3 ms·
I don't suppose there's any more information on how remote attestation works? (Ideally something an idiot like me could comprehend). I can't understand how, if
by BuildTheRobots 7y ago
I don't suppose there's any more information on how remote attestation works? (Ideally something an idiot like me could comprehend).
I can't understand how, if the company has control of the code running there, they can't just modify it to report as the known good code. It seems like it'd be slightly different from the DRM example where the end user can't access the code running in the enclave in the first place and doesn't know what it'd be reporting back.
- BuildTheRobots 7y agoI can't edit my comment, but after reading up on Intel's secure enclave last night, I still don't get how this would work in practise. As the end user (me) needs to know what the server is going to return in order to verify that, I don't understand what's stopping the server from returning that anyway. Even if it's using public key crypto to sign a challenge I send it, I still don't understand how I can have any assurance that this key only exists inside the enclave and isn't just running in software on the server.