Hacker News new | ask | show | jobs
by bad416f1f5a2 1293 days ago
No hand waving: what “one subtle thing” will this insider do to make this attack possible? I’m guessing FIPS 140-2 has already thought about it.

HSMs are hardened against individual bad actors. Their threat model envisages the presence of nation state actors.

Is it possible that an HSM attack happened here? I wouldn’t bet on it.