Re: [friam] Mandatory backdoors was "Google Vault and capabilities"

Tony Arcieri <[email protected]> Sun, 31 May 2015 15:41:55 -0700
Newsgroups gmane.comp.capabilities.general
Message-ID <CAHOTMVK4o=VhNZVy+FCZ-0ZxrYC3XQoqhVq-jAQdwkc2tZNDcw@mail.gmail.com>
I think putting more tools into the hands of defenders is a good thing. It
remains to be seen if they're useful.

SGX goes a long way in reducing the total footprint of trusted hardware
down to the CPU itself and I think that's a good trajectory.

On Sun, May 31, 2015 at 2:28 PM, Carl Hewitt <[email protected]> wrote:

>  Of course, SGX must support the legacy ;-)
>
>
>
> But the prospects for liberty will turn on the outcome of the security
> services request for mandatory backdoors.
>
>
>
> Comments and suggestions appreciated on the penultimate draft attached to
> this message.
>
>
>
> Thanks!
>
> Carl
>
>
>
> *From:* friam-/[email protected] [mailto:friam-/[email protected]] *On Behalf
> Of *Norman Hardy
> *Sent:* Saturday, May 30, 2015 21:23
> *To:* friam-/[email protected]
> *Cc:* General discussions concerning capability systems.
> *Subject:* Re: [friam] Google Vault and "capabilities"
>
>
>
> Keykos can run much legacy machine language code (compilers, X11) without
> even recompiling.
>
> Intel’s SGX cannot.
>
> I suspect the CHERI can run gcc and quite a few other legacy apps with
> replacement only of libc.
>
> We shall see.
>
>
>
> Keykos is designed to protect the interests of multiple stake holders on
> one machine.
>
> SGX seems designed, as far as I can tell, to protect the interests of the
> CPU manufacturer, system manufacturers and IP holders.
>
> Keykos, as implemented, trusts whoever has physical access to the system.
>
>
>
> On 2015 May 30, at 11:31 , Carl Hewitt <[email protected]> wrote:
>
>
>
>   For better or worse our legacy is also our mainstream future ;-)
>
>
>
> The challenge is to add the following to the Intel and ARM architectures:
>
> ·       RAM-processor package encryption (SGX is a start)
>
> ·       Every-word-tagged architecture (as you mentioned, CHERI could be
> adapted)
>
>
>
>
>
>
>
> --
> You received this message because you are subscribed to the Google Groups
> "friam" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to friam+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/[email protected]
> To post to this group, send email to friam-/JYPxA39Uh5TLH3MbocFF+G/[email protected]
> Visit this group at http://groups.google.com/group/friam.
> For more options, visit https://groups.google.com/d/optout.
>
> --
> You received this message because you are subscribed to the Google Groups
> "friam" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to friam+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/[email protected]
> To post to this group, send email to friam-/JYPxA39Uh5TLH3MbocFF+G/[email protected]
> Visit this group at http://groups.google.com/group/friam.
> For more options, visit https://groups.google.com/d/optout.
>



-- 
Tony Arcieri

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk