2 ms·
There are a few categories of usage for enclaves (well, more broadly, Trusted Execution Environments): 1) Clouds (you mostly trust the provider, but maybe not
by strstr 2y ago
There are a few categories of usage for enclaves (well, more broadly, Trusted Execution Environments):
1) Clouds (you mostly trust the provider, but maybe not fully. And you want to make sure they don’t have anything up their sleeves. Consider the FBI vs Apple encryption dispute)
2) Intra-corporation stuff as a mitigation against hacked users, malicious insiders, and malware (think crypto oracles for terminating SSL, requiring bootchain attestation before giving corporate credentials)
3) The more icky category: Places where you distrust your own customer (DRM, and probably eventually, game anticheat)
The userspace code being more privileged than kernel code has never really been true. Maybe arguably true for SGX, but even then, all you get is the ability to prove you were initialized in the “right” way. All the other TEEs have a kernel mode component (they are typically ways of running attestable VMs).
- hurutparittya 2y agoIf only there was a way to make the third use case illegal... Users should be treated as GODS on the machine they own. They should be the one holding all the keys to the kingdom. There should not be any hardware/firmware feature that can subvert this authority by either concealing things, or snitching on the user. My machine should not work against me.