3 ms·
Could be in a TPM as well.
by 1001101 5y ago
Could be in a TPM as well.
- monocasa 5y agoTPMs are pretty slow; the LPC bus they sit off of is basically run at ISA bus speeds.
- nitrogen 5y agoMaybe they used TPM when they meant HSM
- monocasa 5y agoEven then, it's probably too high of latency. These Netflix caching boxes are perennially the subject of "this is how you TLS at line rate and memory bandwidth limits" talks. When you combine this with the fact that these boxes aren't just installed anywhere, but deep inside ISP networks, and ostenisbly the certs aren't for *.netflix.com, but instead for either that specific ISP or even that specifc box, _and_ the certs need to be remotely updated anyway, so they can't just live in an HSM the whole time, I'd just store them on disk if I were Netflix.
- soneil 5y agoWouldn’t HSM only be needed for the private key though? Once it’s in memory it’s free
- monocasa 5y agoAnd you need the private key for every new TLS connection. And when you are running multiple 100Gb interfaces, that's a lot of TLS connections. Versus, what's the attack? The ISP with physical access to the box can pull can screw with the cached video data somehow? Or MitM and know what Netflix videos their users are watching?