Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think the requirement here is that the owner of the user account needs to be able to register their own attestation keys. The owner of the account may be an employer or an end user.

It must not be a hardware manufacturer.



Yes, that I can support.


Note, this makes the system more secure, because the manufacturer is no longer a single point of failure, and a compromised key can be rotated by the account owner.


As long as the system is fully auditable and open source, I’d be happy. Having the keys be external is a big plus, assuming that is fully auditable as well. Having no “management engine” is a big plus too.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: