Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Again and again, we've seen that HSMs aren't secure against physical access of the device.


Can you point me to an example of a FIPS level 3+ certified device having its private keys compromised due to a defeat of the tamper resistant boundary?


Here are a couple examples of physical access leading to key extraction. You're welcome to be pedantic (those are side channel attacks, they don't defeat the boundary!) but one way or another, physical access wins.

https://www.cl.cam.ac.uk/~rnc1/descrack/ https://ninjalab.io/eucleak/




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: