logoalt Hacker News

prmphyesterday at 9:20 AM6 repliesview on HN

I thought not trusting clients was already security 101?


Replies

edelbitteryesterday at 1:32 PM

We're at something like 116 now and they keep coming up with funny terms for it.

secure enclaves, secure virtualization, trusted execution environment, trusted platform, confidential computing, protected execution, LaGrande, protected launch, hardware attestation, ..

red_admiralyesterday at 5:34 PM

It was, back when I took my intro to security class. And that was back in the day when we talked about domestic and export versions of RSA.

creeryesterday at 7:07 PM

> I thought not trusting clients was already security 101?

Of course it is. Always has been.

The security field is riddled with complete nonsense. Much of it even couched in terms of "best practices". It's the perfect field for people with zero specific knowledge or experience to be trusted with management or engineering - since it doesn't matter until it did matter, at which point a mild non-apology is usually sufficient.

show 1 reply
nicman23yesterday at 4:42 PM

sorry we only can install a literal rootkit on your device to detect tampering

ehutch79yesterday at 3:52 PM

I am still surprised by how often this is a problem

palatayesterday at 12:06 PM

It is, but most software doesn't include security.