public inbox for [email protected]  
help / color / mirror / Atom feed
From: Laurenz Albe <[email protected]>
To: [email protected]
To: Bruce Momjian <[email protected]>
Cc: Ken Marshall <[email protected]>
Cc: [email protected]
Subject: Re: Enquiry about TDE with PgSQL
Date: Mon, 03 Nov 2025 19:30:01 +0100
Message-ID: <[email protected]> (raw)
In-Reply-To: <[email protected]>
References: <[email protected]>
	<CO1PR19MB4984B665A5F9F38A5E0FB5969BF9A@CO1PR19MB4984.namprd19.prod.outlook.com>
	<[email protected]>
	<CAKt_ZfuwPgG_nJHp6S=8k_+NdA6Op7hE0z7+s4-HuBqr1cnwsg@mail.gmail.com>
	<CAG0qCNjd2m9Ej1ZEwuCCkgsqJz0vnso3ZFwjKCxzwUfnfu=SNw@mail.gmail.com>
	<[email protected]>
	<[email protected]>
	<CAKAnmmJ4yRTb-TV=ik0aoEZsWzDzuKRgCjXFfF5DCzR5jiCQdA@mail.gmail.com>
	<[email protected]>
	<[email protected]>
	<[email protected]>
	<[email protected]>

On Mon, 2025-11-03 at 16:39 +0100, [email protected] wrote:
> The HSM should be backed up, too. Which is only possible by connecting 
> physically to it with a notebook and inserting an USB stick.
> 
> Which begs the question: where do you source an USB stick with the same 
> trust-level as the 20k-a-pop HSM?

I'd say that you don't need a very secure USB stick.  You just put the
USB stick in a very secure safe that only two very trustworthy people
can open together.

Yours,
Laurenz Albe






view thread (9+ messages)  latest in thread

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: [email protected]
  Cc: [email protected], [email protected], [email protected], [email protected]
  Subject: Re: Enquiry about TDE with PgSQL
  In-Reply-To: <[email protected]>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox