So, the problem with USB tokens that we basically have two choices: - Unauditable black boxes built on *supposedly* more secure ICs that require NDAs to develop for - Open and auditable, but definitely pwnable off the shelf microcontrollers. Which poison do you prefer?
-
-
FIPS is not very relevant... Common Criteria certification is. (and ROCA chip was CC certified). CC are not perfect (hence ROCA), but it doesn't mean they are useless... It remains far away more difficult to break a CC chip, than a STM32
-
Auditability is great, but only if it brings more security! Auditability on a broken device only allows everyone to verify it's indeed broken... NDA for secure chips is not ideal, but vendors want to protect their IPs... Designing a secure chip is not easy!
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.