Hacker News new | ask | show | jobs
by plugger 2310 days ago
Don't know who they are but there's some speculation that Yubico is Crypto AG like.
3 comments

This is testable, and also very difficult to falsify without testing it. I'd say there is more value in doing or sponsoring the research to investigate it and I wouldn't cast aspersions on the vendors. They are better than passwords for the majority of consumer and corporate use cases.

The most basic attack and test is to verify and/or reduce the entropy of secret symmetrical (AES) keys in the SE after personalization.

The challenge with hardware security modules is verifying outputs from the same keys but on different devices, because the key is derived/instantiated in the secure tamper proof environment. The whole point is the key doesn't exist anywhere else.

If your threat model includes the intelligence agencies of super powers, your main problem is more diplomatic than technical.

Not by anyone with half a clue there isn’t.
This is such a lame conspiracy theory that me and lawnchair_larry are on the same side of it.
Can you link to a source for that?
Have a look at the comments regarding the recent Crypto AG story here. There's some insinuation in there.
This one? https://news.ycombinator.com/item?id=22297963

I did a ctrl + f on both pages of comments for "yubi" with no results. Sorry if I've missed something obvious.