logoalt Hacker News

philsnowyesterday at 7:35 PM1 replyview on HN

The HSMs that Signal and Apple are using are on-device though. Yes you still have to trust Signal / Apple to not exfil your key matter once decrypted by the HSM, but I submit that that is materially better than having the HSMs be hosted in a datacenter.


Replies

modelessyesterday at 7:37 PM

Signal and Apple and Google all use HSMs in datacenters as well as on device.