Re: [friam] Google Vault and "capabilities"
Ben Laurie <[email protected]> Sun, 31 May 2015 13:26:10 +0100
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CABrd9SQ=486zRV26PNrK6cvb5bhVL8B=h+XnNT9dvngQ6anQOw@mail.gmail.com> |
On 31 May 2015 at 05:22, Norman Hardy <norm-vN3M59HtaNxWk0Htik3J/[email protected]> wrote: > Keykos can run much legacy machine language code (compilers, X11) without > even recompiling. > Intel’s SGX cannot. > I suspect the CHERI can run gcc and quite a few other legacy apps with > replacement only of libc. > We shall see. > We have already seen :-) CHERI can indeed run legacy apps, without even recompiling. > > Keykos is designed to protect the interests of multiple stake holders on > one machine. > SGX seems designed, as far as I can tell, to protect the interests of the > CPU manufacturer, system manufacturers and IP holders. > Keykos, as implemented, trusts whoever has physical access to the system. > > On 2015 May 30, at 11:31 , Carl Hewitt <[email protected]> wrote: > > For better or worse our legacy is also our mainstream future ;-) > > The challenge is to add the following to the Intel and ARM architectures: > · RAM-processor package encryption (SGX is a start) > > It is not clear to me that this is a requirement. CHERI doesn't currently provide it, yet we provide pretty solid security. I haven't, so far, managed to convince myself that if you trust the hardware/OS you need it - and if you don't, I suspect you are screwed anyway. > · Every-word-tagged architecture (as you mentioned, CHERI could be > adapted) > > > > -- > You received this message because you are subscribed to the Google Groups > "friam" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to friam+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/[email protected] > To post to this group, send email to friam-/JYPxA39Uh5TLH3MbocFF+G/[email protected] > Visit this group at http://groups.google.com/group/friam. > For more options, visit https://groups.google.com/d/optout. > _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk