#YubiHSM
Trust, but verify!

The Dark Bio firmware and device signing keys are hardware bound to genuine YubiHSM and YubiKey devices.

Furthermore, the public audit logs demonstrate (within the limits of the YubiHSM 2 capabilities) that no malicious firmware exists.
As a commitment to transparency, we've created a repository of our signing keys and operations.

The repository also includes YubiHSM and YubiKey provenance attestations, signer certificate chains and full audit logs.

More in an upcoming blog post.
GitHub - dark-bio/transparency: Cryptographic transparency reports
Cryptographic transparency reports. Contribute to dark-bio/transparency development by creating an account on GitHub.
github.com
March 9, 2026 at 7:49 PM
Just landed: Learn Kubernetes weekly 180! My top picks:

🔐 Hardware-backed TLS with YubiHSM 2
📈 KEDA on GKE: Event-Driven Autoscaling
🔀 Migrate from NGINX to Traefik in Minutes
🧠 RootCause MCP Server

Read it here: https://kube.today/issues/180
April 22, 2026 at 12:11 PM
new toy! new toy! this is like a yubikey nano but at 10x the cost!

its going to take a while to figure out how to make use of this but it will be prefect for what i need
March 7, 2025 at 6:27 AM
New root of trust for my @dark.bio genomic Arks. 🥳 Because I don't want to trust myself to not mess up handling the root keys. Also because I can generate an audit log of signatures to prove nothing malicious was ever signed. #yubihsm #darkbio
July 14, 2025 at 9:02 AM
Unless I'm misunderstanding the docs, seems that @yubico.com 's YubiHSM modules fall short at a crucial operation from being a truly auditable root of trust for a system.

Specifically, you cannot prove that you didn't create a hidden copy of a private key. 🧵
June 1, 2025 at 8:58 AM
Really excited to test out the YubiHSM 2 as a very low cost option for running our PKI on prem.
April 8, 2025 at 3:58 PM
My personal pain is because I want to create a transparency report for my @dark.bio project, which seems semi-impossible with the YubiHSM.

If your threat model is to protect the keys from bad actors, a YubiHSM is perfect. If you want to demonstrate no misuse, though luck.
July 17, 2025 at 5:33 PM
You should checkout the YubiHSM.
December 7, 2024 at 3:08 PM
Added a shell YubiHSM audit log verified because @yubico.com does not provide one (seems an annoying omission).
Publicly auditable YubiHSM logs
Publicly auditable YubiHSM logs. GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
July 15, 2025 at 1:03 PM
Took me two days, but managed to finally automate my @dark.bio firmware release flow 🥰 Sooooooo many keys all over the place 🤪

Still need a tiny CLI to pull a released binary and sign it with a YubiKey/YubiHSM and push the sigs back, but otherwise it's so nice to see it work...
May 28, 2025 at 3:16 PM
For my @dark.bio genomic project, I'm still debating how much to open source; but what I'd definitely like open, is an audit trail of the things I signed with the root keys.

To that end, I've been exploring how to create a publicly verifiable #YubiHSM audit log. 1/N 🧵
July 15, 2025 at 11:25 AM
An all die #YubiKeys nutzen, es gibt wohl eine ungepatchte Sicherheitslücke un d #Yubico weigert sich die betroffenen Keys auszutauschen:
www.notebookcheck.com/Ungepatchte-...
Ungepatchte Sicherheitslücke im Zwei-Faktor-Authentifizierungsschlüssel von Yubico beeinträchtigt die Sicherheit der meisten Yubikey 5, Security Key und YubiHSM 2FA-Geräte
Eine ungepatchte Sicherheitslücke im Zwei-Faktor-Authentifizierungsschlüssel von Yubico gefährdet die Sicherheit der meisten Yubikey 5, Security Key und YubiHSM 2FA-Geräte. Die Feitian A22 JavaCard is...
www.notebookcheck.com
September 25, 2024 at 1:54 PM
Sigh, seems my enthusiasm was premature. The #YubiHSM audit logs are not digitally signed and there is no way to have the HSM attest them.

