So, the problem with USB tokens that we basically have two choices: - Unauditable black boxes built on *supposedly* more secure ICs that require NDAs to develop for - Open and auditable, but definitely pwnable off the shelf microcontrollers. Which poison do you prefer?
-
-
The point is they'd have to cause physical damage and the glitter would be impossible to replicate without extreme cost. It isn't to make the device tamper proof, just tamper resistant for a few minutes or so.
-
Yeah, but revoking PGP/SSH keys is less trivial, so a higher level of physical tamper resistance to key extraction is desirable depending on your use case.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.