Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Remote attestation poses a problem when working with proprietary network services. But you already have a problem in that case, the network service.

But when done sensibly and used in a system that's under the user's control (incl. that remote service), it's a security enhancing feature.

And people might not be as much in arms about it anymore because the landscape changed: The original Palladium proposal was made in an environment where the only threat model was "consumers 'steal' content".

Today, measured boot is also a legitimate security measure against criminal activity targetted at the user (eg boot kits, extortion ware), which didn't really enter the picture back then.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: