2 ms·
If you use a smartcard, you should use a class2/class3 card reader with pin-pad and never enter the pin on you computer. So the machine can replace the hash tha
by cleeus 10y ago
If you use a smartcard, you should use a class2/class3 card reader with pin-pad and never enter the pin on you computer. So the machine can replace the hash that is to be signed, but cannot intercept and replay the PIN.
- nickpsecurity 10y agoIt's not always possible but should be whenever possible. The concept is called a trusted path: an unspoofable, un-interceptable interface between the user and the security-critical part of the system. Was required for all high-assurance security under the Orange Book. Still used in some HSM and payment sectors. Example for other readers on p4 under Luna PCI and Igenico reader that looks like it's a kid's pocket calculator haha: https://www.keyon.ch/de/Produkte-Loesungen/SafeNet-HSM/HSM_TrueHardware-basedKeyManagement_NextGenPKIApps_FB_-EN-_web.pdf https://www.keyon.ch/de/Produkte-Loesungen/SafeNet-HSM/HSM_T... http://www.smartcardsource.com/contents/en-ca/Ingenico_myleo.pdf http://www.smartcardsource.com/contents/en-ca/Ingenico_myleo...