

    You cannot fool the population for eternity and there's a reflexive response to a campaign of misinformation, as the graph above shows; notice it keeps growing and growing, albeit not the defamatory one from the (Google-funded) Mozilla- and Red Hat-connected Luis Villa, who put in the GNONE Foundation Microsoft people



  24. EPOLeaks on Misleading the Bundestag -- Part 9: A Veritable Virtuoso of Legal Sophistry

    "Lutz is also reputed to be closely linked to the German branch of the influential UPC lobby group centred around Prof. Winfried Tilmann."



  25. He Said, Xi Said: Hard to Censor Techrights and It's More Than a Web Site

    An explanation of some of the latest Techrights changes (mostly work on IPFS and Gemini this week, as they complement the Web site)



  26. A Patent System for Giant Corporations Like Boeing and Airbus, Not for Ordinary European Citizens

    There's hardly any illusion left that the patent system in Europe is supposed to serve the public; instead what we're seeing is an office that lost sight of its purpose and is instead trying to make law firms and their largest clients richer



  27. Links 7/4/2021: Godot 3.3 RC 8, Canonical Targets Robotics

    Links for the day



  28. IRC Proceedings: Tuesday, April 06, 2021

    IRC logs for Tuesday, April 06, 2021



  29. Pro-Free Software Foundation Petition Soon Reaching 6,000 Signatures (and Still Rising Steadily)

    It seems rather apparent that not many people have been conned by the hateful corporations, their corporate media, and corporate-led (or funded) NGOs that insisted FSF should reject its very own founder



  30. Links 7/4/2021: “Getting Things GNOME” Reaches 0.5, IBM Boasts Its Role in Masters

    Links for the day


RSS 64x64RSS Feed: subscribe to the RSS feed for regular updates

Home iconSite Wiki: You can improve this site by helping the extension of the site's content

Home iconSite Home: Background about the site and some key features in the front page

Chat iconIRC Channel: Come and chat with us in real time

Recent Posts