Conversation

Oh huh Signal has been compromised by The Woke, time to take a big sip of water and check out the politics of the original authors I guess

1
2
0
@mjg59 i don't care about this that much but i'd like if they fixed the privacy issue: https://social.kernel.org/notice/AhqRIM69n1KYN5p5hg. good times to promote this given the board changes...
1
0
1
@mjg59 also previous work exists where piggy packing CPU attestation into x.509 has been demonstrated. At least Enarx has this feature. So proof-of-concept done I guess.
1
0
0

Jarkko Sakkinen

Edited 1 year ago
@mjg59 Reported to https://support.signal.org/hc/en-us/requests/new. Not holding my breath, probably will be plain ignored...

Also "protecting from 3rd parties via SGX" does not hold in the case of Signal as they have their own data centers. Physical machine is already an enclave if you own it. Plain TPM2 would do.

So there's no actual scenario with SGX for Signal that make sense, plain and simple. Providing CPU attestation to client user would be such scenario, or if Signal was using 3rd party data centers. So it is provably only marketing that they use SGX, and has been that since 2017 when Moxie was around.

Fake marketing scam by definition.
0
0
0