Post Aw4JNLZz2B3EAXMxCC by feld@friedcheese.us
 (DIR) More posts by feld@friedcheese.us
 (DIR) Post #Avz3V7QYxrfxXMqaR6 by whitequark@mastodon.social
       2025-07-10T06:23:20Z
       
       1 likes, 0 repeats
       
       *hits blunt* "what if we put the HSM... on a rotor spinning fast enough that if you rotated in a chair that fast it would Kill you" https://tches.iacr.org/index.php/TCHES/article/view/9290/8856(via @mimir)
       
 (DIR) Post #Avz3V9PZaW4XgsOpAe by whitequark@mastodon.social
       2025-07-10T06:27:11Z
       
       0 likes, 0 repeats
       
       personally i'm saying let's go one step forward and mount the HSM onto an ultracentrifuge. if you try to slow it down, it erases itself. if you attack it mechanically and make _one single mistake_, the released energy destroys your entire lab. and maybe two or three adjacent floors
       
 (DIR) Post #Avz3VAfutEjvbr3OHg by whitequark@mastodon.social
       2025-07-10T06:28:46Z
       
       0 likes, 0 repeats
       
       if that's not secure enough, you could put the HSM into a gas cylinder and pressurize it to 300 bar. the tamper detection circuitry breaks off the valve
       
 (DIR) Post #Avz3VBpAcJjhAqOILY by alwayscurious@infosec.exchange
       2025-07-10T07:22:02Z
       
       0 likes, 0 repeats
       
       @whitequark I believe there are military HSMs that detonate explosives if tampered with.
       
 (DIR) Post #Avz3VCeDYWZLjAH3ui by teajaygrey@snac.bsd.cafe
       2025-07-10T07:48:30Z
       
       0 likes, 0 repeats
       
       Banking has had "active zeroization" hardware going back to at least the 1990s last I looked into such realms?The destruction doesn't need to be particularly explosive when contending with most PCB level designs. At least, not that anyone would consider explosive who has contended with "srs" explosives. Does a popped capacitor seem explosive? It can make a loud noise! "Magic smoke" moments and hardware becoming inoperative are usually more than sufficient. IIRC, マクロスプラス「makurosu purasu」"Macross Plus" had a scene of some similar level circuit board destruction in animated form in the early to mid 1990s.Thankfully, I haven't worked anywhere that had a "grandfathered" Halon fire presuppression system in operation since 2006! Even before that I had worked at places which had at least transitioned to non-lethal FM200 (not as volumetrically dense than Halon for storage, but won't kill you if deployed). The risks for some sorts of things are nontrivial. You never know what poor SOB might be in a server room after all, and do you want their blood on your hands if Halon got deployed because of some overly aggressive "detonation"?There used to be the informal parlance: "It's the US Army, not the THEM Army" and every soul was counted and depended on and the goal was to save as many lives as possible.However, last I checked, Halon was still used in military systems probably with more cavalier abandon than that past employer of mine with their "grandfathered" system circa 2006? With the requisite casualty considerations presumably still being calculated by some higher up brass.I had one colleague who mentioned "thermite" when it came to such things; but I think that was in an unofficial DIY capacity, not something produced and sold and deployed? I can hope! Admittedly, that individual worked for SAIC as their day job (and as the joke used to go: "Like the CIA" backwards) so who the hell knows?I wouldn't put it past the military to make a bigger mess of things; but there are many reasons I never formally enlisted!My dad was drafted back when conscription was still a thing and the mercenary industrial complex already predated upon me and my friends when we were minors. None of us enlisted, no matter what evil deeds they had already made us do.To wit, the only person from where we grew up who became military (or maybe cop?) adjacent was the son of a cocaine dealer, just to give an indication of how corrupt such realms had become and what might entice someone to become an authority figure in such circles.TL;DR if folks are making detonating HSMs?They're fucking morons and they're going to learn some very hard lessons, the very hard way, someday, presumably. Maybe not this lifetime, but eventually.
       
 (DIR) Post #Aw4JNLZz2B3EAXMxCC by feld@friedcheese.us
       2025-07-10T06:36:20.326431Z
       
       1 likes, 0 repeats
       
       @whitequark oooh this seems like a product @SlicerDicer would build
       
 (DIR) Post #Aw4JSOpkMWdhi49Sim by SlicerDicer@friedcheese.us
       2025-07-12T20:41:30.259688Z
       
       0 likes, 0 repeats
       
       @feld @whitequark Maybe when I’m not building an ai engine lol