←back to thread

658 points transpute | 3 comments | | HN request time: 0.446s | source
Show context
bawolff ◴[] No.35844267[source]
Its kind of surprising that such a high value key wasn't split into multiple subkeys.
replies(1): >>35844516 #
wmf ◴[] No.35844516[source]
We've had HSMs for decades and Intel isn't forcing their OEMs to use them. This is pretty sad.
replies(1): >>35845649 #
transpute ◴[] No.35845649[source]
https://twitter.com/matrosov/status/1654930508252581888
replies(1): >>35846126 #
1. bawolff ◴[] No.35846126[source]
Sure, but intel is ultimately left holding the bag here not the oem, and it was totally within their power to put stipulations in the contract around key management.
replies(2): >>35846614 #>>35847257 #
2. transpute ◴[] No.35846614[source]
Margins are not great in the x86 PC hardware business. Has there ever been a lawsuit between Intel and an OEM?
3. wmf ◴[] No.35847257[source]
Contracts don't work. IMO Intel should not provide raw keys to the OEMs but HSMs with the keys preloaded. And MS should require good key management for the Secured Core sticker (although probably few/no MSI products are Secured Core anyway).