Compromising Signal's Contact Discovery Enclave (SGX)

12 points
1/21/1970
a day ago
by RobLach

Comments


chews

SGX has NEVER been secure... trusted execution can only come from open design chips like RiskV paired with an HSM. Intel has too many reasons to give intel to the NSA... They technically are 10% owners under America's deal, I mean dear leader.

a day ago

wtallis

Is this or any other SGX exploit a consequence of Intel processors not being open source?

a day ago

rekttrader

At least the open alternatives can be fuzzed, intel minix and intel ME are other examples of NSA exploitware

a day ago

ezst

I might add (although it's getting off topic) that a centralised service, by definition brokering every single user's comms and metadata is NEVER private. The whole premise of Signal as a secure/private solution always seemed silly, the SGX indirection is theater.

a day ago