2 ms·
If you trust the OS, it could hypothetically be built into the OS such that the app only gives what needs to be encrypted to the OS and gets back an encrypted p
by corin_ 5y ago
If you trust the OS, it could hypothetically be built into the OS such that the app only gives what needs to be encrypted to the OS and gets back an encrypted payload to send, then the app wouldn't need to access your keys?
Of course at that point the OS has to either provide good key management itself, or a good API so that the apps can still make things seamless while still not accessing the keys directly.. and probably other problems I haven't thought of.
- tantalor 5y agoMakes sense. OS already does key storage (eg, secure enclave [1]) so its not hard to imagine en/decrypt without the key leaving storage. [1] https://developer.apple.com/documentation/security/certificate_key_and_trust_services/keys/storing_keys_in_the_secure_enclave https://developer.apple.com/documentation/security/certifica...