3 ms·
SGX is a major point and one I thought the linked post would deal with from its title. For a user-owner point of view, I agree with your assessment of SGX. I
by ctz 11y ago
SGX is a major point and one I thought the linked post would deal with from its title.
For a user-owner point of view, I agree with your assessment of SGX. I imagine that, once it becomes used for things like media DRM and games copy protection, users will start turning it off in their BIOS, or managing the signing key whitelist manually. And I wouldn't blame them.
But from a user-not-owner point of view (ie, cloud computing), SGX offers the user more security, and a degree of protection against some cloud computing risks.
- pdkl95 11y agohttps://jbeekman.nl/blog/2015/10/intel-has-full-control-over-sgx/ https://jbeekman.nl/blog/2015/10/intel-has-full-control-over...
- the8472 11y agoIf you don't trust your cloud provider i'm not sure whether SGX is the solution. Consider all those side-channel attacks. It might provide an additional defense barrier, but you'd still want to run on trusted hardware. And if you have trusted hardware then it should be ok to use user-provided signing keys, just as you can do with secure boot configurations (at least the acceptable kind). So as long as you're the exclusive user of a machine it should be sufficient to also hand your public key to the cloud provider so they can put it in the BIOS. The only reason for SGX to not support that is DRM&Co.