Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, because that way a rogue kernel could overwrite the exclave itself and the next reboot would be insecure. You can’t trust a low-trust environment to update a high-trust environment.


Is that why everything is cryptographically secured in the boot chain? To ensure only trusted code is loaded?


Exactly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: