5 ms·
Again and again, we've seen that HSMs aren't secure against physical access of the device.
by mhluongo 6mo ago
Again and again, we've seen that HSMs aren't secure against physical access of the device.
- bob1029 6mo agoCan you point me to an example of a FIPS level 3+ certified device having its private keys compromised due to a defeat of the tamper resistant boundary?
- mhluongo 6mo agoHere are a couple examples of physical access leading to key extraction. You're welcome to be pedantic (those are side channel attacks, they don't defeat the boundary!) but one way or another, physical access wins. https://www.cl.cam.ac.uk/~rnc1/descrack/ https://www.cl.cam.ac.uk/~rnc1/descrack/ https://ninjalab.io/eucleak/ https://ninjalab.io/eucleak/