Comment by philsnow

Comment by philsnow 12 hours ago

1 reply

The HSMs that Signal and Apple are using are on-device though. Yes you still have to trust Signal / Apple to not exfil your key matter once decrypted by the HSM, but I submit that that is materially better than having the HSMs be hosted in a datacenter.

modeless 12 hours ago

Signal and Apple and Google all use HSMs in datacenters as well as on device.