Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> the kernel can read all memory

That's great, iff you have root-level access.

> I don’t even see how a future MKTME v2 would be useful for DRM.

Intel already tried that with SGX. (Intel's documentation for SGX was all about creating a "Trusted Computing" environment, using the old Palladium/NGSCB DRM-sense of "trusted".



> That's great, iff you have root-level access.

And if you don’t have root access, then you can’t read other users’ memory. The MMU must be an evil scheme for DRM!


The difference is that SGX was explicitly designed to protect memory/execution from kernel access, and TME doesn’t have such a facility or any path I can see towards becoming one.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: