Hacker News new | ask | show | jobs
by pxc 1033 days ago
> Now you want me to lug around a 2U HSM appliance?!

If you don't need a certified HSM that generates keys on device (and you don't, right? You can generate keys on a ramdisk from live media with no persistence and no/encrypted swap), you can use basically any PGP smartcard, including nice little USB ones like Yubikey and NitroKey. And even if you do you can get a little USB HSM.