|
|
|
|
|
by arcurn
1771 days ago
|
|
Thanks for the question! I addressed some of this in an answer above: https://news.ycombinator.com/item?id=28129362 The summary version is that we share source code and platform control registers (PCRs) with enterprise customers who need these kind of security guarantees, and also expose the Nitro Enclaves attestation documents to them so they can establish secure channels with E3 in a provable way. |
|
Or maybe you're a government honeypot, like Crypto AG, or the numerous other cryptography companies that turned out to actually be mass decryption companies.
If you're building an encryption company, the onus is on you to prove it. BitWarden for example is fully open source, and you can self host the server.