Re: [friam] Google Vault and "capabilities"

Ben Laurie <[email protected]> Sun, 31 May 2015 13:26:10 +0100
Newsgroups gmane.comp.capabilities.general
Message-ID <CABrd9SQ=486zRV26PNrK6cvb5bhVL8B=h+XnNT9dvngQ6anQOw@mail.gmail.com>
On 31 May 2015 at 05:22, Norman Hardy <norm-vN3M59HtaNxWk0Htik3J/[email protected]> wrote:

> Keykos can run much legacy machine language code (compilers, X11) without
> even recompiling.
> Intel’s SGX cannot.
> I suspect the CHERI can run gcc and quite a few other legacy apps with
> replacement only of libc.
> We shall see.
>

We have already seen :-)

CHERI can indeed run legacy apps, without even recompiling.


>
> Keykos is designed to protect the interests of multiple stake holders on
> one machine.
> SGX seems designed, as far as I can tell, to protect the interests of the
> CPU manufacturer, system manufacturers and IP holders.
> Keykos, as implemented, trusts whoever has physical access to the system.
>
> On 2015 May 30, at 11:31 , Carl Hewitt <[email protected]> wrote:
>
> For better or worse our legacy is also our mainstream future ;-)
>
> The challenge is to add the following to the Intel and ARM architectures:
> ·       RAM-processor package encryption (SGX is a start)
>
>
It is not clear to me that this is a requirement. CHERI doesn't currently
provide it, yet we provide pretty solid security. I haven't, so far,
managed to convince myself that if you trust the hardware/OS you need it -
and if you don't, I suspect you are screwed anyway.


> ·       Every-word-tagged architecture (as you mentioned, CHERI could be
> adapted)
>
>
>
>  --
> You received this message because you are subscribed to the Google Groups
> "friam" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to friam+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/[email protected]
> To post to this group, send email to friam-/JYPxA39Uh5TLH3MbocFF+G/[email protected]
> Visit this group at http://groups.google.com/group/friam.
> For more options, visit https://groups.google.com/d/optout.
>

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk