Conversation

Jarkko Sakkinen

I'm re-formalizing my question because I could wrong too

Using any formation of #Signal App, is it possible to get #SGX #attestation of contact discovery back to the client and view the certificate, or how does it benefit the end user?

Or is from client possible to get this attestation using the raw protocol that the app uses?
0
0
0

@cherti I don’t know, that’s why I’m asking.

In order to attest correctly it should:

  1. Get CPU attestation packed into certificate periodically from the service.
  2. Compare this certificate against Intel CA.

Please show where these steps are done because I’m interested…

0
0
0

Jarkko Sakkinen

Edited 5 months ago
@cherti Why are you making such claims then?
0
0
0
@cherti No you made a claim without evidence.
1
0
0
@cherti And making false claims does not help anyone. On the contrary it leads to false beliefs.
0
0
0
@cherti Please go away, thanks.
1
0
0
@cherti In my books a claim without evidence is a false claim, and frankly I don't care what your interpretation is. Even if that random guess would actually shown to be true.
0
0
0