Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Forgive me if I'm being dense but what harm would embedded crypto and compression engines do? You don't have to use them right?



There's little room for tampering with crypto, the only room is for tampering with the RNGs.

As far as I know all crypto algorithms are deterministic based on the key/IV and the data.


While that's true and required to successfully decrypt most algorithms, it is also true that there are more types of tampering one can do than changing the output ciphertext. Usually involving storing the key or leaking data somehow.


Assuming they've already compromised the crypto bits of the chip there's nothing to gain in avoiding them since the non-crypto bits could just as well have the same compromises. Might as well just take the time/energy savings.

Tampering with the RNG probably provides the best value for an attacker, and is harder to detect.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: