NewsLab
Aug 28 17:52 UTC

Compromising Signal's Contact Discovery Enclave (SGX) (v12.sh)

12 points|by RobLach||4 comments|Read full story on v12.sh

Comments (4)

4 shown
  1. 1. chews||context
    SGX has NEVER been secure... trusted execution can only come from open design chips like RiskV paired with an HSM. Intel has too many reasons to give intel to the NSA... They technically are 10% owners under America's deal, I mean dear leader.
  2. 2. wtallis||context
    Is this or any other SGX exploit a consequence of Intel processors not being open source?
  3. 3. rekttrader||context
    At least the open alternatives can be fuzzed, intel minix and intel ME are other examples of NSA exploitware
  4. 4. ezst||context
    I might add (although it's getting off topic) that a centralised service, by definition brokering every single user's comms and metadata is NEVER private. The whole premise of Signal as a secure/private solution always seemed silly, the SGX indirection is theater.