Yubico announces tiny, cheap YubiHSM 2
31–40 of 94 posts
Re: Yubico announces tiny, cheap YubiHSM 2
#32How useful are such measures when Intel has backdoored each and everyone of their CPUs with its "Intel Management Engine" [0] (and AMD has a similar mechanism)? If Intel/AMD have a backdoor into every PC and server, then so does the US gov't (NSA, CIA, FBI, etc.) and of course other uninvited hackers from even hostile countries. And how did Western society just accept all of this anti-democratic craziness? [0] https:…
Re: Yubico announces tiny, cheap YubiHSM 2
#33How useful are such measures when Intel has backdoored each and everyone of their CPUs with its "Intel Management Engine" [0] (and AMD has a similar mechanism)? If Intel/AMD have a backdoor into every PC and server, then so does the US gov't (NSA, CIA, FBI, etc.) and of course other uninvited hackers from even hostile countries. And how did Western society just accept all of this anti-democratic craziness? [0] https:…
Re: Yubico announces tiny, cheap YubiHSM 2
#34How useful are such measures when Intel has backdoored each and everyone of their CPUs with its "Intel Management Engine" [0] (and AMD has a similar mechanism)? If Intel/AMD have a backdoor into every PC and server, then so does the US gov't (NSA, CIA, FBI, etc.) and of course other uninvited hackers from even hostile countries. And how did Western society just accept all of this anti-democratic craziness? [0] https:…
However that is no reason not to use good security otherwise.
> And how did Western society just accept all of this anti-democratic craziness?
Because people buy it voluntary.
Re: Yubico announces tiny, cheap YubiHSM 2
#35More generally why is this not $3. Can we get a Kickstarter for this please?
It was also featured on HN: https://news.ycombinator.com/item?id=12053181
Re: Yubico announces tiny, cheap YubiHSM 2
#36Re: Yubico announces tiny, cheap YubiHSM 2
#37Re: Yubico announces tiny, cheap YubiHSM 2
#38How useful are such measures when Intel has backdoored each and everyone of their CPUs with its "Intel Management Engine" [0] (and AMD has a similar mechanism)? If Intel/AMD have a backdoor into every PC and server, then so does the US gov't (NSA, CIA, FBI, etc.) and of course other uninvited hackers from even hostile countries. And how did Western society just accept all of this anti-democratic craziness? [0] https:…
Western societies, so as not to upset the guise of freedom and personal rights to privacy, do so in secret but it's not exclusive to them. China publicly mandates government backdoors into their equipment too.
Re: Yubico announces tiny, cheap YubiHSM 2
#39How useful are such measures when Intel has backdoored each and everyone of their CPUs with its "Intel Management Engine" [0] (and AMD has a similar mechanism)? If Intel/AMD have a backdoor into every PC and server, then so does the US gov't (NSA, CIA, FBI, etc.) and of course other uninvited hackers from even hostile countries. And how did Western society just accept all of this anti-democratic craziness? [0] https:…
HSMs are not protections against the gocernment. Simple as that
Re: Yubico announces tiny, cheap YubiHSM 2
#40How can HSMs be considered MITM-proof if does not have dedicated input system (touchscreen/keyboard) ?
Even most 'dedicated' systems do NOT have a direct link to the input terminals most of the times since they are simple usb keypads. Some smartcard readers for PC have pin-pads but this is rarely the case and they are way more expensive than a keyboard and a regular reader. The normal way is to process transaction data through the hsm, and onto the terminal after which the user has to see/check (on the terminal) if the data is correct. This is how the better (not best) Bank-transaction-verifiers work. A secure connection to the pinpad/terminal has and can be set up (either in advance, via a pre-known mechanism or ad-hoc), but there are some attack vectors there as well.
HSMs are not "MITM proof", the system at-large has to be. Using a HSM does not give you MITM proofness, but makes it sure the old-fashioned 'steal the private key and act like nothing happened' won't happen. Stupid design choices or even simple "call them and ask for a new intermediary certificate" sometimes cause more harm. You CA Root/CSP keys are safe but you are still screwed. Unless you steal the usb drive of course. There are still other ways to do a mitm though.
The main advantage is for small and medium businesses that they won't have to buy a hugely expensive ethernet/pcie HSMs from the known companies which are hugely overpriced (I have several on my desk and they range from 1-2K to 10K+, which are the cheap ones). It also helps with some legal compliance if YubiCo can get it FIPS 140-2 approved (which I doubt).
Considering they made it small, I guess they need to provide some form of duplication/backup since people are going to lose them.