4 ms·
An HSM is a device that's meant to hold keys, allow you to use them, but never allow you to access them. In other words, it's a true digital 'key' that can't b
by dmayle 6y ago
An HSM is a device that's meant to hold keys, allow you to use them, but never allow you to access them. In other words, it's a true digital 'key' that can't be copied.
If you truly care about the encryption on your servers, for example, then normally your server can't boot/decrypt the drive without an HSM (which you aren't supposed to leave plugged in). You give one to your CEO, your CTO, and your CFO, for example, and you require that at least two of them are present to boot your servers (to prevent attack by theft).
There are more fault-tolerant possibilities out there (e.g. Hashicorp Vault), but they're generally bootstrapped from HSMs.