3 ms·
I am probably very uninformed, but I was hoping we might see the kernel + userland running entirely from a secure enclave. As I understood, this would make col
by blitmap 8y ago
I am probably very uninformed, but I was hoping we might see the kernel + userland running entirely from a secure enclave. As I understood, this would make cold boot attacks more difficult? I'm sure it's like using a sledgehammer to close a narrow attack surface, though. From a performance point of view it's probably not a great exchange.
At minimum I'd want full-disk encryption programs (veracrypt) and biometric authentication services running from an enclave. Lenovo does this for their fingerprint reader.
It would be cool to have the facilities to say "everything run by this user runs in the enclave", but I think the argument is the same as FDE - don't invite the possibility of a leak by selective encryption. All or nothing.
- jki275 8y agoThat's very restrictive in terms of general purpose computing. It makes a lot of sense in some other cases though.