So, the problem with USB tokens that we basically have two choices: - Unauditable black boxes built on *supposedly* more secure ICs that require NDAs to develop for - Open and auditable, but definitely pwnable off the shelf microcontrollers. Which poison do you prefer?
-
-
But anybody who signed the NDA can't tell others, because they have signed not to do it?
-
Exactly
End of conversation
New conversation -
-
-
The biggest issue AFAIK is that all good hardware countermeasures are patented, even obvious ones. I am afraid one cannot build an open source secure element without infringing on a bunch of them.
-
Surely some of those have expired by now? It's 2020, SEs existed in the 90s.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.