What a hardware security module taught me about trust
Six weeks configuring Thales HSMs in a San Francisco data centre, and the one lesson that outlasted the project.
A hardware security module is a box whose entire job is to refuse. It holds keys it will never hand back, signs what you ask, and logs the attempt either way. Nothing about the interface is convenient, and that is the design.
Setting up a security world means deciding, up front and in writing, who can do what — how many cards it takes to unlock, who holds them, what happens when one is lost. There is no admin override. Systems that behave this way are rare, and they are the only ones I have never seen quietly bypassed under deadline pressure.
I have carried that shape into product work since. Write down the constraint before the feature. Make the recovery path explicit rather than implied. Prefer a system that says no clearly over one that says yes and hopes.
Replace this text with your own version of the post. The structure here is what a finished piece looks like in the panel: a lead paragraph, three or four sections, and a closing line worth quoting.