Private Key Security Risks

This cluster discusses vulnerabilities and risks associated with private cryptographic keys, including theft by hackers, insiders, or governments, secure storage in HSMs, and scenarios like key escrow or client-side exposure.

📉 Falling 0.4x Security
4,460
Comments
20
Years Active
5
Top Authors
#7310
Topic ID

Activity Over Time

2007
1
2008
4
2009
25
2010
45
2011
105
2012
93
2013
326
2014
297
2015
318
2016
302
2017
269
2018
299
2019
302
2020
314
2021
333
2022
381
2023
458
2024
263
2025
283
2026
48

Keywords

HSM ECDH PNC KDF UK HMAC MITM IIRC FAQ UDS keys key private key private stolen private keys access attack decrypt extracted

Sample Comments

Siira Jun 24, 2020 View on HN

Can't the key get stolen if it's on the client?

cryptonector Dec 3, 2021 View on HN

Let me guess: as long as there's key escrow or equivalent.

pOVTVOItY Dec 29, 2016 View on HN

Private keys can be stolen or extracted via bribery, etc.

pabs3 Jul 19, 2022 View on HN

Probably the keys are on well-guarded offline HSMs.

justinsb Nov 13, 2014 View on HN

What is the attack you're envisaging?Presumably they detect unauthorized case-intrusion and immediately delete the keys. This isn't foolproof, but it's probably good enough to stop anyone except the people that are going to get the data no matter what you do.

SeanDav Jun 16, 2016 View on HN

Once a malicious 3rd party gets the keys to this kingdom it is game over.

manjushri Apr 9, 2018 View on HN

That's wrong. Insiders can leak the private key, or hackers can take it.

natch Jun 11, 2017 View on HN

If there is a way to extract the keys then the keys will be extracted by rogue actors.

randyrand Jun 10, 2013 View on HN

Do we know they don't have access to the private keys?

pavel_lishin Sep 5, 2023 View on HN

The response to your devil's advocate argument is: giving you the keys is not actually a solution, because now every foreign government is racing to break, steal or buy those keys, and not only can we not guarantee that it won't happen, but we can't even discover if it happens, or when. We can build a secret entrance, but we cannot guard it!