PrivateCore demonstrates industry's first PRISM-proof Tor server in public cloud
reuters.com
reuters.com
there is no information about how this tech actually accomplishes this on their site. i suspect it's "stuff everything in the TPM because you can trust hw crypto" from normal memory, but this is just a guess. i would expect that the hw assurance claim is tied to storing id info in the TPM as well.
Seem like something that can be usefull for android devices, since the main vulnerability of android devices is the ability if chips(like the modem) that have closed source firmware , to access the ram.
[1]http://en.wikipedia.org/wiki/TRESOR#Potential_vulnerabilitie...
> Using PrivateCore vCage, no trace of Tor server code or data is maintained in memory or on disk, eliminating the possible exposure of secret key material through memory forensics.
This isn't at all what the NSA's attacks on Tor are, but uh, good for them, I suppose.
If Amazon or Rackspace got an NSL, would the NSA be able to get an image of your VPS without you being told?
It seems relevant.
Open source doesn't automatically guarantee anything, but you can't have real security without it.