The HSM universe is a nightmare. It’s genuinely terrible.
It’s like someone at the NSA in 1991 decided what the use-cases and APIs should look like, and nobody ever cared to bring any of it into the 21st century. It’s such garbage.
This is the “use cases” section for Amazon CloudHSM and reading the manual it’s like: yup, that’s pretty much all you could ever do with this garbage API.
The state of the art in 2021: multisig authentication.
Oh look, ten years into the cryptocurrency era they finally bothered to support secp256k1 (“blockchain”). Good luck with EdDSA.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Matthew Green

Matthew Green Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @matthew_d_green

4 Dec
I love Bell Labs (in the 1960s) for their combination of technical prescience and terribly-stupid prediction quality. ethw.org/w/images/c/c7/… Image
This is how they thought electronic payments would work. In fairness, it’s not that bad compared to the status quo 1965-2015. Image
It’s kind of amazing when you feed this through Kubrick. ImageImageImageImage
Read 4 tweets
2 Dec
I think it’s funny how little computer security people know about the Dapp ecosystem. It’s like they’re living in the hotel from The Shining and they have no idea what’s going down in Room 237.
Crypto/security people: we can’t *possibly* run a secure messaging app over the web because everything’s too insecure!

Dapp folks: let’s secure $100m using Javascript served by Cloudflare.
In case you don’t know what I’m on about. coindesk.com/business/2021/…
Read 6 tweets
1 Dec
Oof. I would say that NSS gives me the willies but all these crypto libraries give me the willies. googleprojectzero.blogspot.com/2021/12/this-s…
Oh god oh god. Image
Where am I going to store my post-quantum RSA keys in this data structure? Has anyone even thought about this?
Read 4 tweets
30 Nov
This picture should be presented to everyone who activates iCloud Backup.
“Our end-to-end encrypted system is only really encrypted if you don’t touch our janky unencrypted backup service that we practically beg you to use.”
Maybe if Apple implements some really good automated scanning in iMessage, the government might allow me to encrypt my backups.
Read 14 tweets
25 Nov
I still don’t understand why “let’s make system RNGs fast and insecure in case someone wants to run a Monte Carlo simulation” was ever considered to be anything other than the dumbest of all possible thoughts.
Apparently there is this huge population of language/OS users running Monte Carlo simulations and THEIR LIVES WILL BE UTTERLY RUINED if those simulations run slow.
I mean if I’m doing statistical simulations and the built-in system PRNG is slow, what’s the impact? I guess I’ll have to spend the 10 minutes copy/pasting the Mersenne Twister off Wikipedia. Seems pretty non-devastating.
Read 4 tweets
12 Nov
I headed over to the Home view to see why tech Twitter has gotten so much lamer, and it’s all people speculating on when Bitcoin will hit 100K.
So henceforth this account will just speculate on the Bitcoin price.
I’ve been using Latest Tweets for a couple months now and switching back to Home is like going home to find your parents have turned your bedroom into a Taco Bell. ImageImage
Read 6 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(