Earlier quoted context omitted.
At least in my mind, the defining attribute of an HSM is protection against physical compromise of the device. Maybe we disagree on that definition: I guess it is hardware, and it exists for security, and it's a module. I admit it's unfair to compare this with a $10,000 HSM from Thales or Safenet, of course. But it seems like a smartcard based solution might be better on that front, as they're designed to withstand p…
> smartcard Those are not at all secure against compromised hosts. > EM/RF emissions You probably don't want to use this to secure the nuclear launch codes. But I think you'd have to work pretty damn hard to get anything out of it. There are no external parts here, it's all one SoC, one that is specifically designed to keep proprietary code out of the hands of Chinese hackers. If it were easy to attack it would lose…
> Those are not at all secure against compromised hosts.
How so? Certainly there are poorly designed applications on smartcards that are vulnerable, but the smartcard itself should be fine.