Hacking HSMs without hardware access is extremely hard—probably not impossible but likely will take a sizable amount of inference compute (I’d guess $Bs)
I meant to say that, if the user-facing app has soft attack surfaces, a model could hack the user’s app and send commands from there; and that this app is constantly exposed to model outputs.
Hacking HSMs without hardware access is extremely hard—probably not impossible but likely will take a sizable amount of inference compute (I’d guess $Bs)
I meant to say that, if the user-facing app has soft attack surfaces, a model could hack the user’s app and send commands from there; and that this app is constantly exposed to model outputs.