4 ms·
From the paper: https://github.com/Layr-Labs/d-inference/blob/master/papers/dginf-private-inference.pdf https://github.com/Layr-Labs/d-inference/blob/master/pap
by btown 6mo ago
From the paper: https://github.com/Layr-Labs/d-inference/blob/master/papers/dginf-private-inference.pdf https://github.com/Layr-Labs/d-inference/blob/master/papers/...
> Apple’s attestation servers will
only generate the FreshnessCode for a genuine device that
checks in via APNs. A software-only adversary cannot
forge the MDA certificate chain (Assumption 3). Com-
bined with SIP enforcement (preventing binary replace-
ment) and Secure Boot (preventing bootloader tampering),
this provides strong evidence that the signing key resides
in genuine Apple hardware.
- saagarjha 6mo agoI am not entirely sure they understand that System Integrity Protection and Secure Boot can be turned off.
- deleted 6mo ago[deleted]
- btown 6mo agoMy understanding from the paper is that doing so should cause certain things in Apple's hardware security enclaves to break a signing chain, and a server-side MDM system integrated with Apple servers can detect this. But I'm not familiar with the underlying technology, so not sure if underlying assumptions are incorrect.
- saagarjha 6mo agoAFAIK that just ensures the SEP is present but perhaps they are signing the boot state now