All the really high end stuff is in financial data centers anyway, surrounded by TV cameras 24/7. Tamper reactance in the HSM itself is cool and everything but the surrounding security handles a lot of what the HSM is made to do.
Side-channel ignorance: none of the SW solutions are properly zeroing the data. Side-channels can still read them. SW vendors refuse to do that because of performance. Clearing the caches is too expensive.
That's not surprising. FIPS 140 is primary a signalling mechanism for how desperate you are to sell to the USG and USG-affiliated organisations, not a security indicator. Only a company prepared to set fire to $100k or more gets to play.
4 comments
[ 0.21 ms ] story [ 17.0 ms ] thread