Hacker News new | ask | show | jobs
by emceepeepants 2170 days ago
Google does not have an agent on confidential vms; that defeats the purpose. The confidential VM runs a shielded OS which includes vTPM based attestation to protect against boot/rootkits so you know if someone has tampered with your boot chain up thru kernel.