3 ms·
One of the things that bugged me about this presentation (and, to a similar extent, with Oxide as a whole) is the assertion that the only way we can have safe a
by Sirened 4y ago
One of the things that bugged me about this presentation (and, to a similar extent, with Oxide as a whole) is the assertion that the only way we can have safe and trustworthy systems is if each and every component is trustworthy. This is, obviously, a true statement—if we manage to wrangle every component of a system and put it under the control of safe and secure software, we have a really secure system. I don't, however, believe that this is the only way (or, in fact, even the most realistic). Rather, I think we will (for better or for worse) go straight in the opposite direction and end up treating the entire system as an autonomous sea of untrustworthy cores. SGX, for all of its flaws, I think got the nearest to this because it bootstrapped trusted compute in an environment where it couldn't even trust DRAM to not change underneath it. Assuming that every other system agent is hostile lets you use random proprietary garbage without needing to fully control every single core and microcontroller on the platform. It is truly a pain in the ass to program this way but it is, fundamentally, something we can do.
This, of course, isn't to say I wouldn't love to have a system where we can run our own open implementation on every bit of the platform, but rather that I don't believe we ever will. Oxide has made it pretty far, no doubt, and it's an incredible feat but as Bryan mentioned, their staff is literally reverse engineering hardware and finding completely undocumented cores in the things they're putting in charge of their platform. Hell, most companies I've been at hardly even know the full capabilities of their shipped silicon (did we slap a chicken bit on that? did we fuse off that performance analysis module for production runs? did we fully remove that one feature that didn't verify before our tapeout deadline? did we backport that one bug fix to all relevant generations? and on and on) and so its many times not even a case of companies being over protective but rather people not being able to even reason about these complex systems.
Both Bryan and Roscoe raise the question of who is at the helm of the ship and each find a different monster steering. The truth is that nobody is actually in control on these SoCs because nobody has the last word or some distinct power that cannot be compromised with some other random power. SoCs are not hierarchical; they're ridiculously complex systems of federated power, and we really need to treat them as such.
- pas 4y agoYou still need at least one trusted core/chip, you need trusted comms to it (eg. it needs an embedded, or securely programmable secret/privkey, and it needs to be able to run some kind of crypto, key exchange), and then you are still left with wondering what the other cores/components are doing. Who is leaking/sniffing/corrupting data, when, and how... So what we need is compartmentalization and a blessed central core ... and that's hierarchy anyway. Yes, of course 99.99..% it's a forgotten fuse or whatever legacy junk. But apparently some folks believe there's is a business model to be built on that last 0.00.. :)