2 ms·
I definitely prefer an open standard, (preferably where it can be attested that it is disabled) over possible proprietary implementations being setup with vendo
by monkeybutler 4y ago
I definitely prefer an open standard, (preferably where it can be attested that it is disabled) over possible proprietary implementations being setup with vendor generated pins before purchase, etc..
Based on simcards and similar, I don't think the pin situation is actually that nice for a user. You can choose from re-entering it often on the possibly keylogged device you didn't want to trust, forgetting it, having it on a piece of paper next to the token. Then you need a way for malicious code or user error to DOS it so that it can be short, then people start to ask why there is no escrow of a management puk. I'm exaggerating the limitations a bit, but the foot guns of having a plan that works seem to add up.
As with enterprise HSMs I think there is always a conflict of adding features and ways to recover from every possible mistake that erode the few clear security USPs that one can put together to just make and take an understandable risk trade off.