So, the problem with USB tokens that we basically have two choices: - Unauditable black boxes built on *supposedly* more secure ICs that require NDAs to develop for - Open and auditable, but definitely pwnable off the shelf microcontrollers. Which poison do you prefer?
Ideally you have *both* physical attack mitigations *and* a strong passphrase that cryptographically wraps your private key.
-
-
Ideally, but HW vendors with SE sell you "trust our certified chip" and passphrase doesn't fit their narrative :-). Honestly, there's no ideal hardware solution yet. All SE are covered by tons of obscurity coming from current chip industry, where you cannot fart without NDA.
-
Indeed, hence my tweet :-) It's a sad state of affairs, tbh. There is no good reason not to have *any* open option for SEs.
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.