4 ms·
You know it was hard enough for PayTV smart card developers to keep transistor level reverse engineers from getting inside their chips, and all that was at stak
by cyphunk 9y ago
You know it was hard enough for PayTV smart card developers to keep transistor level reverse engineers from getting inside their chips, and all that was at stake then was $35 content subscriptions. I can't imagine how putting personal banking inside SGX will fare. Or, I acknowledge I am probably missing something. Am i?
- mike_hearn 9y agoIt wasn't that hard and the stakes were much higher than that. Individual subscriptions could be much more, but the entire black market of glitching units was an industry worth many hundreds of millions of dollars. Ultimately DirecTV was able to kill pay TV hacking by simply introducing a new generation of cards that were better protected, the P4 series iirc. Other pay TV firms invested less and were mostly undermined by just one guy (Tarnovsky) - not exactly an army of reverse engineers. The weak points in SGX security aren't the electronics themselves. So far all attacks on it are side channel based.
- cyphunk 9y agoTarnovsky wasn't the only key. There was also a single minded team of former intelligence investigators spread around the world coercing and infiltrating, on top of a smartcard dev team packed with most of moscows mathematics prize winners, in addition to another red team in haifa with their own tarnovsky's. I speak from first hand knowledge because in my younger and more naive years I used to worked with them. Still, the analogy applies because the stakes with a cryptocurrency that depends on transistor security become a much more interesting target then the, now boring++, paytv market. It should not be assumed that any secrets will stay inside of that secure enclave, at all. ++it's boring to hack paytv because streaming, downloads and card sharing removed a large bulk share of the need
- awakeasleep 9y agoyou're missing that the protections SGX offers will only be one layer of the security model