Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
costan
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
costan
11y ago
Thank you very much for this feedback! Re: 1 - I re-read the relevant SDM sections, and saw that there is no requirement that the new upgrade version exceeds the current microcode version. Thank you very much for pointing that out! The next
2.
▲
by
costan
11y ago
SGX serves a good purpose, at least in theory. Many people, myself included, wanted it to turn out to be good. So, I don't think many Intel folks objected to it. Instead, I think that a bunch of MBAs showed up and decided SGX is securi
3.
▲
by
costan
11y ago
But enclaves are worthless without attestation. If the OS is evil and you don't do attestation, it can emulate SGX and run your code in a simulated enclave environment where EGETKEY returns keys that the OS knows about. If the OS is no
4.
▲
by
costan
11y ago
Do you happen to know if the Launch Enclave has the debug flag set? If so, you can't use it to launch production enclaves.
5.
▲
by
costan
11y ago
There's some support in Intel's Management Engine for DRM, called Intel Insider (the successor of PAVP). One of the SGX papers mentions plans for hooking up SGX enclaves with PAVP. Based on public docs, you can't do DRM decod
6.
▲
by
costan
11y ago
TXT requires an ACM, which is essentially a small signed BIOS subset. At least ACMs are freely downloadable from Intel, and they don't look into what you'd like to run under TXT. https://software.intel.com/en-us&#x
7.
▲
by
costan
11y ago
It gives Intel control over developers. In general, a computer will execute what you ask it to. SGX will not let you run production enclaves without Intel's permission. This is like Verified Boot, except there's no credible securi
8.
▲
by
costan
11y ago
Sadly, leaking the key is not the answer. You'd give independent developers the freedom to use SGX, but at the same you'd make SGX worthless. Details: if the key used to sign architectural enclaves (like the Launch Enclave) would
9.
▲
by
costan
11y ago
I expect this to play out like the W3C EME standard. Software attestation separates debug from non-debug enclaves, so your kernel will need to load production enclaves for you to watch Netflix. If Mozilla/Firefox caved, so will Linux.
10.
▲
by
costan
11y ago
Perhaps it means they're trying to be thorough? A Xeon implementation would have to secure the QPI links between the CPU chips. These run at significantly higher speeds than DRAM, so the current MEE design would likely not be able to k
11.
▲
by
costan
11y ago
I'm terrible at writing. I am trying to say that SGX cannot restore things from the SSA, and it has to use some protected area. To the best of my knowledge, they're using the non-architectural area of the TCS, which is protected f
12.
▲
by
costan
11y ago
If SGX becomes successful, Intel becomes the Verizon+ATT+Tmobile+Sprint of hardware security. No signed enclave, no security.
13.
▲
Iterating on Mobile Apps at Web Speed
(pwnall.github.io)
1 points
by
costan
12y ago
|
0 comments
14.
▲
by
costan
14y ago
Thanks! Platform for 6.470 day 1? (html / css / js)
15.
▲
by
costan
14y ago
I can't promise anything, but I can assure you that we're well-aware of the pains of the current authentication model.
16.
▲
Dropbox.js - official support for JavaScript Dropbox apps
(tech.dropbox.com)
14 points
by
costan
14y ago
|
4 comments
17.
▲
by
costan
15y ago
Did you try using Prey? Do you know when and how is the GPS used?
18.
▲
by
costan
15y ago
Flashed the Insyde BIOS using http://hexxeh.net/?p=328117655 and got Ubuntu 11.04 at it, when it was just an alpha. Filing bugs since. Will switch to the 11.10 dev version when the first alpha is out. I always liked to test the developmen
19.
▲
by
costan
16y ago
I wouldn't expect performance to be a problem. For computational tasks, Ruby works just as fine on Windows as on a UNIX platform. Windows perf suffers because (1) in some rare cases, the needed primitives aren't provided by the kernel, and
20.
▲
by
costan
16y ago
Censorship is horrible. But if you think it's restricted to China... think about what would happen if 10,000 people would tweet something sensitive on 9/11. My guess is something along the lines of http://www.huffingtonpost.com/2010/05/10/
21.
▲
by
costan
16y ago
Spam-following people on twitter to promote your app: bad idea. I reported you as a spammer.
22.
▲
by
costan
16y ago
I like the nice succinct description of claims. Thanks!
23.
▲
by
costan
17y ago
Zipped source code: http://6.470.scripts.mit.edu/lectures/security/security_in_w... Live source code: http://github.com/costan/security_in_webapps_slides
24.
▲
[S5 Slides] Security in Web Applications
(6.470.scripts.mit.edu)
16 points
by
costan
17y ago
|
3 comments
25.
▲
Building fat iPhone static libraries (device + simulator in one file)
(blog.costan.us)
1 points
by
costan
17y ago
|
0 comments
26.
▲
by
costan
17y ago
Good overview of the issues you'll need to deal with: (read the paper, not so much the class notes) http://pdos.csail.mit.edu/6.893/2009/schedule.html
27.
▲
by
costan
17y ago
Thank you for the recommendations! I didn't know about the Cputech product. Your intuition was right, they are too expensive for me. So, I should clarify: I am happy with using current-generation smart-card chips, but I would like to use th
28.
▲
Ask HN: any SDKs for embedded secure processors?
2 points
by
costan
17y ago
|
3 comments
29.
▲
by
costan
17y ago
Same here. 4-5 people, at most 3 / project.
30.
▲
by
costan
17y ago
Hm, I just saw this question, sorry. I should definitely clarify. I witnessed NO racism or xenophobia at Apple. I was treated very well throughout my internship. To the best of my knowledge (2006), Apple does H1 visas, but they don't sponso
More ›