Security research on Private Cloud Compute
security.apple.com
Security research on Private Cloud Compute
1–10 of 124 posts
Re: Security research on Private Cloud Compute
#2Re: Security research on Private Cloud Compute
#3I hope you'll consider adding witness cosignatures on your transparency log though. :)
Re: Security research on Private Cloud Compute
#4Looks like they are really writing everything in Swift on the server side. Repo: https://github.com/apple/security-pcc
Re: Security research on Private Cloud Compute
#5Of course, this limits the potential attackers to 1) exactly one government (or N number of eyes) or 2) one company, but there's really no way that you can trust remote hardware.
This _does_ increase the trust that the VMs are safe from other attackers, but I guess this depends on your threat model.
Re: Security research on Private Cloud Compute
#6I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…
Re: Security research on Private Cloud Compute
#7I feel like this is all smoke and mirrors to redirect from the likelihood intentional silicon backdoors that are effectively undetectable. Without open silicon, there's no way to detect that -- say -- when registers r0-rN are set to values [A, ..., N] and a jump to address 0xCONSTANT occurs, additional access is granted to a monitor process. Of course, this limits the potential attackers to 1) exactly one government…
Re: Security research on Private Cloud Compute
#8Re: Security research on Private Cloud Compute
#9How is this different than a bug bounty?
Re: Security research on Private Cloud Compute
#10How is this different than a bug bounty?