3 ms·
Even if an SGX attack does take place, tx's aren't recognized as the system is secured with Cryptonote's ring signatures (1st reply in FAQ https://github.com/mo
by AfouToPatisa 6y ago
Even if an SGX attack does take place, tx's aren't recognized as the system is secured with Cryptonote's ring signatures (1st reply in FAQ https://github.com/mobilecoinfoundation/mobilecoin https://github.com/mobilecoinfoundation/mobilecoin)
here too about 11mins in - https://www.youtube.com/watch?v=e9afDQ_M5CU https://www.youtube.com/watch?v=e9afDQ_M5CU
- codethief 6y agoThe problem is: Signal already relies on SGX for lots of other features (Signal PINs & Secure Value Recovery, contact discovery etc. etc.) and these depend on SGX working as advertized.
- AlexCoventry 6y agoI wasn't aware that Signal relies on SGX. If I want to use Signal without being exposed to risk of SGX compromise, is it still possible?
- codethief 6y agoFor contact discovery, AFAIK no[0]. For everything else: Yes, by setting a randomized long Signal PIN since SGX is effectively used to add entropy to Signal PINs[1]. You can also disable Signal PINs – in this case Signal will simply set a randomized long PIN for you. [0]: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ [1]: https://signal.org/blog/secure-value-recovery/ https://signal.org/blog/secure-value-recovery/
- AlexCoventry 6y agoThanks!