That means I can just forge an arbitrary audit journal and publish that. Only physically querying the HSM can prove it's real or fake. 🤮
For my @dark.bio genomic project, I'm still debating how much to open source; but what I'd definitely like open, is an audit trail of the things I signed with the root keys.

To that end, I've been exploring how to create a publicly verifiable #YubiHSM audit log. 1/N 🧵
July 16, 2025 at 9:30 AM
My Yubikey has a small nylon string loop like this one, so maybe something similar.

www.yubico.com/product/yubi...
Yubico x Keyport ParaPull Lanyard
ParaPull Lanyard is the ideal accessory for removing YubiKey Nano and YubiHSM products from the USB port.
www.yubico.com
December 8, 2025 at 4:19 PM
Hey @yubico.com , on your website you state that the YubiHSM audit logs are *signed* by the device. Please share how I can retrieve the *signature*.

I don't want the *hash*, but the *signature* that's mentioned on your product page. Thank you.
July 16, 2025 at 10:10 AM
Having played with a #YubiHSM for about 4 full days, I'm kind of happy with the choice! 😁 That said, it also falls short on a number of places, so your mileage may vary (also some places where I needed it not to fall short). 🧵
July 17, 2025 at 5:33 PM
Does anyone have experience with YubiHSM? I'd like to be able to digitally sign some firmwares for secure boot. But once I go down that path, my key needs to live as long as any device bound to it. I.e. I need to take care of the key properly.
February 8, 2025 at 1:45 PM
Fuck my life, a #YubiHSM can:

- Attest asymmetric keys
- Generate asymmetric wrap keys
- CANNOT attest asymmetric wrap keys

I.e. when you're trying to back up your HSM to another HSM, it's cryptographically impossible to prove that it will be encrypted to the HSM you intend to.
July 18, 2025 at 8:49 AM
As a commitment to transparency, we've created a repository of our signing keys and operations.

The repository also includes YubiHSM and YubiKey provenance attestations, signer certificate chains and full audit logs.

More in an upcoming blog post.
GitHub - dark-bio/transparency: Cryptographic transparency reports
Cryptographic transparency reports. Contribute to dark-bio/transparency development by creating an account on GitHub.
github.com
March 9, 2026 at 7:42 PM
TIL that Ed25519 digital signatures have 2 modes: pure-ed25519 and ed25519ph. The former operates on a raw message, the latter on a pre-hashed message.

The purpose of ed25519ph is to run on HSMs. The YubiHSM does not support it... so for $800, it can only sign 2019 bytes max. 🥲
July 21, 2025 at 11:35 AM
Sooo... I think I can still solve it, but it's 🤮🤢🤮🤢🤮

The YubiHSM *does* have an identity, but you *cannot* attest the audit log with it.

But if you add an asym-key auth, your session with the HSM will be authenticated. So get the logs and publish the entire comms 🤪🤮
July 16, 2025 at 11:05 AM
Please pray to the live demo Gods over lunch so Ximon can show you our #DNSSEC signer Cascade in action this afternoon at #OARC46.

We’ll cover incremental signing with IXFR in and out with TSIG, all on a YubiHSM we packed. 🤞
May 17, 2026 at 11:00 AM
tried to see how it would work if i put a yubikey nano on a chainmaille chain and i love it. except that they are capacitive touch and having a metal attached seems to glitch things out.

dont know if the yubihsm (same form factor but way cooler) uses touch yet but i want that on a chain
March 7, 2025 at 6:41 AM
Then I can do something like:

params.FindSecureBootSigner(params.STAGING))

And it returns me a construct that I can just call to sign a firmware blob, without caring if it's a dev key, yubikey, yubihsm, whatever.

Feels so good to work in #golang a bit, jesus the productivity.
July 19, 2025 at 10:22 AM
All in all there doesn't seem to be a better product on the market at a price range I can actually afford, so the YubiHSM will have to do, but anyone looking into it, be advised, the auditing capability assumes a *lot* of trust that could have been avoided, just wasn't. Fin.
July 17, 2025 at 5:33 PM