|
|
|
|
|
by Veserv
1174 days ago
|
|
How did you verify and validate that a AWS Nitro Enclave actually provides isolation and attestation guarantees? Do they provide certifications or audits confirming conformance to multi-level security guarantees? Or do they provide you detailed specifications allowing you to evaluate that yourselves? Did you run red team exercises that resulted in no detected deficiencies as would be required by a multi-level security claim? |
|
Which is what we and our customers do already, when we run our workloads on it.
We know this is a problem, but this is where we’re ok with drawing the line. If you’ve seen Reflections on Trusting Trust you’ll know we have to draw the line somewhere.