Hardware security module
32
MENTIONS
19
EPISODES
14
PODCASTS
Search complete. 32 mentions across 19 episodes found for "Hardware security module".
Sep 17, 2026
CompTIA Security+ SY0-801: 1.3 Cryptographic Solutions & Trust Engine
S
17:26Sec GuyHOST
Second, the hardware security module or HSM.
S
17:30Sec GuyHOST
While the TPM protects an individual endpoint, an HSM is a high performance enterprise grade physical appliance or PCIe card deployed in data centers and cloud environments.
S
17:44Sec GuyHOST
HSMs are engineered to securely generate, store, and manage massive volumes of master cryptographic keys, handling heavy cryptographic operations for certificate authorities and payment processing systems.
S
17:58Sec GuyHOST
HSMs feature physical tamper detection mechanisms that instantly zeroize and destroy stored keys if physical intrusion is detected.
S
18:08Sec GuyHOST
Third, secure enclaves and confidential computing.
S
18:12Sec GuyHOST
Modern cloud architectures leverage hardware isolated memory partitions within the central processor.
Infrastructure Attack Surfaces: Spectre, VM Escape, & Memory Mastery
S
1:09Sec GuyHOST
A TPM is for your laptop.
S
1:11Sec GuyHOST
An HSM, hardware security module, is for the server.
S
1:17Sec GuyHOST
If you are managing keys for a bank or a certificate authority, you aren't using a TPM.
S
1:23Sec GuyHOST
You are using an HSM to offload that cryptographic processing.
S
1:28Sec GuyHOST
If an attacker compromises the firmware, they own the machine before the operating system even loads.
S
1:35Sec GuyHOST
But in the real world, we deal with side-channel attacks.
#146 AI Found What Nine Years of Security Research Missed with Charles Guillemet // CTO @ Ledger
C
6:11Charles GuillemetGUEST
So basically it's a SaaS platform that is also leveraging hardware.
C
6:15Charles GuillemetGUEST
We are leveraging HSM on the backend, but also we are providing them with personal security device.
T
6:21Tobias SchlottkeHOST
But at the end, it's a lot of software.
C
6:24Charles GuillemetGUEST
And to answer your question, today I would say that the hardware revenue is not the biggest one anymore.
Post-Quantum Crypto with Michael Howard
C
53:37Carl FranklinHOST
yeah
M
53:37Michael HowardGUEST
and then you re-wrap it using aes kw which managed HSM in Azure, and now Key Vault, actually, Key Vault Premium in public preview, supports AESKW key wrapping, which is post-quantum resilient.
C
53:50Carl FranklinHOST
Yeah, go ahead.
M
53:52Michael HowardGUEST
So there's two issues that I see developers need to really, really think about.
M
57:56Michael HowardGUEST
And then the last one, which is incredibly important, is the key wrapping.
M
58:00Michael HowardGUEST
And we now have that in Azure.
M
58:03Michael HowardGUEST
So managed HSM has had AS key wrapping since day one.
M
58:07Michael HowardGUEST
And Azure Key Vault now has it, ASKW.
Institutional Custody, Multisig & the War on Cash | Mike Belshe SLP773
M
11:03Mike BelsheGUEST
All right, so in this model, we hold one key and you hold two keys.
M
11:07Mike BelsheGUEST
So when you provision a wallet with us, That one key we provision on our servers, it's in HSMs.
M
11:13Mike BelsheGUEST
We've been doing, those are hardware security modules.
M
11:14Mike BelsheGUEST
We've been doing that longer than anybody because we were the first kind of into the space.
31 MINS LATER
S
42:31Stephan LiveraHOST
I mean, that's that's that's definitely part of it.
S
42:33Stephan LiveraHOST
I think the political activism part of it is becoming more and more of a thing like Bitcoin is becoming bigger and bigger and therefore Bitcoiners could start being politically active in terms of donations and things like that.
