4 ms·
> Signals new PIN thing relies (almost) entirely on SGX being secure to make their encrypted profile and contact backups secure. This just seems irresponsible.
by usmannk 6y ago
> Signals new PIN thing relies (almost) entirely on SGX being secure to make their encrypted profile and contact backups secure.
This just seems irresponsible. How could they excuse this? It seems like anyone who has even peripherally been working with TEEs recently is _well_ aware that SGX is broken beyond repair. It's not just a matter of patching bugs, this whole model seems bunk.
- RL_Quine 6y agoSeems unlikely they were mentioned in the paper in this depth without being made even casually aware that this paper would be published. Which means they just went ahead with it anyway.
- lima 6y agoStill useful for plausible deniability if the government comes knocking.
- saagarjha 6y agoEven people not working on TEEs are aware that SGX is broken. Actually, you don't even have to even know what SGX is to bring up the concern that their entire scheme relies on SGX working correctly.