{"id":35134,"date":"2019-10-31T22:02:29","date_gmt":"2019-10-31T19:02:29","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimosti-v-hsm-modulyah-kotorye-mogut-privesti-k-atake-na-klyuchi-shifrovaniya\/"},"modified":"2019-10-31T22:02:29","modified_gmt":"2019-10-31T19:02:29","slug":"uyazvimosti-v-hsm-modulyah-kotorye-mogut-privesti-k-atake-na-klyuchi-shifrovaniya","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-hsm-modulyah-kotorye-mogut-privesti-k-atake-na-klyuchi-shifrovaniya","title":{"rendered":"Vulnerabilit\u00e0 nei moduli HSM che possono portare a un attacco alle chiavi di crittografia","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Un gruppo di ricercatori della societ\u00e0 Ledger, specializzata in wallet hardware per criptovalute, <noindex><a rel=\"nofollow\" href=\"https:\/\/cryptosense.com\/blog\/how-ledger-hacked-an-hsm\/\">ha messo in luce<\/a><\/noindex>  ha identificato alcune vulnerabilit\u00e0 nei dispositivi HSM (<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Hardware_security_module\">Hardware Security Module<\/a><\/noindex>), che possono essere sfruttate per estrarre chiavi o per eseguire attacchi remoti per alterare il firmware del dispositivo HSM. Al momento, il rapporto sulla questione <noindex>\u00e8 disponibile<\/noindex> \u00e8 disponibile solo in francese; \u00e8 prevista la pubblicazione di una versione in inglese <noindex><a rel=\"nofollow\" href=\"https:\/\/www.blackhat.com\/us-19\/briefings\/schedule\/#everybody-be-cool-this-is-a-robbery-16233\">ad agosto durante la conferenza Blackhat USA 2019. Un HSM \u00e8 un dispositivo esterno specializzato, progettato per conservare chiavi pubbliche e private utilizzate per generare firme digitali e per criptare dati.<\/a><\/noindex> ad agosto, durante la conferenza Blackhat USA 2019. L'HSM \u00e8 un dispositivo esterno specializzato, progettato per memorizzare le chiavi pubbliche e private utilizzate per la generazione di firme digitali e per la crittografia dei dati. <\/p>\n<p>L'HSM consente di migliorare significativamente la sicurezza, isolando completamente le chiavi dal sistema e dalle applicazioni, fornendo solo API per eseguire i principali primitivi crittografici implementati sul dispositivo. Di solito, l'HSM viene utilizzato in ambiti che richiedono la massima protezione, come banche, exchange di criptovalute, e centri di certificazione per la verifica e generazione di certificati e firme digitali.<\/p>\n<p>I metodi di attacco proposti consentono a un utente non autenticato di ottenere il pieno controllo sul contenuto dell'HSM, inclusa l'estrazione di tutte le chiavi crittografiche memorizzate nel dispositivo e delle credenziali dell'amministratore. I problemi sono causati da un overflow del buffer nel gestore comandi PKCS#11 e da un errore nell'implementazione della protezione crittografica dei firmware, che consente di bypassare il controllo della firma digitale del firmware PKCS#1v1.5 e di avviare il caricamento di un proprio firmware nell'HSM. <\/p>\n<p>Come dimostrazione \u00e8 stato organizzato il caricamento di un firmware modificato, in cui \u00e8 stata inserita una backdoor, che rimane attiva anche dopo i successivi aggiornamenti di firmware standard forniti dal produttore. Si afferma che l'attacco possa essere effettuato da remoto (il metodo di attacco non \u00e8 specificato, ma si presume si riferisca alla sostituzione del firmware da caricare o all'invio per la lavorazione di certificati appositamente elaborati).<\/p>\n<p>Un problema \u00e8 stato rilevato durante l'applicazione del fuzzing testing sull'implementazione interna delle istruzioni PKCS#11 proposta nell'HSM. I test sono stati organizzati tramite il caricamento di un proprio modulo nell'HSM utilizzando il normale SDL. Di conseguenza, nell'implementazione di PKCS#11 \u00e8 stata trovata una vulnerabilit\u00e0 di overflow del buffer, che si \u00e8 rivelata sfruttabile non solo dall'interno dell'HSM, ma anche attraverso l'accesso al driver PKCS#11 dal sistema operativo principale del computer a cui \u00e8 collegato il modulo HSM. <\/p>\n<p>Successivamente, l'overflow del buffer \u00e8 stato sfruttato per eseguire codice sul lato HSM e modificare i parametri di accesso. Durante l'analisi interna, \u00e8 emersa un'altra vulnerabilit\u00e0 che permette di caricare un nuovo firmware senza firma digitale. Alla fine, \u00e8 stato scritto e caricato nell'HSM un modulo personale, che espelle all'esterno tutti i segreti memorizzati nell'HSM.