3 ms·
What about things like Trusted Execution Environments? I know that people love bashing them for being broken, but realistically speaking.. if you don't have mal
by v4dok 4y ago
What about things like Trusted Execution Environments? I know that people love bashing them for being broken, but realistically speaking.. if you don't have malicious nation state level actor in your threat model(since legally there is no way to get the data, only by breaking it, and even then with a lot of asterisks), they could help a lot with moving things server side in an encrypted form.
- hedora 4y agoHobbyists are pulling keys out of current TPM chips, but why bother with that (it requires physical access), when automated, fully remote attacks are available: https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/tang https://www.usenix.org/conference/usenixsecurity17/technical...