top | item 9943608

(no title)

higherpurpose | 10 years ago

There's also such thing as "key stealing". I imagine it would be quite a valuable target.

discuss

order

UnoriginalGuy|10 years ago

When you're signing a binary blob, protecting the private key is actually pretty easy since it can be air-gapped/offline. Or heck you can buy appliances where they'll perform specific functions using the private key but won't expose it themselves without physical intervention.

tinco|10 years ago

If I were a mega-corporation protecting a firmware private key, your name would have to be Tom Cruise to get it. Though unfortunately responsible corporations seem to be as rare as real-life Tom Cruise characters, so I guess it's a valid concern you have.