Conversation

1/3 Thankyou I entirely agree. "My major issue with SVR is that it’s something I basically don’t want, and don’t trust." Yep. And thanks for telling me I can at least generate a high-entropy password instead of a PIN - that is not at all obvious from the UI.
Quote Tweet
I wrote a post about why Signal’s “Secure Value Recovery” backup system (and decision to force users to choose PIN codes) has made me so concerned. blog.cryptographyengineering.com/2020/07/10/a-f
Show this thread
5
24
Thanks for the careful and clear explanations! One thing I am curious about: if the threat model is "SGX gets pwned", how does this compare to the threat model of "your phone gets pwned by a Spectre-like attack"?
1
2
A leaked key from any SGX implementation or from an Intel employee is enough to bypass the feature. They aren't just relying on the security of SGX but also an attestation system based on a root of trust. SGX also isn't a proper secure element. It's not isolated from the CPU.
1
1