If we could "prove" security, we would. Proving security in a networked environment? Hahaha - there have been successful attacks on airgapped envs.
If we could "prove" security, we would. Proving security in a networked environment? Hahaha - there have been successful attacks on airgapped envs.
Apple goes further than standard end-to-end encryption messaging by adding a software attestation component to the hand shake. And they say they will publish the server side software for researchers to poke at. And there is a certificate security style log so you can be sure that the server side software is published.
I’m not saying the system is good or works, I’m just saying don’t totally discount the idea of designing a system that has provable security properties.
https://securityintelligence.com/news/apple-m-series-chips-h...
Everything Apple's done yields verifiable security - but it's not "provably secure". The two are distinct, and when you try to sell to me with bad language I get squinty-eyed. Especially since "confidential computing" already exists on x86/AWS, and I struggle to see the difference. It just sounds like Apple marketing to me.
> don’t totally discount the idea of designing a system that has provable security properties
They're only as provable as your assumptions/givens. Given a hardware vuln, where is your security now?