Hacker News new | ask | show | jobs
by usbreply 4217 days ago
Have you seen the mikeselectricstuff youtube channel ? He did a teardown of a credit card reader. The "self wipe" functionality is implemented in a fairly simple way.
2 comments

HSMs are on an entirely different level compared to credit card readers.

To OP, those devices are not cheap - they run $22k from SafeNet (dependent on what model, obviously). In addition, FIPS criteria is meant to be tamper evident (not tamper resistant). SafeNet does require a special key to recover after a tamper attempt, though: http://goo.gl/RyVtFj

HSMs also vary by manufacturer. The SafeNet Luna you linked to has both tamper as the case level and tamper as the actual HSM level. If you read the FIPS documentation for the SafeNet Luna SA, it has a PCIe card inside with a cryptographic module on the card that is the core to the system. Tampering with that is ever more destructive than just opening the case.
Depends on the reader I think. I would be interested to see what he did there.

Credit card readers get scored on how hard they are to attack, and pass above some threshold based on difficulty of attack and time taken.