I am curious about a couple of things:
Assuming you use Intel chips, how do you manage to trust the firmware/ME from them? Do you write your own BIOS to ensure that it is safe? Or do you use ARM/PowerPC/other ISA and have an entirely open source stack?
Does the Titan assume no phyiscal access? And if you do assume someone could steal the chip/try to reverse engineer the chip, do you have anything in it to stop an adversery? I would wonder if there would be a private/nation state agency would want access to certain secrets so bad that they would try to alter it physically, rather then through root access.
Edit: See [0] where Titan was first briefly introduced earlier this year, for an image of it attached to one of our custom networking cards.
[0] https://www.blog.google/topics/google-cloud/bolstering-secur...
https://twitter.com/jbeda/status/715373975182807040
Will you convince Niels to publish a paper?
re: Niels paper, out of my control.
Can I serve a different firmware image after the verification goes through and the PCH starts loading the flash? :)
your name reminds to IBM. Is Titan your internal weapon against the NSA?