Re: Smart Card
[email protected] (Peter Gutmann)
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <E1BJbZe-0000TU-RO@medusa01> |
Goetz Babin-Ebell <[email protected]> writes: >If the private key ever leaves the Smart Card (exception: key backup), the >security model of your environment is broken. Even if the key doesn't leave the card, if it's attached to a compromised host then it's as good as broken because the host can have the card do anything it wants, unless it's one of the (very rare) card setups with PIN entry via the reader, a secure (meaning not controlled by the host) display on the reader, and the card only allows one transaction before the user has to re- authenticate. I've only ever seen a few readers like that, and they were quite expensive and faded from use fairly quickly. Peter.