S
42:46Stephan LiveraHOST
i guess some people will have a bit of a that gives a bad taste in the mouth because maybe they don't want to be involved in the state or politics at all but yeah i kind of do align more on that side of hey uh it's uh what's the word uh what's the saying it's like politics you may not be interested in politics but politics is interested in you and for that reason um yeah i think uh we're gonna have to try to improve that situation and that's kind of in many places around the world um I wanted to get back to kind of the custody side of things and like security questions on like BitGo and HSMs and things like this.
S
43:24Stephan LiveraHOST
How do...
Professor Messer's Security+ Study Group After Show - September 2026
J
27:51James MesserHOST
But notice with many of these topics, that they give you the topic like trusted platform module, and then right after it, TPM.
J
28:01James MesserHOST
Then they have hardware security module.
J
28:03James MesserHOST
Right after that, HSM.
J
28:06James MesserHOST
They have certificate revocation lists, CRLs.
J
28:11James MesserHOST
They have online certificate status protocol, OCSP.
Post-Quantum Crypto with Michael Howard
C
53:52Carl FranklinHOST
yeah
M
53:52Michael HowardGUEST
and then you re-wrap it using aes kw which managed HSM and Azure, and now Key Vault, actually, Key Vault Premium in public preview, supports AES-KW key wrapping, which is post-quantum resilient.
C
54:05Carl FranklinHOST
Yeah, go ahead.
M
54:07Michael HowardGUEST
So there's two issues that I see developers need to really, really think about.
M
58:11Michael HowardGUEST
And then the last one, which is incredibly important, is the key wrapping.
M
58:15Michael HowardGUEST
And we now have that in Azure.
M
58:17Michael HowardGUEST
So managed HSM has had AS key wrapping since day one.
M
58:22Michael HowardGUEST
And Azure Key Vault now has it, ASKW.
Post-Quantum Crypto with Michael Howard
M
53:15Michael HowardGUEST
So if you have a 256-bit AES key, you just decrypt it or unwrap it using RSA, for example, and then you rewrap it using AES-KW.
M
53:25Michael HowardGUEST
which managed HSM in Azure, and now Key Vault, actually, Key Vault Premium in public preview, supports AESKW key wrapping, which is post-quantum resilient.
C
53:35Carl FranklinHOST
Yeah, go ahead.
M
53:37Michael HowardGUEST
So there's two issues that I see developers need to really, really think about.
M
57:41Michael HowardGUEST
And then the last one, which is incredibly important is the key wrapping.
M
57:45Michael HowardGUEST
And we now have that in, in Azure.
M
57:48Michael HowardGUEST
So managed HSM has had a key wrapping since day one.
M
57:52Michael HowardGUEST
And, um, as a key vault now has it, uh, ASKW.
Paper in a Safe: The Most Rugged Key Backup
C
2:17CornHOST
It's not ruggedized bricks.
C
2:19CornHOST
It's HSMs.
H
2:20Herman PoppleberryHOST
Right.
H
2:21Herman PoppleberryHOST
A YubiKey 5 is $50 to $80, does OpenPGP and FIDO2 and PIV, and the private key material can't be copied back out.
12 MINS LATER
H
14:10Herman PoppleberryHOST
The dry run is the difference between a backup and a hope.
H
14:14Herman PoppleberryHOST
Let's talk about the
C
14:15CornHOST
trust problem with HSMs more directly, because Daniel's context is sovereign networking stacks.
C
14:21CornHOST
A government building its own infrastructure has a specific problem with a sealed box from a foreign vendor.
Zeroization: Wiping Keys, Not Data
H
6:43Herman PoppleberryHOST
The wipe has to complete faster than an attacker can reach the die.
H
6:47Herman PoppleberryHOST
That's why HSMs use battery-backed SRAM for key storage rather than flash.
H
6:52Herman PoppleberryHOST
SRAM is volatile.
H
6:54Herman PoppleberryHOST
Pull power, and the keys are gone.
9 more episodes mention Hardware security module.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.