logoalt Hacker News

Reddit_MLP2today at 6:10 PM1 replyview on HN

but if the host OS is already comprised, what is the point of sandbox inside of it?


Replies

necovektoday at 7:03 PM

Maybe we need secure attestation for sandbox to be protected against compromised host :)

It does sound hard, and might need to employ homomorphic encryption with hw help for any memory access after code has been also verifiably unaltered through (uncompromised) hw attestation.