LATIDIA · Ciberseguridad
Almacenes de claves de hardware para flujos de trabajo de firma de agentes de IA: una arquitectura de cumplimiento MCP de confianza cero
arXiv:2608.06130v2 Tipo de anuncio: reemplazar Resumen: los agentes de IA firman cada vez más confirmaciones de Git, certifican documentos y certifican artefactos de liberación en nombre de sus operadores, utilizando claves privadas que viven en software-accessib
WhatsApp ↗Telegram ↗
La noticia
arXiv:2608.06130v2 Announce Type: replace Abstract: AI agents increasingly sign Git commits, certify documents, and attest release artifacts on behalf of their operators, using private keys that live in software-accessible locations (plaintext files, environment variables, container memory) readable by any process the agent can reach. A widely deployed agent framework recently leaked its keys this way to a single email injection. Hardware keystores (HSM, TPM, smart card) keep the key on-device, but exposing the keystore as a tool an LLM agent can call moves the problem rather than removing it: once a signing session exists, the hardware cannot tell a request reflecting the operator's intent from one injected into content the