confidential-computing / confidentialcomputing.io

A place to track website changes.
5 stars 1 forks source link

FAQ answer should be not be single-vendor-specific #11

Open dthaler opened 4 years ago

dthaler commented 4 years ago

https://confidentialcomputing.io/faq/ has the question "Can this technology/confidential computing be used for nefarious purposes? How will the CCC protect against this?"

But the answer calls out Intel in particular with "There are research experiments that have been probing Intel-based enclave technologies". This should be replaced by language that is not Intel specific, as there have also been experiments probing other TEE technologies (e.g., here and here).

In addition, the FAQ answer doesn't really address the core question of ways TEEs might be misused, such as are suggested here and here. That is, can a TEE be used to hide malware from virus scanners. The answer is basically that the "authenticated launch" property mentioned in the whitepaper-in-progress would prevent such misuse.