Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Last I looked, DIME was just org level trust. That is, your domain determines what level of verification you get as far as knowing you have the right key for the recipient.

So if you used, say Gmail and they did DIME, you'd still be trusting them totally. Am I misunderstanding?

And still no admitting he was selling a fundamentally critically flawed service in the first place. If that's not even being mentioned, it really removes confidence from their new service.

As far as hardware HSM, that's cool. I very much enjoyed reading about how an HSM, the Luna CA3, was cracked:

http://www.cl.cam.ac.uk/~mkb23/research/Unwrapping-the-Chrys...



Also, hardware HSM is vulnerable to the "SSL added and removed here! :-)" attack, is it not?

"Dear Mr. Levison, remember that law about pen registers that you clearly hadn't heard off last time around? Well, now that you understand them, please install a pen register on the other side of your fancy FIPS 140-2 hardware security device, and have it send us everything in .pcap format. You don't need to reconfigure your HSM for this, and in fact any attempt to do so is now tampering with evidence in a federal investigation. Cheers, the FBI."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: