5 ms·
> was limited to verified devices in custody by trusted actors. Like a security camera with a tamper evident enclosure, or an organisation being able to attest
by hypfer 2mo ago
> was limited to verified devices in custody by trusted actors. Like a security camera with a tamper evident enclosure, or an organisation being able to attest that they recorded the imagery.
But that is also not the case, because whatever keys are in those devices may have been duplicated in the factory or somewhere along the supply chain.
Or the stuff is cloud connected and an exploit can be executed via that.
Or, as written in the blog post you're commenting on, software exploits.
The whole idea is that the concept works for no one.
- TOMDM 2mo agoWell, you can say the same thing about HSMs, or the CPU in your device. If there's no trust afforded to the device holder, or it's manufacturer, there's no trust in anything. Always to degrees, and never fully, but trust can still be had.