home.social

#confidentialcomputing — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #confidentialcomputing, aggregated by home.social.

  1. Physical security has become an important aspect of protecting confidential computing workloads. Physical access is typically excluded from hardware vendors' CVM attack models, leaving physical and relay attacks largely unaddressed.
    Flashbots and Intel have each been working independently on solutions to help bridge this physical-access gap: writings.flashbots.net/mind-th

    #ConfidentialComputing #CloudSecurity #TPM

  2. Physical security has become an important aspect of protecting confidential computing workloads. Physical access is typically excluded from hardware vendors' CVM attack models, leaving physical and relay attacks largely unaddressed.
    Flashbots and Intel have each been working independently on solutions to help bridge this physical-access gap: writings.flashbots.net/mind-th

    #ConfidentialComputing #CloudSecurity #TPM

  3. Physical security has become an important aspect of protecting confidential computing workloads. Physical access is typically excluded from hardware vendors' CVM attack models, leaving physical and relay attacks largely unaddressed.
    Flashbots and Intel have each been working independently on solutions to help bridge this physical-access gap: writings.flashbots.net/mind-th

    #ConfidentialComputing #CloudSecurity #TPM

  4. Physical security has become an important aspect of protecting confidential computing workloads. Physical access is typically excluded from hardware vendors' CVM attack models, leaving physical and relay attacks largely unaddressed.
    Flashbots and Intel have each been working independently on solutions to help bridge this physical-access gap: writings.flashbots.net/mind-th

    #ConfidentialComputing #CloudSecurity #TPM

  5. Physical security has become an important aspect of protecting confidential computing workloads. Physical access is typically excluded from hardware vendors' CVM attack models, leaving physical and relay attacks largely unaddressed.
    Flashbots and Intel have each been working independently on solutions to help bridge this physical-access gap: writings.flashbots.net/mind-th

    #ConfidentialComputing #CloudSecurity #TPM

  6. Reproducible builds are a valuable property for remote attestation workflows but often hard to maintain. We faced a special challenge building reproducible artifacts that contain signatures.

    Together with @Euler I wrote a blog post about how we used ECDSA public key recovery to generate signatures that match exactly one artifact, can be reproduced by a verifier, and are secure, without anyone ever knowing a private key.

    katexochen.aro.bz/posts/reprod

    #ReproducibleBuilds #RemoteAttestation #Cryptography #ConfidentialComputing #Infosec

  7. Reproducible builds are a valuable property for remote attestation workflows but often hard to maintain. We faced a special challenge building reproducible artifacts that contain signatures.

    Together with @Euler I wrote a blog post about how we used ECDSA public key recovery to generate signatures that match exactly one artifact, can be reproduced by a verifier, and are secure, without anyone ever knowing a private key.

    katexochen.aro.bz/posts/reprod

    #ReproducibleBuilds #RemoteAttestation #Cryptography #ConfidentialComputing #Infosec

  8. Reproducible builds are a valuable property for remote attestation workflows but often hard to maintain. We faced a special challenge building reproducible artifacts that contain signatures.

    Together with @Euler I wrote a blog post about how we used ECDSA public key recovery to generate signatures that match exactly one artifact, can be reproduced by a verifier, and are secure, without anyone ever knowing a private key.

    katexochen.aro.bz/posts/reprod

    #ReproducibleBuilds #RemoteAttestation #Cryptography #ConfidentialComputing #Infosec

  9. Reproducible builds are a valuable property for remote attestation workflows but often hard to maintain. We faced a special challenge building reproducible artifacts that contain signatures.

    Together with @Euler I wrote a blog post about how we used ECDSA public key recovery to generate signatures that match exactly one artifact, can be reproduced by a verifier, and are secure, without anyone ever knowing a private key.

    katexochen.aro.bz/posts/reprod

    #ReproducibleBuilds #RemoteAttestation #Cryptography #ConfidentialComputing #Infosec

  10. Reproducible builds are a valuable property for remote attestation workflows but often hard to maintain. We faced a special challenge building reproducible artifacts that contain signatures.

