Researchers use Intel SGX to put malware beyond the reach of antivirus software
arstechnica.com
arstechnica.com
Compare: if malware decides to use strong encryption, nothing else can decrypt it.
To me, this is how reliable protection mechanism (secure enclave, encryption) should work. It's either unbreakable by existing means by design, or mostly useless.
It's not the encryption library's work to decide if it encrypts for a good purpose or for a bad purpose. Same for SGX. Protection from malware should occur on a (much) higher level. Once certain code is admitted as legitimate by that higher level (e.g. an OS), the CPU should faithfully execute it, and it does.
Source? AFAIK programs running inside don't have kernel/DMA access.
Source: TFA
[1] https://github.com/digawp/hello-enclave
[1] https://software.intel.com/en-us/articles/sgx-intro-passing-...
edit:
looks like the article might be mistaken. According to an article on SGX internals[2], SGX code may only access enclave memory. A similar diagram can be found in a slide deck [3].
[2] https://blog.quarkslab.com/overview-of-intel-sgx-part-1-sgx-...
[3] http://cwfletcher.net/Content/598/lec04_sgx.pdf page 26
Sure you can stop it talking to the outside world, but you can't force it to give up the key.
In the cloud situation, the customer doesn't trust the cloud provider beyond just running his/her software (but inherently trusts him/herself). The cloud provider doesn't trust the customer to respect its isolation boundaries and must defend itself from SGX enclaves (and indeed all other client software) appropriately.
The largest consumer application of this is DRM - modern UHD Blu-Ray playback on a PC requires a fully SGX-enabled backend; the negotiation to obtain playback keys and the decryption of the on-disc content is done in the SGX enclave.
We've already seen the Sony rootkit fiasco, so it doesn't seem unfair to say one should not trust what DRM providers are doing. We should definitely not let their malicious garbage run in a secure onclave where you can't tell what it's doing as suggested by these researchers.