Skip to content

Comment on Prevent cold boot attacks using TRESORparent

Comments

For servers, a lot of these vectors go away, and if you're theoretically deploying 10k servers, you can spec the controllers, microcode, etc.

I gave up on PC desktops for security a long time ago; just use mobile, tablets, and things like ChromeOS for that. ARM with TrustZones should be enough to fairly easily build something.

What I'd really like is a physically tamper-responding tablet. i.e. the touchscreen, physical enclosure, and all ports sealed in an HSM-like enclosure, such that if you tamper with it, it zeroizes a platform security key, which can be used to remotely attest "I haven't been tampered yet" to servers before communicating. You would then do some kind of physical enclosure size/seals/standards to protect from skimmers layered outside the trusted device, and then some kind of device to user authentication to prove it's a valid device before entering information on it. You could pretty much build this on Android today.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.