In future versions once SGX is available (>= Intel Skylake)? Good luck extracting data from an encrypted enclave. This is, after all, the intended purpose[1] for SGX - to create the "trusted computing" (DRM) that Microsoft has wanted for the last decade[2]. It's not like these new instructions are for the end-user; Intel has to authorize[3] you binary before it can be loaded into an enclave.
Anybody using the CDM - even sandboxed - is helping to create that future. If this isn't fought and rejected now, yet another battle in the War On General Purpose Computers will be lost.
[1] https://software.intel.com/en-us/blogs/2013/09/26/protecting...
[2] "Palladium" / "Next-Generation Secure Computing Base" in the early 2000s
[3] https://jbeekman.nl/blog/2015/10/intel-has-full-control-over...
Why would they gimp their platform so hard? It's not like enabling arbitrary use of SGX prevents DRM from using it.
Wouldn't that make Intel liable for the actions of the binary? They would have to manage an application review process for any binary on any operating system, which sounds like an app store nightmare writ large. Not to mention revocation and repeating the entire process for security updates to software in the enclave. Could different governments require Intel to impose different blacklists on enclave software authors?
It's hard to see why they Intel would open themselves to such complex scenarios, unless it's a trial balloon that precedes a federated model or some other method of distributing key authority to multiple app stores and/or the hardware owner.
"This means that an attacker can easily ... use any kind of attack tool such as IDA Pro, debuggers, emulators, etc."
Attack tools?!
-Richard Stallman in The Right to Read http://www.gnu.org/philosophy/right-to-read.en.html