| > How useful are such measures when Intel has backdoored each and everyone of their CPUs with its "Intel Management Engine" [0] (and AMD has a similar mechanism)? If you trust this YubiHSM but not Intel CPUs, then it is very useful since encryption/decryption occurs on the YubiHSM, not the connected CPU. Just plug it into a computer with a CPU you do trust first to get the official public key(s) for future verifications! If you don't trust this YubiHSM because of the example of Intel CPUs, then please share at what point you do trust third party hardware, so we can discuss how to get to useful encryption from there. Would you only trust RAM you wire-wrapped yourself? Would you only trust a motherboard you built from 7400 series logic gates, each of which you personally verified using X-rays? The line has to be drawn somewhere, but without knowing where you want to do so your comment serves mostly to hijack discussion (which is fine). |