Cipherleaks is the first demonstrated attack against AMD SEV-SNP (2021)
cipherleaks.com
cipherleaks.com
1) Clouds (you mostly trust the provider, but maybe not fully. And you want to make sure they don’t have anything up their sleeves. Consider the FBI vs Apple encryption dispute)
2) Intra-corporation stuff as a mitigation against hacked users, malicious insiders, and malware (think crypto oracles for terminating SSL, requiring bootchain attestation before giving corporate credentials)
3) The more icky category: Places where you distrust your own customer (DRM, and probably eventually, game anticheat)
The userspace code being more privileged than kernel code has never really been true. Maybe arguably true for SGX, but even then, all you get is the ability to prove you were initialized in the “right” way. All the other TEEs have a kernel mode component (they are typically ways of running attestable VMs).
Let's imagine a worst case scenario, where thousands of highly skilled hours are put into building common infrastructure ("barn raising") among capable people with implied social promises but not cash, and then a second wave ("cattle ranchers") comes in and starts collecting money for CVEs and pushing out any claims for compensation by authors..
this scenario is playing out in the EU (CRA laws) or de-facto in the USA (VC startups) right now.. with the monetization of CVEs , but foot-dragging and long speeches for compensation of OSS engineering. make sense?
Vanity is just another explanation, and the hope that the CVE gets "famous" like heartbleed or spectre or meltdown.
Source: I'm the owner of 3 domains (not security related fwiw) but zero businesses.