HSM (Hardware Security Modules), according to Wikipedia, is a physical computer device that secures and manages digital keys for strong authentication and provides cryptography. These modules traditionally take the form of a plug-in card or external device, connected directly to a computer or network server.
In reality, they are devices that look like computer add-on cards or USBs. Their most common use is in financial institutions, government agencies, data centers, cloud , and telecommunications carriers.
Two security researchers in France, Gabriel Campana and Jean-Baptiste Bédrune, have disclosed flaws that could be exploited to remotely recover data from an HSM. Their research has only been published in French for now, but they will soon be presenting it in the United States at Black Hat.

According to the research, these flaws could theoretically allow hackers to gain complete control of the HSM remotely without any authentication. In this way, they could use a cryptographic flaw to upload modified firmware to the HSM, which would not be reverted even with an update. The research was disclosed to the creator of Hardware Security Modules.
Cryptosense, the team behind the security software, translated and provided a summary of the research and shared it. The team also said that the methods used by the Ledger research team are not particularly innovative and that other teams could have discovered these security flaws, perhaps better.
“Surely well-funded research groups dealing with vulnerabilities in government intelligence agencies could have done similar work and discovered this attack,” the Cryptosense.
