[Cryptography] USB hardware token for $2??

Ron Garret ron at flownet.com
Fri Dec 23 01:20:16 EST 2016


On Dec 22, 2016, at 3:38 PM, Kent Borg <kentborg at borg.org> wrote:

> On 12/22/2016 03:58 PM, Ron Garret wrote:
>> https://sc4.us/hsm/
> 
> That device is still gnawing at me! It seems so useful, or at least like it should be so useful. But it has me suffering over endpoint security. It could secure sensitive information for me. The display looks so valuable to get information out, but what about getting information in? How does it know I am me?

That is a very good question, to which I have three answers.

Answer #1: at the moment the device doesn’t know it’s you, but it doesn’t matter because before it does any cryptographic operation it illuminates the LED to let you know it needs attention, displays what it is about to do on the display, and waits for you to push one of the built-in push buttons before it will proceed.

Answer #2: I am working on an ssh-like protocol for communicating with the device.

Answer #3: I’m working on a new version of the device that has a female USB plug on the other end into which you can plug a keyboard.

rg



More information about the cryptography mailing list