Single post

jump to replies

4 visible replies; 2 more replies hidden or not public

back to top
Electronic Eel , @electronic_eel@treehouse.systems
(open profile)

@nyanotech interesting idea!

one thing that i didn't see (or missed while skimming the paper) is what they do when you remove power. you need a lot of power to keep rotating your HSM, so batteries are impractical. a conventional mesh can be easily monitored for weeks just from a battery inside the security envelope.

a power down will obviously be visible from the outside. but the attacker might provide some plausible explanation for a power outage while compromising the HSM. also initial deployment of the HSM might open a attack window while it is transported to the final datacenter in powered down state.

Open remote post (opens in a new window)