4 ms·
SGX’s per-chip private keys are the “flag” in Intel’s unintentional CPU vulnerability CTF. Those keys have been popped so many times. Reading the original the
by strstr 4y ago
SGX’s per-chip private keys are the “flag” in Intel’s unintentional CPU vulnerability CTF.
Those keys have been popped so many times.
Reading the original they explicitly state that side channels are out of scope for their threat model. As a result, designed a system that was essentially maximally vulnerable to side-channels (and other architectural issues). It’s really hard to trust SGX as a result. Otoh, if I were in a bind and needed to do trusted computation on an untrusted host, are there really other options that don’t suffer similar (or worse) issues?
- anonymousDan 4y agoNot really (at least not on 'commodity' CPUs). It is still an active (and very interesting) area of research. There is a lot of work going on into both attacks and practical defenses for this kind of stuff. Whether it is truly solvable in practical settings remains unclear. I do believe it raises the bar enough for it to be useful in many scenarios though.