    Together with @Euler I wrote a blog post about how we used ECDSA public key recovery to generate signatures that match exactly one artifact, can be reproduced by a verifier, and are secure, without anyone ever knowing a private key.

    katexochen.aro.bz/posts/reprod

    #ReproducibleBuilds #RemoteAttestation #Cryptography #ConfidentialComputing #Infosec

  11. Ubuntu 26.04 Security Shift

    Ubuntu 26.04 LTS brings TPM-backed disk encryption, confidential computing, safer defaults, and more. Here is what matters most.

    beitmenotyou.online/ubuntu-26-

  12. Ubuntu 26.04 Security Shift

    Ubuntu 26.04 LTS brings TPM-backed disk encryption, confidential computing, safer defaults, and more. Here is what matters most.

    beitmenotyou.online/ubuntu-26-

  13. Cool, KVM-based AMD SEV-SNP support was recently added to Cloud Hypervisor! Including support for Google's oak stage0 firmware and IGVM image format.
    github.com/cloud-hypervisor/cl

    #ConfidentialComputing #virtualization #KVM #CloudHypervisor

  14. Cool, KVM-based AMD SEV-SNP support was recently added to Cloud Hypervisor! Including support for Google's oak stage0 firmware and IGVM image format.
    github.com/cloud-hypervisor/cl

    #ConfidentialComputing #virtualization #KVM #CloudHypervisor

  15. Cool, KVM-based AMD SEV-SNP support was recently added to Cloud Hypervisor! Including support for Google's oak stage0 firmware and IGVM image format.
    github.com/cloud-hypervisor/cl

    #ConfidentialComputing #virtualization #KVM #CloudHypervisor

  16. Cool, KVM-based AMD SEV-SNP support was recently added to Cloud Hypervisor! Including support for Google's oak stage0 firmware and IGVM image format.
    github.com/cloud-hypervisor/cl

    #ConfidentialComputing #virtualization #KVM #CloudHypervisor

  17. Cool, KVM-based AMD SEV-SNP support was recently added to Cloud Hypervisor! Including support for Google's oak stage0 firmware and IGVM image format.
    github.com/cloud-hypervisor/cl

    #ConfidentialComputing #virtualization #KVM #CloudHypervisor

  18. Fabricked, a new attack on AMD SEV-SNP presented: software-based attack that manipulates memory routing of inter-component communication within the SoC to trick the secure processor into improperly initializing the RPM table. The root cause is a missing check in the secure processor firmware to enforce the Data Fabric is locked down.

    fabricked-attack.github.io/

    #ConfidentialComputing #CloudSecurity #AMD

  19. Fabricked, a new attack on AMD SEV-SNP presented: software-based attack that manipulates memory routing of inter-component communication within the SoC to trick the secure processor into improperly initializing the RPM table. The root cause is a missing check in the secure processor firmware to enforce the Data Fabric is locked down.

    fabricked-attack.github.io/

    #ConfidentialComputing #CloudSecurity #AMD

  20. Fabricked, a new attack on AMD SEV-SNP presented: software-based attack that manipulates memory routing of inter-component communication within the SoC to trick the secure processor into improperly initializing the RPM table. The root cause is a missing check in the secure processor firmware to enforce the Data Fabric is locked down.

    fabricked-attack.github.io/

    #ConfidentialComputing #CloudSecurity #AMD

  21. Fabricked, a new attack on AMD SEV-SNP presented: software-based attack that manipulates memory routing of inter-component communication within the SoC to trick the secure processor into improperly initializing the RPM table. The root cause is a missing check in the secure processor firmware to enforce the Data Fabric is locked down.

    fabricked-attack.github.io/

    #ConfidentialComputing #CloudSecurity #AMD

  22. Fabricked, a new attack on AMD SEV-SNP presented: software-based attack that manipulates memory routing of inter-component communication within the SoC to trick the secure processor into improperly initializing the RPM table. The root cause is a missing check in the secure processor firmware to enforce the Data Fabric is locked down.

    fabricked-attack.github.io/

    #ConfidentialComputing #CloudSecurity #AMD

  23. RE: infosec.exchange/@trailofbits/

    Trail of Bits published a really interesting audit report on Meta's confidential computing protection for WhatsApp's AI support. One of the findings is an AML injection attack, which I wrote about in a blog post a few weeks ago: katexochen.aro.bz/posts/badaml/

    There are many other interesting findings, and a lot to learn from them. I really appreciate that they are sharing the full report.

    #ConfidentialComputing #CloudSecurity

  24. RE: infosec.exchange/@trailofbits/

    Trail of Bits published a really interesting audit report on Meta's confidential computing protection for WhatsApp's AI support. One of the findings is an AML injection attack, which I wrote about in a blog post a few weeks ago: katexochen.aro.bz/posts/badaml/

    There are many other interesting findings, and a lot to learn from them. I really appreciate that they are sharing the full report.

