Skip to content

Comment on On Hacking MicroSD Cardsparent

Comments

Yeah, the pressure of NSA demanding access on anything resembling HSM is obvious. Anything that's not open source has the potential to hide undesired behavior.

Also, more fun would be "cryptolocker" disk-based malware. The aspects of capability exist elsewhere today as mentioned in the article and cryptolocker's $15 million USD and counting.

Also also: is there any HIDS yet for checksumming various chipset/peripheral firmwares?

I'm doing a talk on an open hw design/open source HSM at ShmooCon in a month or so, which seems like the only viable way to deal with this threat.

TCG (TPM, TXT, ...) Measured boot sort of includes firmware checksumming. It's often turned off.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.