Show HN: Picohsm, a $5 open-source hsm
picokeys.com
picokeys.com
Show HN is for something you've made that other people can play with.
The project must be something you've worked on personally and which you're around to discuss.
[0]: https://news.ycombinator.com/showhn.htmlMay be I didn't understand something about this project.
Also 124 seconds for RSA2048 sounds awfully slow. Is rp2040 really THAT slow? I feel something's wrong here.
Anyway it's a nice project!
The worst part of using HSMs in enterprise env's is when you're forced to use something certified for FIPS 140 Level 2 or 3 requirements.. Then you're paying for what amounts to a shiny foil "anti-counterfeit / tamper-evident" sticker. This could probably easily meet level 1 via a certified openssl module, but alas, with most enterprise HSMs you're not paying for the _HSM features_.
Indeed from a very quick glance at the source, it's using the mbedtls library (from arm) and I think this is an unmasked implementation. This means key extraction, if you have physical access to the device, will be trivial.
If you're sure you never do a plaintext backup or anything else that might leak the key, then it may not matter. But it is a decent defense in depth measure for high assurance operations.
I heard a story once about a CA (public? private? not sure!) that had an airgapped root CA in a basement lab, only for an enterprising admin to run an Ethernet cable between their desk and the basement lab to save themselves a few trips... An online HSM may allow effective leakage (by allowing arbitrary signing operations), but hopefully would prohibit export by a crypto user and retain audit logs of all operations to identify scope of the compromise.
At some point, you end up reinventing an HSM from first principals. :-) My 2c.
Either that attestation is meaningless and can be easily faked, or this is only as open-source as the TiVo was. Looking around a bit, it looks like it's the former.