Conversation

Jarkko Sakkinen

With confidential computing established it might make sense to have a TPM blob in linux-firmware compiled from open source base and way to certify that for distributors.

Most have some form of certificate authority alike thing in place so this would be good use of that.

Then SGX/SNP/TDX could provide a way to establish a sealed device from that and further distribute a vTPM for each virtual machine.
1
0
0

@jarkko we've suggested several times that the various ACMs should be (at the least) source available with fully reproducible builds.

1
0
1
@vathpela TPM might be easier because it is vendor neutral standard.
1
0
0
@vathpela Sometimes (not always) the problem with vendor-specific proprietary IP (be it software or hardware) is that sub-parts might be re-licensed from other 3rd parties. So it is not always just an evil corps type of thing but opening IP could be hard to realized sometimes, even if there was will from the company.
1
0
0
@vathpela So in principle I do support opening up e.g. ACM's and almost anything really but that said I also get the views of the "other side" :-)
1
0
0

Jarkko Sakkinen

Edited 5 months ago
@vathpela Like any modern silicon product have a huge ecosystem of IP blocks bought from various partners. There's even companies that are specialized just doing small parts of SoC's and other products and selling those IP blocks for industry partners. And it is good to have also this ecosystem because it drives tech forward so openness is in my opinion always about finding the right balance :-) All my opinions on almost anything are these middle-ways dull ones 🤷
0
0
0