EnclaveDB: A secure database using SGX
blog.acolyer.org
blog.acolyer.org
https://www.theregister.co.uk/2017/09/27/signal_turns_to_int...
One of my favourite takeaways is that we don’t always have to think of performance and security as trade-offs
...but security and freedom always are.
Based on some posts from Andy Lutomirski on LKML, it seems highly unlikely that any SGX support will go upstream in Linux until Flexible Launch Control is available in consumer SKUs, at least.[1] In fact, I looked up the latest patches posted just a few days ago, which "Removed in-kernel LE i.e. this version of the SGX software stack only supports unlocked IA32_SGXLEPUBKEYHASHx MSRs."[2]
"SGXv2" with FLC is allegedly available in some SKUs right now (based on some googling[3]), but Intel hasn't been very forthcoming on exactly which ones those are, or even what the major differences between v2 and v1 are, besides FLC...
[1] https://lkml.org/lkml/2017/3/8/605
[2] https://lore.kernel.org/lkml/20180703182118.15024-1-jarkko.s...
This could have been solved if the "computer purchaser" == "computer owner". Instead, you buy hardware but Intel and who else the fuck other owns the rights to functionality.
I went with AMD for my recent computer. The TPM is a separate module that you have to purchase and slot on the motherboard. I didn't get one.
But you can also just ignore a TPM anyway, there's nothing mandating you use it, even if it's there. SGX is somewhat similar, since some cooperation is needed by the operating system to launch enclaves anyway (AFAIU), even if the enclaves are intel-signed, and the user has to authorize that (unless just random unprivileged users can install enclaves willy-nilly, but that seems like a bad idea).
SGX doesn't really seem to add much to any realistic threat model where "Intel is your enemy", given that threat model presumably already includes the Management engine (or AMD PSP) anyway, if it was really your worry. So you were already getting screwed long before this, really -- in such a scenario, they were able to launch undetectable code long before this.
SGX-enabled boot-based malware seems like a much more problematic case that's possible, but given how effective the most basic Ransomware, etc seems to be already without these features, I'm not sure most malware authors need significantly more advanced techniques than this. You're probably screwed anyway.
WTF