mike007 wrote:
I see, what is the SHM capable of then? WHEN would it be able to protect keys as it is intended to do?
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
The YubiHSM doesn't give any data back to the computer it's attached to. All it does is take a OTP and give back a yes/no answer which says whether or not the OTP was valid. It can't (in theory) give the symmetrical keys to the computer.
Another way to implement this would be with a device such as an arduino or especially a raspberry pi. But as these are < 1/10 the price of the device which yubico is planning to produce, I should probably not talk about them here.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iQIcBAEBAgAGBQJOMx0SAAoJEHkZLCwtmxuJ6+QP/RqWThmduOjfR9c3TgtYpQ3y
loaIYlAo0PSZ3qrxRoNgSgUgjoTYglRuYwQ7JWBTLKiWuM+eh/2OobOuc5NDIrVV
E7Ckcq6O/8d6WcRyuFA1YVrCevmFZNzIJPDyhIGr1IxlFo7Ni6QFi84UTdAVp407
sFzNQtwMzpzFiB4FGmem4Y+TLza+nh/d/tyGmT1574nAvN2ReleTO1minfN2f8kk
pZc6RC3mHEKp54z0BdaEPKaUdQe64CBHzABs0Knp8x4nRpgbDyKZE1jsM6WnOkSZ
A9NJ0j4/Qbnw+NYnTUvm2jjPsLBXc9O5OoDF+Q659lgEge33wFLc7/eZOxp4oGzQ
+tseWdWbY6xi13FIrb9h8jRxmGJjYC0HV1OG4HilnBsy/vlYfFR8hpSwWHs1kVNU
gbtWO6MC2QPoBIZjGbem0vHHZ4q8BUKJ8ADjqATzYoUpfvbIE2xEwOBbyEvLjxXX
Cplq/Teb9SonUtzmGizOm9Lb5GBtzp00XmV1sOUQLJP77jbwOl4rUy5Z86BdaeJX
ZVuRAyZ1giI6nXLcbhwHGomjVsR9IM8/418tfgoO4xdaRY9wDsYxkI1uJAnRKLQU
rghvlVU8ca2kT2pAvYlv7m17GzE3zpAqxhk48wKaGhZhlzRmcz/pRL6fYnyUEbYX
k+Fk0faW4c/Oy/hwHyTX
=/FSy
-----END PGP SIGNATURE-----