Earlier quoted context omitted.
>It'll be built into the CPU, instead of having a separate chip so are the trusted execution environments used by fTPMs? >seems to have secret-management functionality for user-specified keys AFAIK TPMs already have that functionality. random search: https://github.com/tpm2-software/tpm2-tools/blob/master/man/... >biometrics, etc. AFAIK some fingerprint readers already use trusted execution environments to handle aut…
The huge difference, and most tin-foil-hat worthy , is that all this functionality is extended to reach the cloud . What's frightening is that - by design - the user will have little/no control or even awareness of what data is being sent or received.
Which means the OS still have full control over what it does send but the "thing" can attest that what the OS sends is valid and not made up.