Skip to main content
Hardware security module

Hardware security module

Search complete. 32 mentions across 19 episodes found for "Hardware security module".

Sep 17, 2026

Sec GuyHOST
17:26
Second, the hardware security module or HSM.
Sec GuyHOST
17:30
While the TPM protects an individual endpoint, an HSM is a high performance enterprise grade physical appliance or PCIe card deployed in data centers and cloud environments.
Sec GuyHOST
17:44
HSMs are engineered to securely generate, store, and manage massive volumes of master cryptographic keys, handling heavy cryptographic operations for certificate authorities and payment processing systems.
Sec GuyHOST
17:58
HSMs feature physical tamper detection mechanisms that instantly zeroize and destroy stored keys if physical intrusion is detected.
Sec GuyHOST
18:08
Third, secure enclaves and confidential computing.
Sec GuyHOST
18:12
Modern cloud architectures leverage hardware isolated memory partitions within the central processor.
Sec GuyHOST
1:09
A TPM is for your laptop.
Sec GuyHOST
1:11
An HSM, hardware security module, is for the server.
Sec GuyHOST
1:17
If you are managing keys for a bank or a certificate authority, you aren't using a TPM.
Sec GuyHOST
1:23
You are using an HSM to offload that cryptographic processing.
Sec GuyHOST
1:28
If an attacker compromises the firmware, they own the machine before the operating system even loads.
Sec GuyHOST
1:35
But in the real world, we deal with side-channel attacks.
Charles GuillemetGUEST
6:11
So basically it's a SaaS platform that is also leveraging hardware.
Charles GuillemetGUEST
6:15
We are leveraging HSM on the backend, but also we are providing them with personal security device.
Tobias SchlottkeHOST
6:21
But at the end, it's a lot of software.
Charles GuillemetGUEST
6:24
And to answer your question, today I would say that the hardware revenue is not the biggest one anymore.
Carl FranklinHOST
53:37
yeah
Michael HowardGUEST
53:37
and then you re-wrap it using aes kw which managed HSM in Azure, and now Key Vault, actually, Key Vault Premium in public preview, supports AESKW key wrapping, which is post-quantum resilient.
Carl FranklinHOST
53:50
Yeah, go ahead.
Michael HowardGUEST
53:52
So there's two issues that I see developers need to really, really think about.
Michael HowardGUEST
57:56
And then the last one, which is incredibly important, is the key wrapping.
Michael HowardGUEST
58:00
And we now have that in Azure.
Michael HowardGUEST
58:03
So managed HSM has had AS key wrapping since day one.
Michael HowardGUEST
58:07
And Azure Key Vault now has it, ASKW.
Mike BelsheGUEST
11:03
All right, so in this model, we hold one key and you hold two keys.
Mike BelsheGUEST
11:07
So when you provision a wallet with us, That one key we provision on our servers, it's in HSMs.
Mike BelsheGUEST
11:13
We've been doing, those are hardware security modules.
Mike BelsheGUEST
11:14
We've been doing that longer than anybody because we were the first kind of into the space.

31 MINS LATER

Stephan LiveraHOST
42:31
I mean, that's that's that's definitely part of it.
Stephan LiveraHOST
42:33
I think the political activism part of it is becoming more and more of a thing like Bitcoin is becoming bigger and bigger and therefore Bitcoiners could start being politically active in terms of donations and things like that.
Stephan LiveraHOST
42:46
i guess some people will have a bit of a that gives a bad taste in the mouth because maybe they don't want to be involved in the state or politics at all but yeah i kind of do align more on that side of hey uh it's uh what's the word uh what's the saying it's like politics you may not be interested in politics but politics is interested in you and for that reason um yeah i think uh we're gonna have to try to improve that situation and that's kind of in many places around the world um I wanted to get back to kind of the custody side of things and like security questions on like BitGo and HSMs and things like this.
Stephan LiveraHOST
43:24
How do...
James MesserHOST
27:51
But notice with many of these topics, that they give you the topic like trusted platform module, and then right after it, TPM.
James MesserHOST
28:01
Then they have hardware security module.
James MesserHOST
28:03
Right after that, HSM.
James MesserHOST
28:06
They have certificate revocation lists, CRLs.
James MesserHOST
28:11
They have online certificate status protocol, OCSP.
Carl FranklinHOST
53:52
yeah
Michael HowardGUEST
53:52
and then you re-wrap it using aes kw which managed HSM and Azure, and now Key Vault, actually, Key Vault Premium in public preview, supports AES-KW key wrapping, which is post-quantum resilient.
Carl FranklinHOST
54:05
Yeah, go ahead.
Michael HowardGUEST
54:07
So there's two issues that I see developers need to really, really think about.
Michael HowardGUEST
58:11
And then the last one, which is incredibly important, is the key wrapping.
Michael HowardGUEST
58:15
And we now have that in Azure.
Michael HowardGUEST
58:17
So managed HSM has had AS key wrapping since day one.
Michael HowardGUEST
58:22
And Azure Key Vault now has it, ASKW.
Michael HowardGUEST
53:15
So if you have a 256-bit AES key, you just decrypt it or unwrap it using RSA, for example, and then you rewrap it using AES-KW.
Michael HowardGUEST
53:25
which managed HSM in Azure, and now Key Vault, actually, Key Vault Premium in public preview, supports AESKW key wrapping, which is post-quantum resilient.
Carl FranklinHOST
53:35
Yeah, go ahead.
Michael HowardGUEST
53:37
So there's two issues that I see developers need to really, really think about.
Michael HowardGUEST
57:41
And then the last one, which is incredibly important is the key wrapping.
Michael HowardGUEST
57:45
And we now have that in, in Azure.
Michael HowardGUEST
57:48
So managed HSM has had a key wrapping since day one.
Michael HowardGUEST
57:52
And, um, as a key vault now has it, uh, ASKW.
CornHOST
2:17
It's not ruggedized bricks.
CornHOST
2:19
It's HSMs.
Herman PoppleberryHOST
2:20
Right.
Herman PoppleberryHOST
2:21
A YubiKey 5 is $50 to $80, does OpenPGP and FIDO2 and PIV, and the private key material can't be copied back out.

12 MINS LATER

Herman PoppleberryHOST
14:10
The dry run is the difference between a backup and a hope.
Herman PoppleberryHOST
14:14
Let's talk about the
CornHOST
14:15
trust problem with HSMs more directly, because Daniel's context is sovereign networking stacks.
CornHOST
14:21
A government building its own infrastructure has a specific problem with a sealed box from a foreign vendor.
Herman PoppleberryHOST
6:43
The wipe has to complete faster than an attacker can reach the die.
Herman PoppleberryHOST
6:47
That's why HSMs use battery-backed SRAM for key storage rather than flash.
Herman PoppleberryHOST
6:52
SRAM is volatile.
Herman PoppleberryHOST
6:54
Pull power, and the keys are gone.

9 more episodes mention Hardware security module.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.