ORWL Aspires To Be A Secure PC - InformationWeek

InformationWeek is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Infrastructure // PC & Servers
12:05 PM
Connect Directly

ORWL Aspires To Be A Secure PC

The small, tamper-resistant device is the focus of a Kickstarter campaign. Olivier Boireau, CEO of Design SHIFT, makers of the ORWL, said he believes the device will appeal to companies interested in privacy and data security.

HP Milestones: A Look Back, As Tech Giant Splits In Two
HP Milestones: A Look Back, As Tech Giant Splits In Two
(Click image for larger view and slideshow.)

Olivier Boireau, CEO of Design SHIFT, stopped by InformationWeek's San Francisco office last week to demonstrate ORWL (pronounced Orwell), a small, tamper-resistant computer scheduled to ship around May 2016. He visited in advance of a presentation at Black Hat Europe and a Kickstarter funding campaign planned for today.

Although desktop computers have been eclipsed by mobile devices, ORWL is highly mobile. It's about the size of large doughnut. The device's portability, not to mention its visual appeal, might make it tempting for thieves, but stealing it would be pointless for all but the most sophisticated adversaries.

(Image: Thomas Claburn)

(Image: Thomas Claburn)

ORWL is designed for security, specifically hardware security. Boireau said that in many organizations today, little thought is given to preventing hardware-based attacks. An adversary could insert a USB drive in an unattended PC, or add a compromised component, and it's unlikely the device's user or IT personnel would be aware.

Even if such scenarios seem unlikely, there's something to be said for hardware that isn't the weak link in the security chain.

[Check out how technology has derailed C-Level careers. Read 14 Security Fails That Cost Executives Their Jobs.]

Boireau said ORWL is roughly comparable to a Lenovo Yoga in terms of processing power. It's not intended for processor-intensive applications like Autodesk's Maya, but it's well-suited for business applications, accessing databases, and browsing.

ORWL can run Linux or Windows. It supports open source software, and the plan is to be as open as possible with the hardware. It's based on Intel's sixth-generation Core M processor family, with Intel HD graphics. The device's planned memory capacity ranges from 2GB to 8GB DDR3 1600MHz, with SSD storage ranging from 64GB to 512GB. It will come with two USB Type-C ports and a mini-HDMI port. Pricing should range from around $600 to $1,300, with a disassembled version planned for about $400.

(Image: Design SHIFT)

(Image: Design SHIFT)

The device is designed as if it were a payment terminal. Boireau, who said he began his career developing electronic warfare technology for the French military, said that ORWL incorporates what his company learned by designing PCI 4.0 compliant devices for Clover, which sells point-of-sale hardware. He said he expects the device will be FIPS140-2 compliant, level 3 or level 4, at least in terms of hardware.

Part of such compliance has to do with how personnel manage keys, said Boireau. "I don't think I want to do that part, but I will do all the hardware certification," he said.

Boireau emphasized that ORWL is not intended to be impervious to all vulnerabilities. A TEMPEST attack -- to read data through electronic emanations -- might be feasible, for example. "If you are at home, I would argue a Bluetooth keyboard is okay," he said. "If you have the NSA behind you [reading your keyboard transmissions], you have bigger problems."

Accessing the device requires an NFC hardware key as well as a password. If the user walks more than 10 meters away with the key, ORWL will lock and disable the data ports. And if ORWL itself is moved while locked, it will shut down, leaving data on the SSD protected by AES256 encryption. Boireau said organizations could affix a hardware key in a data center to allow ORWL to operate unattended as a server in that specific location.

(Image: Thomas Claburn)

(Image: Thomas Claburn)

The device is protected by an active mesh in its casing. Any attempt to breach the case, made of a type of brittle plastic that's prone to shatter if punctured, triggers the MAXIM controller to delete the encryption key that grants access to the user's protected data.

Boireau said he believes the device will appeal to companies and to consumers interested in privacy and data security. "In the corporate space, once you do two-factor authentication, which is what we do here, you can create secure endpoints to a shared database," he said. "So in medical, I think it's essential, and for government and the military. Lawyers and accountants also share this need. You don't want your database to just walk away."

If it does, ORWL has your back.

"We think it enables free communication, once you trust the hardware," said Boireau. "I think it should be everywhere."

Thomas Claburn has been writing about business and technology since 1996, for publications such as New Architect, PC Computing, InformationWeek, Salon, Wired, and Ziff Davis Smart Business. Before that, he worked in film and television, having earned a not particularly useful ... View Full Bio

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.
Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
11/24/2015 | 5:53:41 PM
Protecting data
This device is an intriguing way to manage hardware security. For those with sensitive data on laptops while travelling I imagine this might be a good way of making sure nothing is compromised.
2021 Outlook: Tackling Cloud Transformation Choices
Joao-Pierre S. Ruth, Senior Writer,  1/4/2021
Enterprise IT Leaders Face Two Paths to AI
Jessica Davis, Senior Editor, Enterprise Apps,  12/23/2020
10 IT Trends to Watch for in 2021
Cynthia Harvey, Freelance Journalist, InformationWeek,  12/22/2020
White Papers
Register for InformationWeek Newsletters
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you.
Flash Poll