3 ms·
> Confidential computing is designed to protect applications and their data from theft or tampering by protecting them inside a secure enclave, or trusted execu
by 8jef 3y ago
> Confidential computing is designed to protect applications and their data from theft or tampering by protecting them inside a secure enclave, or trusted execution environment (TEE). This uses hardware-based security mechanisms to prevent access from everything outside the enclave, including the host operating system and any other application code.
That brand of confidentiality appears to be, as it's described in the article, sandboxing for hardware.
Sounds like creating potentially multiple proprietary _black boxes_ inside one system, that could use available network tools to report to vendors any and all system functions, in some uniquely and completely opaque way.
Therefore, _confidential computing_ (black box filtering of processing input and output in different pieces of hardware?) seems as opposed to _confidential use_ (confidentiality of user's data) in a computing system as it possibly can be. Or peddling confidentiality while opening some doors to the exact opposite.
I can understand the need for vendors to be informed about what we do on system they manufacture, just not sure this is what we need as people having to use computers.
- galaxyLogic 3y ago> use available network tools to report to vendors any and all system functions, But you do have firewalls and other network monitoring tools. So if the confidential program would try to do what you say, sending messages to somewhere, that would be detectable, not opaque. No?
- 8jef 3y agoWell, yes, firewalls are there, from the OS. But a hardware black box is a black box, opaque by definition, beyond the realms of the operating system. We already know some (if not most) hardware subsystems already have their own (maybe) limited OS, lighting up even before the main OS boot. What about hardware black boxes with covert networking capabilities no OS can see? I also know that in the case of Windows 10 or 11 (or previous versions?), lots of action is happening without the knowledge of users, behind what is reported by firewall softwares. What about Linux OSes? I'm not succumbing to paranoia here, and I know there are lots of specialised softwares and tools that can intercept and analyze traffic, but I'll never use these, as for most computing device users. Right now, OS's get to spy on us in many ways. >This< will permit hardware vendors to do the same, and worse. Why should I use a computer that has some other computers within it doing all sorts if computation and communication I don't know about?
- galaxyLogic 3y ago> Why should I use a computer that has some other computers within it doing all sorts if computation and communication I don't know about? You shouldn't. You should be in control of enabling confidential computing or not. I don't think the purpose is to make everybody's computers do some secret things they don't know about. This I think is for the case of a company sending some data to the cloud to be processed and wanting to make sure nobody else can see that processing or interfere with that.