>True. But HSM claims performance, correctness and security. Jeffrey's point is that you need whole-system security, not just faster crypto. (And your original note didn't say HSM, but implied just an accelerator card.) For example, how do you make sure that only authentic and authorized software can connect to the HSM?
/r$ -- Principal Security Engineer Akamai Technology Cambridge, MA