← Back to KHAO

Intel · Meta · AMD ·

Confidential computing's core trust mechanism is broken

2 min read

Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.

◌ Single Source

Man sits at a desk in a wood-paneled office cubicle, holding his head near a monitor.

Attested TLS: the handshake that can't prove who's on the other end.

Key facts

Summary

Vendors are trying to position "confidential computing" as the technical backbone of Europe's sovereign cloud ambitions. Confidential computing rests on a mechanism called remote attestation, in which a server cryptographically proves to a client that it is running inside a genuine, unmodified Trusted Execution Environment (TEE) before any sensitive data changes hands. In May, The Register reported that the chip beneath the chip, the management engines running below the operating system on Intel and AMD silicon, falls outside what European sovereignty frameworks like SecNumCloud assess. New, independently verified research answers it, and the answer is not reassuring. Muhammad Usama Sardar, a researcher at TU Dresden, has spent the past two years formally verifying whether that protocol, known as attested TLS, does what it claims.

Read full article at The Register →

#Intel #Meta #European Union #AMD