I present: The HSM alignment chart
benjojo
replied 05 Feb 2026 23:24 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
"The catholic priest in the confession booth is a HSM"
wheeze_NL@hsnl.socia..
replied 05 Feb 2026 23:42 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/Yqp88d32RSQL2SlwdZ
erincandescent@akko...
replied 05 Feb 2026 23:45 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/Yqp88d32RSQL2SlwdZ
@benjojo is the PayShield 9000 (that god awful incredibly slow incredibly expensive HSM that Thales used to sell on the basis that it was the last thing with a FIPS 140-2 certification covering triple-DES to the poor souls who’s compliance department required that) the satanic priest at the confession booth?
hisold@toot.io
replied 05 Feb 2026 17:01 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
f4grx@chaos.social
replied 05 Feb 2026 19:25 +0000
in reply to: https://toot.io/users/hisold/statuses/116019093876563857
tmcfarlane@toot.comm..
replied 05 Feb 2026 17:07 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
madduci@mastodon.soc..
replied 05 Feb 2026 17:15 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
Foxboron@chaos.socia..
replied 05 Feb 2026 18:40 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
f4grx@chaos.social
replied 05 Feb 2026 19:26 +0000
in reply to: https://chaos.social/users/Foxboron/statuses/116019482700324122
reflex@retrogaming.s..
replied 05 Feb 2026 23:49 +0000
in reply to: https://chaos.social/users/f4grx/statuses/116019664644582089
zaire@fedi.absturzta..
replied 05 Feb 2026 19:07 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
novet@infosec.exchan..
replied 05 Feb 2026 19:21 +0000
in reply to: https://fedi.absturztau.be/objects/35dfbc80-18b0-4f57-add1-2a1993772769
@zaire @benjojo A HSM in the high-level sense is a networked computer built on top of well-tested lab certified hardware, with a security-focused OS. They have limited access via some interface that is controlled by internal rules. They are designed to hide and protect cryptographic material. Generally they will also have anti-tamper markings or anti-tamper mechanisms which may even destroy the cryptographic material if tampering is detected. They are used in a manner of things. e-Passport security use HSMs in the gates which prevents anyone (including the operator) from tampering with it. Companies usually store signing keys in HSMs. HSMs secure smart metering systems. They secure mobile money payments. Pin issuing for payment cards is done by HSMs. Around Europe, around 6000km of roads have a "cooperative intelligent transport system" for linking "vehicles, road users, service providers, and road operators" which also uses HSMs in some manner. Some rail systems (five last I checked) use HSMs for signalling. HSMs also fulfill many roles in airlines.
fraggle@social.coop
replied 05 Feb 2026 21:20 +0000
in reply to: https://fedi.absturztau.be/objects/35dfbc80-18b0-4f57-add1-2a1993772769
@benjojo @zaire sometimes we have sensitive cryptographic keys and we worry the computer can be hacked and the keys could get stolen. So an HSM is a magic box that you can put the keys in to keep them safe and secure, except it's actually just another computer that we've convinced ourselves can never be hacked, unlike other computers which sometimes can. Also, now that the keys are secure, you need to authenticate yourself to the HSM to use them, and you do this by using another key that you store outside the HSM. Unless you can get another HSM to store that key in. It's HSMs all the way down, essentially
f4grx@chaos.social
replied 05 Feb 2026 19:25 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
RandamuMaki@mstdn.so..
replied 05 Feb 2026 19:33 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
@benjojo The scary old box: The last person who knew how it worked left the company during a "restructuring" round a couple of years ago, there's no documentation for it, and somehow it still needs diskettes which nobody can find.
bertkoor@mastodon.so..
replied 05 Feb 2026 22:32 +0000
in reply to: https://mstdn.social/users/RandamuMaki/statuses/116019692904612765
@RandamuMaki @benjojo
And the post-it with "do NOT switch off" and the pw on the back fell off.
We're fucked....
Datterich@darmstadt...
replied 05 Feb 2026 19:43 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
thunfisch@chaos.soci..
replied 05 Feb 2026 21:22 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3
@benjojo Sorry, can't find where to place my notebook with handwritten cryptographic keys that I stash under my pillow on the graph. I'll just assume it goes into the top left spot, right?
gabrielesvelto@mas.t..
replied 05 Feb 2026 22:27 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/27DTj8GwVXW7x264J3