3 ms·
Those aren't caveats at all. First, this is explicitly a vulnerability compromising SGX itself, so saying SGX has to be enabled is tautological. It's not a vul
by throwawaymath 7y ago
Those aren't caveats at all.
First, this is explicitly a vulnerability compromising SGX itself, so saying SGX has to be enabled is tautological. It's not a vulnerability attacking Intel processors generally, and it's not being billed that way either.
Second, securing memory against untrusted privileged execution is a defining characteristic of SGX, so it's likewise unsurprising that it would be required. That is quite literally the intended purpose of SGX.
The design thesis of SGX is to prevent "all hope is lost" from being true in the context of privileged execution.