
Péter Szilágyi|Jul 16, 2025 09:31
Sigh, seems my enthusiasm was premature. The #YubiHSM audit logs are not digitally signed and there is no way to have the HSM attest them.
That means I can just forge an arbitrary audit journal and publish that. Only physically querying the HSM can prove it's real or fake. 🤮
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink