3 ms·
> These chips would typically be certified by some vendor (for example, Intel SGX) with some claim that it’s hard to tamper with them. Unfortunately for Intel a
by dane-pgp 4y ago
> These chips would typically be certified by some vendor (for example, Intel SGX) with some claim that it’s hard to tamper with them. Unfortunately for Intel and others, the security community has found a lot of interest in publishing attacks on their "secure" hardware, and we see new hacks coming up pretty much every year.
Even if Intel engineers were capable of writing firmware with zero bugs and their chips were able to resist all hacking attempts, any user of those chips has to treat Intel as a trusted third party.
This is especially bad if, in practice, you have to regularly apply (encrypted?) firmware updates from Intel whenever they tell you to (because your users won't trust an execution which comes with a proof from an out-dated firmware version).
Once you've accepted Intel as a trusted third party, then consider that they are subject to interference by at least one government, so now your threat model has to include them too.