Live data from Hacker News

Why I don't like smartcards, HSMs, YubiKeys, etc.

devever.net

1–10 of 139 posts

Re: Why I don't like smartcards, HSMs, YubiKeys, etc.

#4
This is a somewhat older rant (at least 2015, I think). And the title is misleading. It is really "Why I wish there were a product similar to but different than smartcards, HSMs, YubiKeys, etc." Because there isn't much in there that argues why smartcards (or yubikeys, etc.) are not good at what they do. The author just wants a different thing, and doesn't understand why this fantasy product doesn't exist.

Re: Why I don't like smartcards, HSMs, YubiKeys, etc.

#6
The author brings up many reasonable points but seems to mix issues of HSMs & Smart Cards not providing a generic open hardware platform with possible security problems of a platform.

There is no question that there would be value in having a hardware platform that has certain security features, but that alone doesn't meet the requirements of most users of HSMs and Smart cards. The primary use cases I've seen are allowing a third party to have assurance of protection of data stored in the device and assurance of the rules for accessing the data. In most cases this assurance comes from a combination of the hardware itself and the software/firmware running on the hardware. A hardware platform only solves half the problem that most purchasers of HSMs and smart cards are asking vendors to solve.

Re: Why I don't like smartcards, HSMs, YubiKeys, etc.

#7
The issue of affordable HSM/TPM for general purpose use is something my research group is trying to solve. We have most of the theory down, but the implementation is a work in progress. The key point is trying to maintain full physical isolation from the CPU and OS, while also providing general low-level computing capabilities.

Do you guys think something like this could be patented and/or commercialized?

Re: Why I don't like smartcards, HSMs, YubiKeys, etc.

#8
The author is not thinking about why these things are built and marketed as they are.

The use case for the smart card is different than a HSM with FIPS 140-2 level 3 or 4 validation. The whole point is to operate in a tested, known valid state while resisting tampering. The higher level devices are filled with epoxy and have other anti-tampering features.

A smartcard is most often a form of MFA. It can be used as an HSM of sorts, but offers limited benefit for that purpose.

Re: Why I don't like smartcards, HSMs, YubiKeys, etc.

#10
post #4

This is a somewhat older rant (at least 2015, I think). And the title is misleading. It is really "Why I wish there were a product similar to but different than smartcards, HSMs, YubiKeys, etc." Because there isn't much in there that argues why smartcards (or yubikeys, etc.) are not good at what they do. The author just wants a different thing, and doesn't understand why this fantasy product doesn't exist.

you missed the point, which it easy because author is mostly rambling :)

the irony is that smart cards and even SIM cards in your phone are already general secure computers. the problem is that only by spending a lot of money and signing your life away on a NDA you can have access to it. the result: inefficiency beyond belief.

Post reply on HN