TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Inertial HSMs thwart advanced physical attacks

112 pointsby luuover 1 year ago

16 comments

schlowmoover 1 year ago
I&#x27;m not quite sure what happened in my brain when I read the title (probably some kind of lost in translation, translating between my mother tongue and back again), but I didn&#x27;t expect a <i>spinning</i> device.<p>But when I saw the first picture I immediately understood were this is going. Actually it&#x27;s quite clever - as is the subliminal self-irony of the authors. The <i>Swivel Chair Attack</i> made me laugh harder than it should (someone here in the comments already rightfully called for an ig nobel price for that). And still this idea might be a unconventional but working solution.<p>It&#x27;s kind of a refreshing read.
_dain_over 1 year ago
<i>&gt;4.3 The Swivel Chair Attack</i><p><i>&gt;If we assume whoever integrates the payload into an IHSM has done adequate work and prevented all contactless attacks, we are left with attacks that aim at mechanically bypassing the IHSM’s security mesh. The first type of attack we will consider is the most basic of all attacks: a human attacker holding a soldering iron trying to rotate herself along with the mesh using a very fast swivel chair.</i><p>this is amazing. is there an ig nobel for computer science?
评论 #37331894 未加载
评论 #37331445 未加载
cryptonectorover 1 year ago
Why aren&#x27;t MEMS accelerometers enough by themselves?<p>Well, one should build an HSM to have multiple tamper detection sensors:<p><pre><code> - accelerometers - light sensors (the HSM should be sealed in an opaque box) - vibration sensors - temperature sensors - air pressure sensors (the HSM should be sealed in a pressurized airtight box) - moisture sensors (the HSM could be an air- and watertight box inside a water-tight box full of water) </code></pre> Encase the whole thing in a thick layer of resin, leaving only connections for:<p><pre><code> - water (for cooling) - optical ethernet (to avoid electrical attacks on wire ethernet) - an inductive coupling plate to power everything but the water pump - power for the water pump </code></pre> Put this in a locked cabinet in a locked cage in a locked access-controlled room.
评论 #37329425 未加载
评论 #37332863 未加载
评论 #37329383 未加载
评论 #37339124 未加载
beardedwizardover 1 year ago
If there is one thing I learned working with dedicated and eventually advocating for shared hsm (kms, managed hsm, etc) it&#x27;s that HSM routinely have zero days that invalidate the ability to prove the key never left.<p>I&#x27;m curious what folks feel like they are really getting when they buy a physical hsm in 2023?<p>Do we really believe HSM vendors have a greater incentive to patch vulnerabilities than cloud providers who build services on top of them?<p>I 100% trust google more than Thales to keep things patched, and provide the most trustworthy logs.
评论 #37329834 未加载
评论 #37330329 未加载
shiftingleftover 1 year ago
Their talk was quite nice, they talk about experiences with other HSMs, their history, what lead them to design their own, the many aspects of their design and then go through potential attacks:<p><a href="https:&#x2F;&#x2F;youtu.be&#x2F;zD5EdvGs98U?t=13m23s" rel="nofollow noreferrer">https:&#x2F;&#x2F;youtu.be&#x2F;zD5EdvGs98U?t=13m23s</a>
saagarjhaover 1 year ago
I&#x27;ll try spinning–that&#x27;s a good trick!<p>Curious what the model is for an attacker who creates tools that rotate at the same speed as the HSM dynamo, and then controls it remotely in a seemingly stationary reference frame.
评论 #37327562 未加载
1970-01-01over 1 year ago
Just crazy enough to work! I love it. One hole I can poke in the concept is to copy the IR heartbeat signal and retransmit while destroying the mesh.<p>&gt;Besides power transfer from stator to rotor, we need a reliable, bidirectional data link to transmit mesh status and a low-latency heartbeat signal. We chose to transport an 115 kBd UART signal through a simple IR link for a quick and robust solution. The link’s transmitter directly drives a standard narrow viewing angle IR led.
评论 #37330278 未加载
评论 #37333620 未加载
unixheroover 1 year ago
It would be great if abbreviations are not usednin titles of academic papers. What is an HSM?
评论 #37332754 未加载
solarkraftover 1 year ago
Jan did a talk about DIYing one at GPN: <a href="https:&#x2F;&#x2F;media.ccc.de&#x2F;v&#x2F;gpn20-48-can-t-touch-this-diy-ing-a-hardware-security-module" rel="nofollow noreferrer">https:&#x2F;&#x2F;media.ccc.de&#x2F;v&#x2F;gpn20-48-can-t-touch-this-diy-ing-a-h...</a><p>Like others, I didn&#x27;t expect it to be a computer in a washing machine. A lot of the talk felt surreal due to its &quot;that&#x27;s insane ... but you have a point&quot; kind of vibe.
netsec_burnover 1 year ago
As a layperson in this field, what is stopping an attacker from removing the battery and stopping the motion of the IHSM for reverse engineering?
评论 #37332854 未加载
notpushkinover 1 year ago
[pdf]
lifeinthevoidover 1 year ago
Are there any known stories about real life attacks on HSMs? Would be interesting to hear &#x2F; read about them.
collsniover 1 year ago
Have fun with those earthquake key wipes :)
01100011over 1 year ago
Suggest changing the title to &quot;Inertial HW Security Modules Mitigate Physical Attacks&quot; or something as &quot;HSM&quot; is an overloaded term(I thought it was hierarchical state machines).
评论 #37327355 未加载
throwaway14356over 1 year ago
i remember seeing this, perhaps it was a bomb in a movie.<p>anyway, give it 2 axles or you would be able to rotate a pcb into it
lallysinghover 1 year ago
This looks like it was published just to be the MacGuffin in a movie later.
评论 #37327341 未加载
评论 #37330049 未加载
评论 #37326893 未加载