top of page

CETHERA Security Research Hub
The Hardware Key Exposure Ladder: Seven Places Your Encryption Key Can Exist
Cryptographic keys exist in different locations during their lifecycle. A key may be created in software, stored in a configuration file, loaded into process memory, protected by a platform module, retained in a hardware security module.
21 hours ago5 min read
HSM vs TPM vs Secure Enclave vs QSPU: Where Should Cryptographic Keys Live?
Cryptographic keys should be kept in a security boundary appropriate to their purpose, value, and workload. A device identity key, a certificate-authority key, a disk-encryption key, and a high-volume TLS traffic key do not have identical requirements.
21 hours ago4 min read
What Happens to TLS Keys When a Server Is Compromised?
TLS 1.3 protects data in transit, but active session secrets must exist somewhere while a connection runs. Learn what can be exposed when a server is compromised—and how hardware key custody changes the model.
21 hours ago3 min read
Your Server Is Encrypted—So Why Can Malware Still Steal the Keys?
Encryption protects data only while an attacker cannot obtain the cryptographic key needed to use it. A server may correctly encrypt storage, database records, backups, and network traffic, yet still handle active cryptographic keys in host memory while those services run.
22 hours ago2 min read
bottom of page
