Hacker News new | ask | show | jobs
by UnoriginalGuy 3979 days ago
When you're signing a binary blob, protecting the private key is actually pretty easy since it can be air-gapped/offline. Or heck you can buy appliances where they'll perform specific functions using the private key but won't expose it themselves without physical intervention.