
DEF CON 33 - Reconfigurable HSMs: Future Proofing Hardware Security - Pablo Trujillo
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 25:01
Revised Summary
The presentation proposes using reconfigurable FPGA devices to implement flexible cryptographic systems that can be updated to counter evolving threats, particularly quantum computing. The presenter, an FPGA designer who shares projects on platforms like Hackster and Hackaday, argues that traditional cryptographic implementations (both software and hardware) lack the adaptability needed for future security challenges.
Key Takeaways:
• Current cryptographic vulnerabilities: MD5, SHA0, and SHA1 have already been broken due to collision attacks. When quantum computing is factored in, SHA2 and most encryption algorithms become vulnerable through Grover's algorithm (reducing security from n to √n) and Shor's algorithm (efficiently finding prime factors). Only SHA3 remains secure against quantum attacks.
• Quantum computing threats: Quantum computers use qubits that can represent multiple values simultaneously through superposition, enabling the execution of quantum algorithms that dramatically reduce the security of current cryptographic systems. Grover's algorithm reduces the security of symmetric algorithms like AES-256 from 256 bits to 128 bits, while Shor's algorithm effectively breaks RSA by finding prime factors.
• Software implementation limitations: Cryptographic software suffers from poor performance due to OS overhead and processor limitations. Keys stored in hard disks create significant security risks, and while easy to update, software implementations create dependencies on specific processor extensions.
• Traditional hardware constraints: Devices like TPM modules provide better performance and secure key storage but create vendor lock-in and algorithm dependencies. Most TPMs implement only widely used algorithms like SHA-256 and lack post-quantum alternatives.
• FPGA advantages: Reconfigurable devices allow implementing multiple cryptographic algorithms in parallel, can be updated to post-quantum a
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hello everybody and thank you for being here today to in this session this presentation we are going to talk about security and the algorithms and the devices in charge of our security when we are navigator on internet or we are sharing files or information we're going to talk about keys hesit also we're going to we're going to talk about the future threats that can essentially break them for example example the quantum computing also in the in the beginning of the ending of the presentation I want to propose you to use reconfigurable devices to uh be in charge of that security recon reconfigurable devices are devices that the the designer can program or can configure its internal hardware um architecture in order to make them resilient to new uh thread for example or to the to update the …