Skip to content

Building a More Assured Hardware Security Module [pdf]

ripe69.ripe.net
31 pointsbracewel14 comments
On HN

Comments

Regarding HSMs, a great read is the Cambridge team that broke the Luna CA3 Chrysalis HSM. A great reversing tale. "Unwrapping the Chrysalis": http://www.war-room.co.uk/~dc352/UCAM-CL-TR-592.pdf

Search around for more- I remember them having a few different write-ups.

Great tip, thanks!

The wiki[1] says that

"Recent revelations have called into question the integrity of some of the implementations of basic cryptographic functions and devices used to secure communications on the Internet. There are serious questions about algorithms and about implementations of those algorithms in software and particularly hardware."

I'm curious about that, does anybody here know about these recent revelations? I understand the feeling, but I don't remember seeing any news about the security of HSM recently, or ever actually.

[1]: http://wiki.cryptech.is -- see JoachimS' comment

Man powerpoint presentations after the fact are all but useless for conveying the original point.

Might not want to use pink comic sans on a slide deck if you want be taken seriously...

I'm not sure if it's the NetBSD crowd or some general crypto-focused community, but there's a theme going on about presenting and publishing on security in comic sans. The goal is to see what you are more focused on: the slickness of the presentation or the correctness of the code.

https://mobile.twitter.com/Nambitious/status/595230807138111...

I remember coming across quite a few networking-related slide sets that were almost exclusively in comic sans; they might've come from a widely used book, and it's not too far of a stretch to think that the trend spread over into security too.

many OpenBSD developers use comic sans intentionally in their presentations.

That's it. I said NetBSD, but meant OpenBSD.

yup. I was excited to read this until....oh no....hot pink comic sans. Had to close me eyes for a second to recalibrate. Don't make it such an effort to have to get over the barrier to the knowledge.

Where is the call to action (where do you engage to get involved?)

The front page is here: https://cryptech.is More tech info etc are here: http://wiki.cryptech.is

We use mail lists. The second link Provides links to archives, sign up info. There you also find web access to all repos.

And if there are questions esp related to the digital HW side of Cryptech just ask and I'll try to answer.

BTW, your wiki's certificate is untrusted, because it was issued for "bikeshed.cryptech.is".

Yes, that is correct and by design.

It boils down to (the lack of) trust in the CAs and the HSMs they use. Basically.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.