HaJ3FgupAm8RrDJW3MHgT9X7Ft27eVaD
  • kibiz0r@midwest.social
    link
    fedilink
    English
    arrow-up
    7
    ·
    6 days ago

    Unique private key per device, pre-provisioned certificate at manufacturing time, hardware-level separation of crypto operations so sensitive creds are never in memory.

    It’s a bit more expensive to manufacture, in terms of BOM and logistics. And then you have a lot more complexity to your production system too.