Hacker News new | ask | show | jobs
by deno 493 days ago
Intel SGX was never pushed on anyone and it's also Intel only Skylake to Ice lake and requires vendors to provide consistent firmware updates to stay secure. You can’t run the entire OS in SGX enclave because it can’t do I/O on its own.

> There are TPM 2.0 dTPMs. If the conspiracy is that they want to push people towards "hardware attestation", then they're doing a pretty bad job.

No "normies" are doing TPM bypasses. That’s the point. Majority will eventually be on unbypassable TPM.

1 comments

>Intel SGX was never pushed on anyone

Considering that's the only way to play most DRM protected 4K videos, it's probably more of a "push" than requiring TPM. It didn't even have the fig leaf of being usable for FDE or webauthn.

>No "normies" are doing TPM bypasses. That’s the point. Majority will eventually be on unbypassable TPM.

If the bar is "normies", then you don't even need TPM. You can just slap denuvo or whatever and call it a day.

You can just not buy blurays, they were never popular on PCs anyway. TPM is being pushed on everyone upgrading to Win11. One is opt in, the other is maybe opt out if you jump through hoops, for now. Very different. Also you can do other things with SGX though admittedly it’s mostly useful on servers, but you would still use SGX indirectly via remote attestation. E.g. it’s what Signal uses for some of its core functionality.

> If the bar is "normies", then you don't even need TPM. You can just slap denuvo or whatever and call it a day.

Again, missing the point. Denuvo, Widevine, whatever, it’s all weak to crack once & enjoy but only if you control the OS. The Great TPM Conspiracy Theory is about limiting what you can do with your mainstream Windows/Linux/Macos installation, in the ways I’ve laid out earlier. Taking the ‘P’ out of PC.