Re: [friam] Mandatory backdoors was "Google Vault and capabilities"
Tony Arcieri <[email protected]> Sun, 31 May 2015 15:41:55 -0700
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAHOTMVK4o=VhNZVy+FCZ-0ZxrYC3XQoqhVq-jAQdwkc2tZNDcw@mail.gmail.com> |
I think putting more tools into the hands of defenders is a good thing. It remains to be seen if they're useful. SGX goes a long way in reducing the total footprint of trusted hardware down to the CPU itself and I think that's a good trajectory. On Sun, May 31, 2015 at 2:28 PM, Carl Hewitt <[email protected]> wrote: > Of course, SGX must support the legacy ;-) > > > > But the prospects for liberty will turn on the outcome of the security > services request for mandatory backdoors. > > > > Comments and suggestions appreciated on the penultimate draft attached to > this message. > > > > Thanks! > > Carl > > > > *From:* friam-/[email protected] [mailto:friam-/[email protected]] *On Behalf > Of *Norman Hardy > *Sent:* Saturday, May 30, 2015 21:23 > *To:* friam-/[email protected] > *Cc:* General discussions concerning capability systems. > *Subject:* Re: [friam] Google Vault and "capabilities" > > > > Keykos can run much legacy machine language code (compilers, X11) without > even recompiling. > > Intel’s SGX cannot. > > I suspect the CHERI can run gcc and quite a few other legacy apps with > replacement only of libc. > > We shall see. > > > > Keykos is designed to protect the interests of multiple stake holders on > one machine. > > SGX seems designed, as far as I can tell, to protect the interests of the > CPU manufacturer, system manufacturers and IP holders. > > Keykos, as implemented, trusts whoever has physical access to the system. > > > > On 2015 May 30, at 11:31 , Carl Hewitt <[email protected]> wrote: > > > > For better or worse our legacy is also our mainstream future ;-) > > > > The challenge is to add the following to the Intel and ARM architectures: > > · RAM-processor package encryption (SGX is a start) > > · Every-word-tagged architecture (as you mentioned, CHERI could be > adapted) > > > > > > > > -- > You received this message because you are subscribed to the Google Groups > "friam" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to friam+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/[email protected] > To post to this group, send email to friam-/JYPxA39Uh5TLH3MbocFF+G/[email protected] > Visit this group at http://groups.google.com/group/friam. > For more options, visit https://groups.google.com/d/optout. > > -- > You received this message because you are subscribed to the Google Groups > "friam" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to friam+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/[email protected] > To post to this group, send email to friam-/JYPxA39Uh5TLH3MbocFF+G/[email protected] > Visit this group at http://groups.google.com/group/friam. > For more options, visit https://groups.google.com/d/optout. > -- Tony Arcieri _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk