SGX: when 20 patch versions aren't enough
SGX: when 20 patch versions aren't enough
Posted Apr 24, 2019 1:01 UTC (Wed) by amarao (guest, #87073)Parent article: SGX: when 20 patch versions aren't enough
Posted Apr 24, 2019 6:39 UTC (Wed)
by smurf (subscriber, #17840)
[Link] (4 responses)
Posted Apr 24, 2019 9:45 UTC (Wed)
by grawity (subscriber, #80596)
[Link] (3 responses)
Um, but that was already the question: why is the entire enclave encrypted, as opposed to just the "data" pages being encrypted. "It's encrypted because it's encrypted" doesn't quite answer it. (The article notes that encryption is done at enclave startup time – the original code blob is merely signed, but not encrypted yet.)
Not that it would help much, if at all. You'd quickly find malware putting a bytecode interpreter in the "code" part, and all the interesting stuff being stored as "data".
Posted Apr 24, 2019 13:29 UTC (Wed)
by mageta (subscriber, #89696)
[Link]
In regards to the thought that the images are only signed, not encrypted: there is some thoughts on how attackers/drm-providers might load code into an enclave at run-time: http://theinvisiblethings.blogspot.com/2013/09/thoughts-o.... This way you can not inspect the code at all, even if you can inspect the original image/blob.
Posted Apr 24, 2019 14:34 UTC (Wed)
by smurf (subscriber, #17840)
[Link]
Posted Apr 24, 2019 16:57 UTC (Wed)
by flussence (guest, #85566)
[Link]
Posted Apr 24, 2019 17:01 UTC (Wed)
by luto (guest, #39314)
[Link]
Posted Apr 24, 2019 20:16 UTC (Wed)
by mm7323 (subscriber, #87386)
[Link]
SGX: when 20 patch versions aren't enough
SGX: when 20 patch versions aren't enough
SGX: when 20 patch versions aren't enough
SGX: when 20 patch versions aren't enough
SGX: when 20 patch versions aren't enough
SGX: when 20 patch versions aren't enough
SGX: when 20 patch versions aren't enough