Tenement Farming and Cloud HSMs
unmitigatedrisk.com
unmitigatedrisk.com
The drawback is that they are very expensive, so you have to be really paranoid to want to use them, and they are new enough and complicated enough that you have to trust us and our auditors to have done everything right.
> they are a lot more isolated from meddling by Amazon insiders than Amazon's Cloud HSM is.
I'm curious how you can make this claim.
I think this space is ripe for significant evolution.
Authors point re hashicorp vault being marginally better than checking keys into source control hits home. Eg often infra is one stolen ssh key away from having code committed that can select * from vault. That also comes with crappy provenance that doesn't integrate well with gitops.
My hopeful view is that we can incrementally fix this bottom-up:
1. ssh should use the mobile phone biometrics as HSM and expose that via ssh-agent
2. From there simple projects should use sops to commit their ssh encrypted secrets to git. I wrote https://github.com/tarasglek/github-to-sops to make it easy to share secrets this way. One can even use sshd private keys to separate secrets for infra from dev ones.
3. For more complex projects one can loop aws kms type hsms.
4. For more complex orgs we then need to borrow some cleverness from crypto ecosystem as they actually made a lot of progress in various tricks to derive trust/ownership...but instead of stupid blockchain one should keep using git.
5. This then can be extended down to database level mods where one could extend row-level ACLs with signature-based provenance checks in 4
Note I am in no way a security person. Just have a desire for someone to make this problem go away for us mere mortals.
Via PKCS11 libtergent.
It’s unreasonable, expensive, and probably unnecessary and irrational for the vast majority of customers, but it still niggles at me from time to time.
I am aware of industry talks of lobbying on behalf of HSM manufacturers that led to these requirements and that's just sad.
HSMs make most sense when they’re performing high-level operations (“Is this credit card CVC valid?”); when used as signature or decryption oracles (“Hi, I’m a trusted application server, now sign this email!”) their security gain rapidly diminishes.
Sometimes they get used for key storage alone (“Hi, I’m an application server booting up, give me the RSA signing key for account x!” or even worse “Hi, I’m an application server booting up, give me the key wrapping all the user keys in our database!”), with obvious implications.
Getting an HSM vendor to implement your use case can get very expensive; confidential computing lets you do it yourself, i.e. draw a much larger “trusted” box in your architectural diagram than otherwise feasible.
When it is on cloud, who knows what?