<\/p>\n<p>Il nome del produttore degli HSM che presenta vulnerabilit\u00e0 non \u00e8 ancora stato divulgato, ma si afferma che i dispositivi problematici siano utilizzati da alcune grandi banche e fornitori di servizi cloud. Si riporta inoltre che le informazioni sui problemi erano state precedentemente inviate al produttore, il quale ha gi\u00e0 risolto le vulnerabilit\u00e0 con un recente aggiornamento del firmware. I ricercatori indipendenti ipotizzano che il problema possa riguardare i dispositivi della societ\u00e0 Gemalto, che a maggio <noindex><a rel=\"nofollow\" href=\"https:\/\/safenet.gemalto.com\/technical-support\/security-updates\/?LangType=1049\">ha rilasciato<\/a><\/noindex> l'aggiornamento Sentinel LDK con la correzione delle vulnerabilit\u00e0, l'accesso alle informazioni sulle quali \u00e8 attualmente <noindex><a rel=\"nofollow\" href=\"https:\/\/supportportal.gemalto.com\/csm?id=kb_article_view&#038;sys_kb_id=f4c8e1624f413b00102400818110c78a&#038;sysparm_article=KB0018794\">chiuso<\/a><\/noindex>.<\/p>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50838\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Ledger, \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0435\u0439 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u044b\u0435 \u043a\u043e\u0448\u0435\u043b\u044c\u043a\u0438 \u0434\u043b\u044f \u043a\u0440\u0438\u043f\u0442\u043e\u0432\u0430\u043b\u044e\u0442\u044b, \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 HSM (Hardware Security Module), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u044b \u0434\u043b\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0435\u0439 \u0438\u043b\u0438 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0438 \u0434\u043b\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 HSM-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430. \u0412 \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u0434\u043e\u043a\u043b\u0430\u0434 \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u0444\u0440\u0430\u043d\u0446\u0443\u0437\u0441\u043a\u043e\u043c \u044f\u0437\u044b\u043a\u0435, \u0430\u043d\u0433\u043b\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0439 \u0434\u043e\u043a\u043b\u0430\u0434 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35134","post","type-post","status-publish","format-standard","hentry","category-novosti-interneta"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Ledger, \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0435\u0439 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u044b\u0435 \u043a\u043e\u0448\u0435\u043b\u044c\u043a\u0438 \u0434\u043b\u044f \u043a\u0440\u0438\u043f\u0442\u043e\u0432\u0430\u043b\u044e\u0442\u044b, \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 HSM (Hardware Security Module), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u044b \u0434\u043b\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0435\u0439 \u0438\u043b\u0438 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0438 \u0434\u043b\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 HSM-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430. \u0412 \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u0434\u043e\u043a\u043b\u0430\u0434 \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u0444\u0440\u0430\u043d\u0446\u0443\u0437\u0441\u043a\u043e\u043c \u044f\u0437\u044b\u043a\u0435, \u0430\u043d\u0433\u043b\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0439 \u0434\u043e\u043a\u043b\u0430\u0434 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-hsm-modulyah-kotorye-mogut-privesti-k-atake-na-klyuchi-shifrovaniya\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 HSM-\u043c\u043e\u0434\u0443\u043b\u044f\u0445, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043a\u043b\u044e\u0447\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Ledger, \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0435\u0439 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u044b\u0435 \u043a\u043e\u0448\u0435\u043b\u044c\u043a\u0438 \u0434\u043b\u044f \u043a\u0440\u0438\u043f\u0442\u043e\u0432\u0430\u043b\u044e\u0442\u044b, \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 HSM (Hardware Security Module), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u044b \u0434\u043b\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0435\u0439 \u0438\u043b\u0438 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0438 \u0434\u043b\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 HSM-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430. \u0412 \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u0434\u043e\u043a\u043b\u0430\u0434 \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u0444\u0440\u0430\u043d\u0446\u0443\u0437\u0441\u043a\u043e\u043c \u044f\u0437\u044b\u043a\u0435, \u0430\u043d\u0433\u043b\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0439 \u0434\u043e\u043a\u043b\u0430\u0434 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-hsm-modulyah-kotorye-mogut-privesti-k-atake-na-klyuchi-shifrovaniya\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:02:29+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:02:29+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilit\u00e0 nei moduli HSM che possono portare ad attacchi alle chiavi di crittografia | ProHoster","description":"Un gruppo di ricercatori dell'azienda Ledger, che produce portafogli hardware per criptovalute, ha identificato diverse vulnerabilit\u00e0 nei dispositivi HSM (Hardware Security Module), potenzialmente sfruttabili per estrarre chiavi o effettuare attacchi remoti per sostituire il firmware del dispositivo HSM. Al momento, il rapporto sul problema \u00e8 disponibile solo in francese, mentre una versione in inglese \u00e8 prevista per essere pubblicata ad agosto durante la conferenza Blackhat.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-hsm-modulyah-kotorye-mogut-privesti-k-atake-na-klyuchi-shifrovaniya","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 HSM-\u043c\u043e\u0434\u0443\u043b\u044f\u0445, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u043f\u0440\u0438\u0432\u0435\u0441\u0442\u0438 \u043a \u0430\u0442\u0430\u043a\u0435 \u043d\u0430 \u043a\u043b\u044e\u0447\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f | ProHoster","og:description":"\u0413\u0440\u0443\u043f\u043f\u0430 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Ledger, \u0432\u044b\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0435\u0439 \u0430\u043f\u043f\u0430\u0440\u0430\u0442\u043d\u044b\u0435 \u043a\u043e\u0448\u0435\u043b\u044c\u043a\u0438 \u0434\u043b\u044f \u043a\u0440\u0438\u043f\u0442\u043e\u0432\u0430\u043b\u044e\u0442\u044b, \u0432\u044b\u044f\u0432\u0438\u043b\u0430 \u043d\u0435\u0441\u043a\u043e\u043b\u044c\u043a\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430\u0445 HSM (Hardware Security Module), \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u0443\u0442 \u0431\u044b\u0442\u044c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u044b \u0434\u043b\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u043a\u043b\u044e\u0447\u0435\u0439 \u0438\u043b\u0438 \u0441\u043e\u0432\u0435\u0440\u0448\u0435\u043d\u0438\u044f \u0443\u0434\u0430\u043b\u0451\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0438 \u0434\u043b\u044f \u043f\u043e\u0434\u043c\u0435\u043d\u044b \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 HSM-\u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432\u0430. \u0412 \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u0439 \u043c\u043e\u043c\u0435\u043d\u0442 \u0434\u043e\u043a\u043b\u0430\u0434 \u043e \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0435 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0442\u043e\u043b\u044c\u043a\u043e \u043d\u0430 \u0444\u0440\u0430\u043d\u0446\u0443\u0437\u0441\u043a\u043e\u043c \u044f\u0437\u044b\u043a\u0435, \u0430\u043d\u0433\u043b\u043e\u044f\u0437\u044b\u0447\u043d\u044b\u0439 \u0434\u043e\u043a\u043b\u0430\u0434 \u043f\u043b\u0430\u043d\u0438\u0440\u0443\u0435\u0442\u0441\u044f \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0432 \u0430\u0432\u0433\u0443\u0441\u0442\u0435 \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u043a\u043e\u043d\u0444\u0435\u0440\u0435\u043d\u0446\u0438\u0438 Blackhat","og:url":"https:\/\/prohoster.info\/it\/blog\/novosti-interneta\/uyazvimosti-v-hsm-modulyah-kotorye-mogut-privesti-k-atake-na-klyuchi-shifrovaniya","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:02:29+00:00","article:modified_time":"2019-10-31T19:02:29+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35134","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 21:59:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:09:54","updated":"2026-01-21 21:59:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/35134","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=35134"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/35134\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=35134"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=35134"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=35134"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}