logoalt Hacker News

Borealidtoday at 3:55 AM1 replyview on HN

MK-TME allows having memory encrypted at run time, and the platform TPM signs an attestation saying the memory was not altered.

Malicious code can't be injected at boot without breaking that TPM.


Replies

fc417fc802today at 4:18 AM

Subject to the huge caveat that the attacker does not have physical access. https://tee.fail/