3 ms·
"The HSM-based Backup Key Vault will be responsible for enforcing password verification attempts and rendering the key permanently inaccessible after a limited
by MarkMc 5y ago
"The HSM-based Backup Key Vault will be responsible for enforcing password verification attempts and rendering the key permanently inaccessible after a limited number of unsuccessful attempts to access it"
Is this standard practice for HSM? It seems to give hackers the ability to maliciously delete the users key and thereby effectively delete the users data.
- willxinc 5y agoHSMs typically will have a fixed number of login attempts that reset only on successful login. If the password verification attempts are passed through directly to the HSM, then yes, this is standard.