Hacker News new | ask | show | jobs
by philsnow 143 days ago
The HSMs that Signal and Apple are using are on-device though. Yes you still have to trust Signal / Apple to not exfil your key matter once decrypted by the HSM, but I submit that that is materially better than having the HSMs be hosted in a datacenter.
1 comments

Signal and Apple and Google all use HSMs in datacenters as well as on device.