Hacker News new | ask | show | jobs
by bob1029 82 days ago
Can you point me to an example of a FIPS level 3+ certified device having its private keys compromised due to a defeat of the tamper resistant boundary?
1 comments

Here are a couple examples of physical access leading to key extraction. You're welcome to be pedantic (those are side channel attacks, they don't defeat the boundary!) but one way or another, physical access wins.

https://www.cl.cam.ac.uk/~rnc1/descrack/ https://ninjalab.io/eucleak/