A GS645w isn’t much larger than a modern 35mm digital, and is certainly lighter.
HN user
achamayou
More like 45k now (assuming you mean post tax, pre-tax is even higher of course): https://www.gov.uk/government/statistics/percentile-points-f...
Mermaid (https://mermaid-js.github.io/) is excellent, easy to embed inline in Markdown or reStructuredText and to version with the rest of the documentation.
No, the user is still in control of what they execute on the machine, whether it is run in enclave or not. If anything, because it is deliberately unable to patch itself, software running in an enclave gives more control and auditability to a user who can know exactly what code they are running.
Importantly, a user who does not fully trust the machine administrator can still maintain integrity and confidentiality over their computation.
SGX memory encryption keys are ephemeral, they are generated at boot, and they do not need to be owned by anyone to be useful, on the contrary!
I don’t think it’s helpful to confuse side-channel or micro-architectural attacks with attacks on SGX itself. Stating that hardware enclaves don’t work and do not ship is absurd, they are present in virtually every modern phone for one thing.
Code running in an SGX enclave is measured and absolutely known at enclave launch. The fact that enclave memory is encrypted for confidentiality is unrelated.
I don’t understand why you think trusting the hyper visor is helping anything. You are still open to this attack, and to all side channel attacks as soon as you run any untrusted code.
The same person creating separate accounts for automation is explicitly permitted however: https://help.github.com/en/github/getting-started-with-githu...
I’m not sure why you think that SGX shows hardware enclaves “don’t work”. I also don’t see why you think enclaves “protect the malware from you”. Enclaves are created and started from host code, which can interrupt or terminate them at any time.
The scheme you suggest, which isn’t typically how TrustZone is used, gives zero integrity and confidentiality guarantees for applications. I don’t know if it’s “the right way” for some threat model, but for the most typical TEE use cases which are trying to establish strong integrity and confidentiality guarantees in the presence of an untrusted host, it’s absolutely not right nor useful.
Why not? An OS is a large beast, it’s a massive TCB. Much easier to audit a small amount of code running in an enclave with few dependencies.
Not that I know, I suspect a limiting factor is that there aren’t many cloud providers with good support for SGX at the moment.
There are many interesting uses for enclaves, most of which have nothing to do with DRM. A good example is Signal’s secure value recovery mechanism: https://signal.org/blog/secure-value-recovery/
How do you distribute it out freely without affecting the market price? If packaging and transport are a substantial part of the cost, which they are for milk, who’s going to pay that cost?
Which is French for tired.
Mistakes were made along the way: https://medium.com/@fs0c131y/tchap-the-super-not-secure-app-...
I suspect cases are even worse. Screens are at least smooth and easy to clean.
A substantial difference as others pointed out is that Apple did this quietly, whereas limp mode is typically notified to the driver about loudly as anything can be.
Not the government, who was never using WhatsApp, the Tory Party.
A Type 45 destroyer is almost 10000 tons though, a WWII destroyer would have been 2 to 3000. It’s probably difficult to come up with an accurate cost comparison, but I suspect the difference is even greater than for tonnage.
It's not part of Azure, it's part of Experience + Devices, which is a different top-level group from Cloud + AI.
The Raft paper has a full section on understandability, and comes with a TLA+ spec.
I am baffled that a serious effort at producing papers that are understandable and implementable is dismissed as a “social phenomenon”. Deliberately obscure papers are bad, sloppy science, not a clever signaling mechanism.
As pointed out elsewhere in the conversation and indeed in revised editions of the Paxos paper, it does not even break new ground and is equivalent to the earlier view management protocol.
We’re talking about what would be good for the UK. Countries that never had strong exports definitely wouldn’t benefit.
Britain is definitely in the northern half of Europe.
Yeah it’d be even better for Britain if it was in control of that currency, you’re definitely right there!
If only there was some sort of regional currency, less susceptible to a single country’s economic changes, that one could use...
The plan seems to be to do it in common with Germany and Spain: https://www.iiss.org/blogs/military-balance/2019/06/franco-g...
Check out Logic Apps :)
The clue is perhaps in the name, it isn’t called “The Students’ College”.
And anyway you really want mkstemp ;)