Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1393543

Re: [PATCH 0/6] Intel Secure Guard Extensions

From Pavel Machek <pavel@ucw.cz>
Newsgroups linux.kernel
Subject Re: [PATCH 0/6] Intel Secure Guard Extensions
Date 2016-05-03 17:40 +0200
Message-ID <ruKAz-29Y-43@gated-at.bofh.it> (permalink)
References <rrSEj-1jR-33@gated-at.bofh.it> <rsgwV-4xy-5@gated-at.bofh.it> <rtn3j-3Ce-1@gated-at.bofh.it> <ruo70-61q-11@gated-at.bofh.it> <ruEOu-5yj-15@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Hi!

> We have been following and analyzing this technology since the first
> HASP paper was published detailing its development.  We have been

(1)

> 
> I told my associates the first time I reviewed this technology that
> SGX has the ability to be a bit of a Pandora's box and it seems to be
> following that course.

Can you elaborate on the Pandora's box? System administrator should be able to
disable SGX on the system, and use system to do anything that could be done with
the older CPUs, right?

> support data and application confidentiality and integrity in the face
> of an Iago threat environment, ie. a situation where a security

(2)

> Intel is obviously cognizant of the risk surrounding illicit uses of
> this technology since it clearly calls out that, by agreeing to have
> their key signed, a developer agrees to not implement nefarious or
> privacy invasive software.  Given the known issues that Certificate

Yeah, that's likely to work ... not :-(. "It is not spyware, it is just
collecting some anonymous statistics."

> domination and control.  They probably have enough on their hands with
> attempting to convert humanity to FPGA's and away from devices which
> are capable of maintaining a context of exection... :-)

Heh. FPGAs are not designed to replace CPUs anytime soon... And probably never.

> the Haven paper in which Microsoft Research discussed how SGX could be
> used to run unmodified Windows applications within an SGX TEE.

(3)

> I think Intel was somewhat sobered by the follow on paper in which
> Microsoft demonstrated that in an Iago environment an interloper was
> capable of determing with accuracy levels greater then 60% what was
> being done in an SGX TEE.  Matt Hoekstra was very quick to call out
> the need for the community to understand and develop side channel

(4)

> In the TL;DR department I would highly recommend that anyone
> interested in all of this read MIT's 170+ page review of the
> technology before jumping to any conclusions.... :-)

(5)

Would you have links for 1-5?

Thanks,
									Pavel
-- 
(english) http://www.livejournal.com/~pavelmachek
(cesky, pictures) http://atrey.karlin.mff.cuni.cz/~pavel/picture/horses/blog.html

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: [PATCH 0/6] Intel Secure Guard Extensions Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-04-29 22:20 +0200
  Re: [PATCH 0/6] Intel Secure Guard Extensions "Austin S. Hemmelgarn" <ahferroin7@gmail.com> - 2016-05-02 17:40 +0200
    Re: [PATCH 0/6] Intel Secure Guard Extensions "Dr. Greg Wettstein" <greg@enjellic.com> - 2016-05-03 11:30 +0200
      Re: [PATCH 0/6] Intel Secure Guard Extensions Pavel Machek <pavel@ucw.cz> - 2016-05-03 17:40 +0200
        Re: [PATCH 0/6] Intel Secure Guard Extensions "Dr. Greg Wettstein" <greg@enjellic.com> - 2016-05-04 11:10 +0200
          Re: [PATCH 0/6] Intel Secure Guard Extensions Pavel Machek <pavel@ucw.cz> - 2016-05-04 13:10 +0200
      Re: [PATCH 0/6] Intel Secure Guard Extensions Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-05-06 13:40 +0200
        Re: [PATCH 0/6] Intel Secure Guard Extensions Thomas Gleixner <tglx@linutronix.de> - 2016-05-06 14:00 +0200
          Re: [PATCH 0/6] Intel Secure Guard Extensions Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-05-09 07:40 +0200
            Re: [PATCH 0/6] Intel Secure Guard Extensions Thomas Gleixner <tglx@linutronix.de> - 2016-05-09 08:30 +0200
              Re: [PATCH 0/6] Intel Secure Guard Extensions Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-05-09 11:30 +0200
              Re: [PATCH 0/6] Intel Secure Guard Extensions "Dr. Greg Wettstein" <greg@enjellic.com> - 2016-05-12 11:00 +0200
            Re: [PATCH 0/6] Intel Secure Guard Extensions Greg KH <gregkh@linuxfoundation.org> - 2016-05-09 09:10 +0200
              Re: [PATCH 0/6] Intel Secure Guard Extensions Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-05-09 11:20 +0200
        Re: [PATCH 0/6] Intel Secure Guard Extensions "Dr. Greg Wettstein" <greg@enjellic.com> - 2016-05-08 12:00 +0200
          Re: [PATCH 0/6] Intel Secure Guard Extensions Andy Lutomirski <luto@amacapital.net> - 2016-05-09 03:40 +0200
    Re: [PATCH 0/6] Intel Secure Guard Extensions Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-05-06 01:00 +0200
      Re: [PATCH 0/6] Intel Secure Guard Extensions Pavel Machek <pavel@ucw.cz> - 2016-05-06 09:20 +0200
        Re: [PATCH 0/6] Intel Secure Guard Extensions Jarkko Sakkinen <jarkko.sakkinen@linux.intel.com> - 2016-05-06 13:30 +0200

csiph-web