4 ms·
I am personally involved in procurring HSMs for regulatory reasons. I would be more than happy to deploy an alternative solution that's demonstrably better suit
by _1tan 3y ago
I am personally involved in procurring HSMs for regulatory reasons. I would be more than happy to deploy an alternative solution that's demonstrably better suited for threats in todays typical cloud environments and fight it out with the regulator. The author sadly doesn't answer that question. Anyone having an idea?
- tptacek 3y agoWhat's the reg you're up against that says your need an HSM?
- 616c 3y agoAlso CAB Forum has started to require private keys in HSM only for code signing certs.
- cpach 3y agoYes, but you can outsource that part to Digicert et al, so that you don’t need to buy the HSM yourself.
- _1tan 3y agoE.g. this: https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Smart-metering/Smart-Meterin-PKI/smart-meterin-pki_node.html https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisati... I am aware of industry talks of lobbying on behalf of HSM manufacturers that led to these requirements and that's just sad.
- awaythrow999 3y agoPretty sure ETSI demands it for trusted service providers https://portal.etsi.org/TB-SiteMap/ESI/Trust-Service-Providers https://portal.etsi.org/TB-SiteMap/ESI/Trust-Service-Provide...
- lxgr 3y agoHow about confidential computing, e.g. AWS Nitro enclaves, Intel TDX etc? HSMs make most sense when they’re performing high-level operations (“Is this credit card CVC valid?”); when used as signature or decryption oracles (“Hi, I’m a trusted application server, now sign this email!”) their security gain rapidly diminishes. Sometimes they get used for key storage alone (“Hi, I’m an application server booting up, give me the RSA signing key for account x!” or even worse “Hi, I’m an application server booting up, give me the key wrapping all the user keys in our database!”), with obvious implications. Getting an HSM vendor to implement your use case can get very expensive; confidential computing lets you do it yourself, i.e. draw a much larger “trusted” box in your architectural diagram than otherwise feasible.