    #ConfidentialComputing #CloudSecurity

  25. RE: infosec.exchange/@trailofbits/

    Trail of Bits published a really interesting audit report on Meta's confidential computing protection for WhatsApp's AI support. One of the findings is an AML injection attack, which I wrote about in a blog post a few weeks ago: katexochen.aro.bz/posts/badaml/

    There are many other interesting findings, and a lot to learn from them. I really appreciate that they are sharing the full report.

    #ConfidentialComputing #CloudSecurity

  26. RE: infosec.exchange/@trailofbits/

    Trail of Bits published a really interesting audit report on Meta's confidential computing protection for WhatsApp's AI support. One of the findings is an AML injection attack, which I wrote about in a blog post a few weeks ago: katexochen.aro.bz/posts/badaml/

    There are many other interesting findings, and a lot to learn from them. I really appreciate that they are sharing the full report.

    #ConfidentialComputing #CloudSecurity

  27. RE: infosec.exchange/@trailofbits/

    Trail of Bits published a really interesting audit report on Meta's confidential computing protection for WhatsApp's AI support. One of the findings is an AML injection attack, which I wrote about in a blog post a few weeks ago: katexochen.aro.bz/posts/badaml/

    There are many other interesting findings, and a lot to learn from them. I really appreciate that they are sharing the full report.

    #ConfidentialComputing #CloudSecurity

  28. FYI: Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Anonym #DataPrivacy #ConfidentialComputing #Partnership

  29. FYI: Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Anonym #DataPrivacy #ConfidentialComputing #Partnership

  30. FYI: Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Anonym #DataPrivacy #ConfidentialComputing #Partnership

  31. RE: abyssdomain.expert/@filippo/11

    Trusted Execution Environments (TEEs) like Intel SGX and AMD SEV-SNP and in general hardware attestation are just f***d. All their keys and roots are not PQ and I heard of no progress in rolling out PQ ones, which at hardware speeds means we are forced to accept they might not make it

    #ConfidentialComputing #pqc

  32. RE: abyssdomain.expert/@filippo/11

    Trusted Execution Environments (TEEs) like Intel SGX and AMD SEV-SNP and in general hardware attestation are just f***d. All their keys and roots are not PQ and I heard of no progress in rolling out PQ ones, which at hardware speeds means we are forced to accept they might not make it

    #ConfidentialComputing #pqc

  33. RE: abyssdomain.expert/@filippo/11

    Trusted Execution Environments (TEEs) like Intel SGX and AMD SEV-SNP and in general hardware attestation are just f***d. All their keys and roots are not PQ and I heard of no progress in rolling out PQ ones, which at hardware speeds means we are forced to accept they might not make it

    #ConfidentialComputing #pqc

  34. RE: abyssdomain.expert/@filippo/11

    Trusted Execution Environments (TEEs) like Intel SGX and AMD SEV-SNP and in general hardware attestation are just f***d. All their keys and roots are not PQ and I heard of no progress in rolling out PQ ones, which at hardware speeds means we are forced to accept they might not make it

    #ConfidentialComputing #pqc

  35. RE: abyssdomain.expert/@filippo/11

    Trusted Execution Environments (TEEs) like Intel SGX and AMD SEV-SNP and in general hardware attestation are just f***d. All their keys and roots are not PQ and I heard of no progress in rolling out PQ ones, which at hardware speeds means we are forced to accept they might not make it

    #ConfidentialComputing #pqc

  36. ICYMI: Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Anonym #DataPrivacy #ConfidentialComputing #PrivacyFirst

  37. ICYMI: Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Anonym #DataPrivacy #ConfidentialComputing #PrivacyFirst

  38. ICYMI: Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Anonym #DataPrivacy #ConfidentialComputing #PrivacyFirst

  39. Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Privacy #DataProtection #Anonym #ConfidentialComputing

  40. Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Privacy #DataProtection #Anonym #ConfidentialComputing

  41. Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Privacy #DataProtection #Anonym #ConfidentialComputing

  42. Reddit and Anonym's data deal: no first-party data leaves, ever: Anonym and Reddit today announced a privacy-safe measurement partnership using confidential computing, marking Anonym's fourth major platform deal in under a year. ppc.land/reddit-and-anonyms-da #Reddit #Privacy #DataProtection #Anonym #ConfidentialComputing