So with AMDs SEV (and I'm guessing similar systems) what's the interface by which a customer will get that information?
What I'm interested in is, is there not a CSP controlled API between the literal hardware and the CSP customer, that might be subject to attack?