TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Yubico announces tiny, cheap YubiHSM 2

138 pointsby procrastinatusover 7 years ago

15 comments

benevolover 7 years ago
How useful are such measures when Intel has backdoored each and everyone of their CPUs with its &quot;Intel Management Engine&quot; [0] (and AMD has a similar mechanism)?<p>If Intel&#x2F;AMD have a backdoor into every PC and server, then so does the US gov&#x27;t (NSA, CIA, FBI, etc.) and of course other uninvited hackers from even hostile countries.<p>And how did Western society just accept all of this anti-democratic craziness?<p>[0] <a href="https:&#x2F;&#x2F;libreboot.org&#x2F;faq.html#intel" rel="nofollow">https:&#x2F;&#x2F;libreboot.org&#x2F;faq.html#intel</a>
评论 #15609868 未加载
评论 #15609655 未加载
评论 #15608956 未加载
评论 #15609417 未加载
评论 #15610558 未加载
评论 #15609055 未加载
评论 #15609209 未加载
评论 #15609084 未加载
confoundedover 7 years ago
What&#x27;s the advantage of this over the ~$100 open source NitroKey HSM?<p><a href="https:&#x2F;&#x2F;www.nitrokey.com&#x2F;files&#x2F;doc&#x2F;Nitrokey_HSM_English.pdf" rel="nofollow">https:&#x2F;&#x2F;www.nitrokey.com&#x2F;files&#x2F;doc&#x2F;Nitrokey_HSM_English.pdf</a>
评论 #15608030 未加载
评论 #15608034 未加载
unwindover 7 years ago
No mention of the actual hardware (processor) they&#x27;ve used. I guess the bill of materials would be funny (although of course I realize that the value is in their expertise and software etc).<p>The performance specs [1] say &quot;HMAC-SHA-(1|256): ~4ms avg&quot; which I guess is for 256 bits [2], compared to [3] which list a 6th gen Skylake 3.1 GHz doing it at 535 MB&#x2F;s.<p>[1]: <a href="https:&#x2F;&#x2F;www.yubico.com&#x2F;products&#x2F;yubihsm&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.yubico.com&#x2F;products&#x2F;yubihsm&#x2F;</a><p>[2]: But I have no idea, perhaps this is a stupid interpretation, in which case I&#x27;ll turn around and blame them for being unclear.<p>[3]: <a href="https:&#x2F;&#x2F;www.cryptopp.com&#x2F;benchmarks.html" rel="nofollow">https:&#x2F;&#x2F;www.cryptopp.com&#x2F;benchmarks.html</a>
Shtirlicover 7 years ago
I must add this post <a href="https:&#x2F;&#x2F;plus.google.com&#x2F;+gregkroahhartman&#x2F;posts&#x2F;WK6ZLEhfQo5" rel="nofollow">https:&#x2F;&#x2F;plus.google.com&#x2F;+gregkroahhartman&#x2F;posts&#x2F;WK6ZLEhfQo5</a> Is it open source? &quot;Yubico has replaced all open-source components that made yubikey NEOs so awesome with proprietary closed-source code in Yubikey 4s&quot;
lisperover 7 years ago
An even lower cost (and open-source) alternative:<p><a href="https:&#x2F;&#x2F;sc4.us&#x2F;hsm" rel="nofollow">https:&#x2F;&#x2F;sc4.us&#x2F;hsm</a><p>The SC4-HSM also includes dedicated I&#x2F;O (a display and two buttons) which makes it more secure than the Yubikey.<p>Disclosure: this is my product.
评论 #15612795 未加载
synicalxover 7 years ago
Never really touched one of these HSMs before, what happens if you&#x27;re using one in production and it dies?
评论 #15611501 未加载
评论 #15608295 未加载
davidpelaezover 7 years ago
This is amazing and literally filling a void for companies aware of the benefits but lacking the budget. There&#x27;s one last barrier though: how to use this in the cloud? A partnership with AWS to have this as a service would be amazing because their HSM offering is not affordable and also because for many compliance reasons companies use AWS (PCI DSS for example) and there would be no way to include HSM 2 there. Let&#x27;s hope this happens!
hdhzyover 7 years ago
I hope te EdDSA curve 25519 support in YubiHSM2 means we&#x27;ll see the curve also in Yubikeys (e.g. OpenPGP applet). Currently Yubico&#x27;s OpenPGP supports only RSA but there are already tokens supporting this modern crypto [0].<p>[0]: <a href="https:&#x2F;&#x2F;debconf17.debconf.org&#x2F;talks&#x2F;162&#x2F;" rel="nofollow">https:&#x2F;&#x2F;debconf17.debconf.org&#x2F;talks&#x2F;162&#x2F;</a>
评论 #15611473 未加载
wav-partover 7 years ago
How can HSMs be considered MITM-proof if does not have dedicated input system (touchscreen&#x2F;keyboard) ?
评论 #15609524 未加载
评论 #15609953 未加载
gumbyover 7 years ago
Think there&#x27;s a chance we could get a Type C key someday that&#x27;s as small as that (well, literally smaller, but I&#x27;m thinking something not much larger than the shell that will stick out of my machine about as much as that Type A one does.
评论 #15608401 未加载
评论 #15608410 未加载
babarover 7 years ago
How much of a market is there for HSMs that are not FIPS 140-2 certified?
评论 #15608240 未加载
评论 #15608089 未加载
评论 #15608331 未加载
评论 #15611984 未加载
xelxebarover 7 years ago
I know very little about hardware security. What are some of the issues that HSMs address that make R&amp;D so challenging?
评论 #15611497 未加载
nikolayover 7 years ago
$650 is cheap?
评论 #15607996 未加载
评论 #15608153 未加载
评论 #15610410 未加载
yositoover 7 years ago
I bought a Yubico key once. The thing was so cheap that between the time I set it up and the first time I actually had to use it, it had disintegrated just from sitting in my pocket every day on my keychain. The plastic was brittle and fell apart piece by piece until eventually the electronics fell apart too.
评论 #15610409 未加载
xchaoticover 7 years ago
More generally why is this not $3. Can we get a Kickstarter for this please?
评论 #15609236 未加载
评论 #15608669 未加载