4 ms·
Signal is applying SGX secure enclaves to engineer a new contact discovery server design. This is doubtlessly promising and innovative. My only question is the
by nkobeissi 9y ago
Signal is applying SGX secure enclaves to engineer a new contact discovery server design. This is doubtlessly promising and innovative.
My only question is the following: what protection is there against the server sending a correct remote attestation for the code being executed to the client, and then, right after this attestation is validated, the server rerouting the network pipe so that the contact list the client sends goes to a different server running different, non-SGX code?
I ask that as a non-expert in SGX, so this might be something that has an obvious answer.
Edited to add: Also, isn't it the case that verifying SGX remote attestations requires phoning home to Intel? If that's the case here (and I'm not sure that it is,) is Intel consequently able to build an IP address graph of Signal users?
Edit 2: Matthew Green has provided a credible answer to my initial question: https://twitter.com/matthew_d_green/status/912745582413918208 https://twitter.com/matthew_d_green/status/91274558241391820...
- JoshTriplett 9y ago> My only question is the following: what protection is there against the server sending a correct remote attestation for the code being executed to the client, and then, right after this attestation is validated, the server rerouting the network pipe so that the contact list the client sends goes to a different server running different, non-SGX code? The same thing that prevents contacting an HTTPS server and having your connection re-routed after verifying the server certificate: the code elsewhere (e.g. outside the enclave) doesn't have the keys.
- nkobeissi 9y agoThat makes sense. In this case I think it would be interesting to analyze the state space for the network protocol involved.