Intel SGX Fuse Key0, a.k.a. Root Provisioning Key Was Extracted by Researchers
twitter.com
twitter.com
Intel already angered tons of enthusiasts who have no use for SGX by releasing a microcode update to lock out undervolting, due to that one exploit that relied on undervolting. Now everyone suffers from increased heat and power usage to protect against something they never needed protection from.
Why?
And wasn't sgx removed from newer cpus anyways? At least in desktop/mobile space...
because undervolting usually results in lower power draw/higher power efficiency
Intel, 1999: “The actual user of the PC — someone who can do anything they want — is the enemy.”
https://www.zdnet.com/article/the-biggest-security-threat-yo...
> Aucsmith said that more and more, software companies and content creators are targeting users as a major threat to security. The reason? With a few keystrokes, users could freely distribute "bits that have value," said Aucsmith -- copying such content as software, DVD video and other valuable data.
Ugh.
And that's not security. Nobody is compromised when someone copies those bits.
if one key gets you all chips, then someone is going to get that because the payout is total dominion. I've seen this trade off in similar protocols, and every time it's like "thanks for the advice, we're going to go with just the one, it's easier." There is one OEM/protocol I suspect actually uses diversified batch keys as their root provisioning secret, and really it's the way to go if you do business globally now.
What's more interesting is what the consequences will be, as if there are none (it's not like the stock will hurt) then the market is saying crypto can be sabotaged with impunity.
Doing so should blow away the disk keys, etc.
I’ve always assumed systems that relied on a key and didn’t support that were backdoored.
seems like apple, since it’s actually an important factor to them and not just to third parties?
I freqently think that my parents best parenting choice was the choice to not have a TV in our house when I was growing up. It both saved them money but removed a very common time wasting/entertainment outlet. My own kids went from playing with legos, creating art, or messing with science kits to playing on their phones as soon as they were given that choice. And i'm still of the opinion that providing that choice was a big mistake, they are experts on the latest social media fad, and quite ignorant about things I wish they would have learned.
So, yes enviroment matters, some kids will hack even when given an xbox and a pile of games, but I think more of them will try it if they aren't given those choices.
And it's not just math. Most of the education is reading the book and then reciting the book at an exam. Nothing else. No original thinking required. Just dumb information retrieval. It's humiliating, really.
But maybe the actual teaching is better than in other countries. I don't know. It's the testing that traumatized me.
Google revokes attestation keys for Android hardware a lot, especially Widevine Level 1 keys.
Ten years into that, the public doesn't seem very excised about it.
It’s unclear if Intel has enough fuses to push a new key and if there is a mechanism to do it in software without a specialized programming station.
If the latter two are possible and they can fix the leak vector with a ucode update then they can likely revoke the key and patch this over.
Now I'm curious, thouyh: Have there really never been any software Blu-ray players supporting AMD?
37C3 - Full AACSess: Exposing and Exploiting AACSv2 Uhd Drm for Your Viewing Pleasure https://www.youtube.com/watch?v=SEBuiecLZGg
If anyone (including Signal) can pretend to be a secure SGX environment, you're back to trusting Signal's personnel/operations, rather than Intel/SGX, for some of the metadata/contact privacy they've historically touted.
More info (2020): https://medium.com/@maniacbolts/signal-increases-their-relia...
compromising SGX wouldn't suddenly open up all of these transactions to exploitation though, since the attacker would need (presumably root) access to the machine and the keys could always be rolled.
I'm no expert but I suspect it would mean urgent firmware updates for anyone relying on SGX
Yes, features like this can be used by corporations to enforce DRM and ensure that you aren't running unapproved or modified versions of their code. However, this works both ways, because it can also be used by customers to make sure that corporations are actually running the code they're claiming to be running, and that's pretty useful.
Signal is a prominent example of this. There is no way to securely implement a way to find people by their phone number without a solution like SGX. You can either remove the feature completely, making your app hard to use and making users more likely to choose closed-source solutions, or you can implement it insecurely, becoming susceptible to hackers and law enforcement actions. With SGX, users can just verify that the code you're running does not, in fact, send all their data to the NSA behind their backs.
Has any company beyond Signal ever done this? Ever?
Probably enough to be genuinely hard for an APT to backdoor even with insider help. Still, ultimately the security relies on Apple hardware signed with Apple keys.
I'm genuinely unclear. How exactly does a user accomplish this? What role does SGX play in this?
That's what SGX does, it lets remote systems provide a cryptographic proof that they are running certain code. Including the ability to have a private key protected by the SGX, so you can public key encrypt your data, send it to the remote server, and know that only the code they've already published is processing your data.
If it modified the application to make it log or leak your data somehow, it could no longer pass that attestation step.
This should work as long as there is no hardware or side channel attack that lets the service operator (or someone it rents hardware from) defeat the SGX security guarantees, as long as there's no backdoor in the enclave implementation, and as long as the signing keys are not leaked or extracted, and are only used in accordance with the published policies.
This is a big claim which needs extraordinary proof if we're going to rely on that assumption for security. Remember, we're talking about an organization that did things like sneak in backdoors in encryption standards or infiltrate Google's internal network to passively extract user data en masse. We should just assume the NSA has gotten the keys from Intel a long time ago, voluntarily or not.
The NSA doesn't respect the rules. Nor do they think about the wider consequences of their actions. They're a reckless and irresponsible organization with an enormous budget. If they want something from Intel, they will have it.
Even if signal used an enclave key to encrypt the local chat database, sgx doesn’t protect the enclave from the keyboard, mouse or display drivers, so someone could simply write a screen scraper that displayed and captured each message of each thread.
The server however is inherently untrusted, and the users of the server can benefit from some form of attestation of the software it's running. SGX tries to provide this, as the siblings in this thread explain.
This still requires trusting Intel.
You should assume that Signal engineers, if they chose to, could access the user data protected by SGX, just like they could log metadata about your message sending and receiving patterns. You only have their word that they don't. The NSA could certainly bypass the SGX given access to the server.
I suppose there may be some legal benefit in putting the data "out of reach" - it would be hard to prove in court that you were capable of leveraging an exploit towards SGX to provide the requested data. But NSA/others will happily take possession of the hardware and do it themselves.