6 ms·
As I understand, the purpose of "secure enclaves" is to enforce DRM, copyright protection, anti-debugging measures, so breaking them is a good thing.
by codedokode 11mo ago
As I understand, the purpose of "secure enclaves" is to enforce DRM, copyright protection, anti-debugging measures, so breaking them is a good thing.
- embedding-shape 11mo agoWell, also used for confidential computing and other stuff that you might benefit from too, so not just to gatekeep stuff. Depending on what you use it for (or rather, what your computer is using it for), you might not want it broken in all cases. With that said, I'd rather see it broken than not, considering it's mostly used for negative stuff, and it isn't open enough to evaluate if it actually is secure enough.
- codedokode 11mo agoThe purpose of secure enclave is to prevent administrator from accessing the data. I don't want anyone doing "confidential computing" on my devices. I am the person which can be trusted so there is no need to hide the encryption keys from me.
- hollerith 11mo agoThe false assumption in your argument IMHO is the assumption that none of the software on your device will ever betray you or contain an exploitable security hole. In actuality, it is useful from time to time to be able to run software you cannot completely trust such that the software cannot access all the data on the device (because the untrusted software cannot access your enclave).
- ndriscoll 11mo agoThat's why you run that software as its own untrusted user and perhaps run it with some kind of sandbox. It's not a reason for you the owner to not have root access at all.
- hollerith 11mo agoRunning each app as its own untrusted user is one of the measures taken by Android, but the designers of Android do not consider that enough, so they also sandbox the app with selinux, but no one has implemented sandboxing an app with selinux on any non-Android non-ChromeOS Linux distro. In general, non-Android non-ChromeOS Linux is not good at this sort of thing: half a dozen sandboxing frameworks exist, but none of them are particularly secure. Also, suppose you want to load an obscure kernel module that reads an obscure filesystem format. How do you sandbox the module?
- codedokode 11mo ago> In general, non-Android non-ChromeOS Linux is not good at this sort of thing: half a dozen sandboxing frameworks exist, but none of them are particularly secure. There are no frameworks that use secure enclave for this purpose either. It's purpose is copyright protection and preventing user from removing features like advertisement and telemetry, not making your system safer. > Also, suppose you want to load an obscure kernel module that reads an obscure filesystem format. How do you sandbox the module? You should use microkernels.
- hollerith 11mo agoIn the actual world with the actual options available, rejecting the technology of the secure enclave has significant opportunity costs. In a theoretical reality in which one of the options available to you and I is a secure-enclave-independent microkernel OS on which you can run a mainstream browser, then you might be right that secure enclaves are unnecessary.
- ndriscoll 11mo agoIn the actual world, secure enclave is used for DRM, setting user permissions and running untrusted code as another user gets you 80% of the security you need if you don't trust something, and running it in a mostly empty container gets you another 19%. Unless you have a habit of running dubious code that you grant network access and keep up to date to ensure it knows the latest exploits, practically speaking you're fine. Of course the obvious solution is don't run malware. Android's need for security partly comes from the fact that the primary repository/store distributes tons of dubious code that it grants network access and keeps up to date. If you stick to e.g. F-droid and turn off automatic updates, you don't find yourself in this adversarial position.
- embedding-shape 11mo ago> The purpose of secure enclave is to prevent administrator from accessing the data Not only, it has many purposes. I'm also the administrator of my computer, and some things I want to be unchangable by software, unless I myself unlock it, like I don't want anyone to be able to boot or install other OSes than the ones I've installed myself. The secure enclave and secure boot is perfect for this, even if my computer gets malware they won't be able to access it, and even if someone gets physical access to my computer, they won't be able to boot their OS from a USB.
- deleted 11mo ago[deleted]
- argomo 11mo agoAgreed. We need legally enforceable standards granting owners full control of their devices. But also: TPMs could be used to prevent evil maid attacks and to make it uneconomical for thieves who stole your device to also steal your data. It makes it possible for devices to remotely attest to their owners that the OS has not been compromised, which is relevant to enterprise IT environments. There are a lot of good uses for this technology, we just need to solve the political problems of aggressive copyright, TIVOization, etc.
- immibis 11mo agoBut I do want to secure my encryption keys on my device from someone who steals my device. Any feature controlled by the owner of the computer is good; features controlled by anyone else like the manufacturer can be bad. And note that in this viewpoint, leasing makes you temporary owner.
- bigmattystyles 11mo agoIt’s also where private keys for your device to secure your data live, so it’s like nuclear power, you can make a bomb or a clean power plant.
- beeflet 11mo agothe private keys to secure my data live in my brain
- AstralStorm 11mo agoNo, these should exist in the TPM and highly volatile memory like CPU cache. This including the decryption code. This can be achieved using mechanisms similar to what Coreboot does before RAM is initialized. No need for the keys or decryption to touch easily intercepted and rowhammered RAM.
- bigmattystyles 11mo agoYes, I think we’re saying the same thing. A TPM is a Secure Enclave.
- codedokode 11mo agoWhy the keys for my device should be not accessible for me? The purpose of secure enclave is to prevent administrator from accessing the data.
- foxyv 11mo agoA secure enclave should allow no one to access the data inside. It's essentially a little self contained computer that can do some basic crypto operations using the stored keys. It should never disclose the keys.
- CGMthrowaway 11mo agoWith the rise of "passkeys" that every single website is cramming down our throats now, aren't those also stored in the secure enclave? AKA the keys to your entire encrypted data and digitized life?
- axus 11mo agoI look forward to recordings of the scam calls, where they ask the victim to "place a small piece of hardware between a single physical memory chip and the motherboard slot it plugs into".
- vlovich123 11mo agoMore like buying old phones en masse to spelunk to find valuable account info.
- foxyv 11mo agoThey also store passkeys for logging into websites with biometrics and PIN.
- whatshisface 11mo agoSo do hard drives.
- foxyv 11mo agoYeah, you can implement a software based method using PBKDF2 or BCrypt. This is why most password managers use a "Master Password." They are much less convenient than hardware based keys like Yubikey and HSMs/Secure Enclave.
- codedokode 11mo agoSecure enclave is not an alternative for Yubikey because the program inside enclave cannot tell if the request comes from the user or from malware.
- foxyv 11mo agoMost secure enclaves use a fingerprint scanner to authenticate the request for data key or private certificate decryption. For instance, on the MacBook you will get a message prompting for fingerprint. On a Windows laptop without a fingerprint scanner it will prompt for a PIN.
- out_of_protocol 11mo agoNot your keys - not your computer
- ls612 11mo agoImagine this being voted down on hacker news.