Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • PC Hardware
    • Servers

    How Do You Secure 100 Million Laptops?

    Written by

    Ryan Naraine
    Published October 12, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      If the plan is perfectly executed, Nicholas Negropontes One Laptop Per Child project will deploy 100 million laptops in the first year. In one fell swoop, the nonprofit organization will create the largest computing monoculture in history.

      Wary of the security risks associated with a computing monoculture—millions of machines with hardware and software of identical design—OLPC foundation officials are seeking help from the worlds best hackers to review the full specifications of the $100 laptops security model.

      “This is an enormous challenge for us,” said Ivan Krstić, director of the security and information platform efforts for the OLPC project in Cambridge, Mass. “Security for these machines is hands down the hardest thing Ive ever worked on.”

      /zimages/1/28571.gifOne Laptop Per Childs CTO explains how new display developments are bringing the $100 laptop closer to reality. Click here to read more.

      Krstić has spent a large portion of 2006 slipping into security conferences around the world, schmoozing with hackers, trying to recruit computer security experts to look at the design and threat model and provide useful feedback.

      “We want hackers to get in touch, look at the documentation, play with the machine, and try to break into it. We run the risk of getting parts of this wrong and thats not something we can afford,” Krstić said in an interview with eWEEK.

      A former director of research at the Medical Informatics Laboratory at Zagreb Childrens Hospital, in Croatia, Krstić said he is well aware of the dangers of the monoculture. “If this succeeds, well have created the largest monoculture in the computer industry. To answer whether thats scary or not is a nontrivial question. The security implications are deeply frightening,” he said.

      The overall design goals have already been released to OLPCs security panel for review, and Krstić plans to publicly release the specs to generate feedback from the open-source community.

      /zimages/1/144670.jpg

      Krstićs team has already pinned down the security policy and threat model for the BIOS, the built-in software that runs when the machine is turned on. The machine, he said, will feature a completely secure BIOS solution that allows fully automatic upgrades without user intervention and fully protects against phishing and automated worm attacks.

      “Many of these kids will have never seen a computer before; they wont have a clue about computer security. That means that a lot of mechanisms in computers today just wont work for them,” Krstić said, stressing that everything on the laptop will be open by design and will not rely on passwords for authentication.

      /zimages/1/28571.gifFour countries commit to buy 4 million OLPC laptops. Click here to read more.

      “One of the main goals is to provide unobtrusive security,” he added. “Were doing security in a way that doesnt depend on the user reading or responding to a prompt on the screen.”

      The key design goal, Krstić explained, is to avoid irreversible damage to the machines. The laptops will force applications to run in a “walled garden” that isolates files from certain sensitive locations like the kernel. Even if the computer is damaged, the security model calls for a trivial reinstall of the operating system to put the machine back into full functionality.

      Despite the security fears, Krstić is optimistic OLPC has a few aces up its sleeve. “We dont have backward compatibility on our list of concerns. Thats a huge advantage,” he said. Without having to worry about existing applications, Krstić said OLPC can actually define the security policy for every piece of software built for the machine.

      “We can tell people, If youre developing software, this is the policy,” he said. “We dont have to worry about thousands of apps that will retroactively break. It gives us an enormous level of control.”

      Still, there are crucial security decisions that are still up in the air. For example, the group is still brainstorming about whether to include automatic updates by default. Krstić is leaning toward implementing automatic updates, but, ideally, if the security model holds up, he expects OLPC to have a level of isolation between the operating system, applications and user data that will reduce the need to issue lots and lots of updates.

      “If we discover vulnerabilities, the security model must hold up enough that even a machine that is unpatched wont be easily exploitable. This gives us a bit of diversity to avoid the monoculture trap,” he said.

      Next Page: Automatic updates a “tricky” issue.

      Page 2

      The issue of automatic updates, he said, remains “tricky” because of the difficulty in making strong assumptions about connectivity. The $100 laptops will feature built-in wireless mesh networking—allowing each laptop to connect to other laptops and work as a wireless mesh router when it is powered down—but the absence of strong connectivity to pull down updates could be awkward.

      /zimages/1/28571.gifThe $100 laptops should teach vendors a lesson. Click here to read Jim Rapozas column.

      “The focus of my work is to make sure that dependence on updates is as minimal as possible,” Krstić added.

      Dave Aitel, an open-source advocate and vulnerability researcher at Immunity, in Miami, said fears of an OLPC monoculture presenting a major security risk may be a bit overblown. “Who wants to [hack] these children anyway? These laptops are not Windows 95, and, in many ways, theyre more advanced than [Microsofts] Vista,” Aitel said in an interview.

      “Its a monoculture of hard targets,” Aitel said, noting that the laptops will use a modern implementation of Linux hardened with ASLR (Address Space Layout Randomization) to handle code-scrambling diversity and Exec Shield, a security patch that flags data memory as nonexecutable and program memory as nonwritable.

      Walter Bender, president of software and content at OLPC, said the foundations long-term goal expressly encourages computing diversity and argued that the “monoculture” tab might be a bit strong.

      “Were designing this machine as an open platform with the expectation that its going to evolve,” Bender said in an interview. “Even though were launching a monoculture, experience has shown that these open platforms evolve and change. Theres no reason to think this wont happen with these machines.

      /zimages/1/150274.jpg

      “We dont expect that a monoculture in the strict sense, where were controlling everything, will last very long,” he added.

      Bender insists that the overall goal of OLPC is to encourage diversity. “In the short term, were trying to launch something,” he said. “Were a nonprofit, educational organization; were not a laptop manufacturer. Were developing an ecosystem that people can expand and bring to kids. Its anything but a monoculture.”

      The OLPC foundation, which traces its roots to Massachusetts Institute of Technology, is sponsored by a roster of big-name companies, including Advanced Micro Devices, eBay, Google, News Corp., Nortel Networks and Red Hat.

      /zimages/1/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Ryan Naraine
      Ryan Naraine

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.