create account

iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud by dana-edwards

View this thread on: hive.blogpeakd.comecency.com
· @dana-edwards · (edited)
$47.68
iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud
The adoption of Intel SGX in my opinion offers a major competitive advantage over all other similar attempts in it's class to the iExec platform. Golem will not have this capability for quite a while and the only other platform which will have privacy of this nature is Enigma.

The benefit of hardware privacy at the CPU level
---

The benefit of this level of privacy is that you get the most bang for your buck. In other words you get the most potential privacy for the cheapest cost in terms of implementation, performance, and other measures. The benefits of using Intel SGX in my opinion far outweigh the risks. There of course has been the exposure of Intel CPUs being vulnerable to [Meltdown and Spectre](https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/meltdown-and-spectre-intel-processor-vulnerabilities-what-you-need-to-know). These risks must be considered and because of this we can say Intel does not have the greatest track record currently.  The vulnerabilities are based on a technique called "speculative execution" which by it's very name sounds in my opinion ridiculous.

> Intel processors built since 1995 are reportedly affected by Meltdown, while Spectre affects devices running on Intel, AMD, and ARM processors. Meltdown is related to the way privileges can be escalated, while Spectre entails access to sensitive data that may be stored on the applicationโ€™s memory space.

So how does this impact Intel SGX? 
----

Intel SGX is vulnerable to Spectre and an attack has been [demonstrated as successful](https://github.com/lsds/spectre-attack-sgx) in code. For this reason, it may be the case that Intel SGX is not sufficiently secure for all use cases. This could give the Enigma Protocol an edge over iExec in the fact that Enigma will provide the option to take security to a level beyond the limits of Intel SGX by using the SHE (somewhat homomorphic encryption) scheme they mention in the Enigma Whitepaper. 

This [quote](https://idfusionllc.com/2018/01/25/sgx-after-spectre-and-meltdown-status-analysis-and-remediations/) in particular should be deeply understood:

> The most important security finding currently available is that there is no credible engineering rationale to support the contention that SGX enclaves will provide confidentiality guarantees in the face of these new micro-architectural cache probing attacks. This is disappointing for a technology that was designed to provide security guarantees in the face of an IAGO threat model or in the previously described service provider models.

In summary:

- Current Intel SGX offers limited security and cannot guarantee privacy due to the exploit/backdoor micro-architectural cache probing attacks. 
- Future Intel SGX may offer fixes to this which could make it secure but can we trust Intel? This is the variable which in my opinion creates the majority of the risk for using future iterations of Secure Enclave.
- While Secure Enclave is a promising idea in theory the implementation which currently exists on the market is for sure vulnerable and should not be trusted. This means Enigma and iExec both are going to be vulnerable to whatever issues exist with Intel architectures and in my opinion both teams must seek to control the risks involved by offering additional security and privacy guarantees. At minimum, new hardware will likely need to be created and for this reason current expectations of privacy must realistically be low for either iExec or Enigma data in the early days until this gets resolved.


Conclusion
---

I'm still quite content with the progress being made by iExec. The Team is working to provide decentralized computation capabilities for decentralized apps. That said, I am not satisfied with Secure Enclave simply because it doesn't currently work to achieve confidentiality for data in motion based on the listed vulnerabilities discussed above. This means iExec will have to invest additional resources and conduct additional research to improve upon the security guarantees they try to achieve with Intel SGX.


References
---
1. https://medium.com/iex-ec/iexec-dev-letter-14-intel-sgx-security-and-r-14-feb-2018-544d87e28869
2. https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/meltdown-and-spectre-intel-processor-vulnerabilities-what-you-need-to-know
3. https://idfusionllc.com/2018/01/25/sgx-after-spectre-and-meltdown-status-analysis-and-remediations/
๐Ÿ‘  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 322 others
properties (23)
authordana-edwards
permlinkiexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud
categoryiexec
json_metadata{"tags":["iexec","enigma","cybersecurity","crypto","crypto-news"],"links":["https://www.trendmicro.com/vinfo/us/security/news/vulnerabilities-and-exploits/meltdown-and-spectre-intel-processor-vulnerabilities-what-you-need-to-know","https://github.com/lsds/spectre-attack-sgx","https://idfusionllc.com/2018/01/25/sgx-after-spectre-and-meltdown-status-analysis-and-remediations/","https://medium.com/iex-ec/iexec-dev-letter-14-intel-sgx-security-and-r-14-feb-2018-544d87e28869"],"app":"steemit/0.1","format":"markdown"}
created2018-02-25 10:46:03
last_update2018-02-25 10:50:24
depth0
children10
last_payout2018-03-04 10:46:03
cashout_time1969-12-31 23:59:59
total_payout_value39.032 HBD
curator_payout_value8.646 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length4,454
author_reputation353,623,611,191,427
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,307,689
net_rshares8,642,319,754,692
author_curate_reward""
vote details (386)
@ahmadin8 ·
Nice post
properties (22)
authorahmadin8
permlinkre-dana-edwards-201834t152859111z
categoryiexec
json_metadata{"tags":["iexec","enigma","cybersecurity","crypto","crypto-news"],"app":"esteem/1.5.1","format":"markdown+html","community":"esteem"}
created2018-03-04 08:29:06
last_update2018-03-04 08:29:06
depth1
children0
last_payout2018-03-11 08:29:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length9
author_reputation-13,702,064,740
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries
0.
accountesteemapp
weight1,000
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id42,078,890
net_rshares0
@bagindooo ·
On progress! Still..
properties (22)
authorbagindooo
permlinkre-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180225t104820825z
categoryiexec
json_metadata{"tags":["iexec"],"app":"steemit/0.1"}
created2018-02-25 10:48:30
last_update2018-02-25 10:48:30
depth1
children0
last_payout2018-03-04 10:48:30
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length20
author_reputation97,115,803,368
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,308,116
net_rshares0
@burhanahmad ·
properties (23)
authorburhanahmad
permlinkre-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180225t172522179z
categoryiexec
json_metadata{"tags":["iexec"],"app":"steemit/0.1"}
created2018-02-25 17:25:24
last_update2018-02-25 17:25:24
depth1
children0
last_payout2018-03-04 17:25:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length12
author_reputation5,296,099,963
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,383,502
net_rshares0
author_curate_reward""
vote details (9)
@crescendoofpeace ·
Running processes with a secure VPN enabled makes hacks less likely, though for a truly determined and talented hacker, even that is not a complete guarantee, as occasionally connections to the VPN can drop for various reasons.

That said, I'll continue connecting via Proton VPN, until a better solution is presented.
properties (22)
authorcrescendoofpeace
permlinkre-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180225t185157959z
categoryiexec
json_metadata{"tags":["iexec"],"app":"steemit/0.1"}
created2018-02-25 18:52:03
last_update2018-02-25 18:52:03
depth1
children0
last_payout2018-03-04 18:52:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length318
author_reputation23,779,495,298,982
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,400,379
net_rshares0
@happypeople ·
## <center>๐ŸŽ‰ Congrats ๐Ÿพ</center>

<div class="pull-right"><img src="https://media.giphy.com/media/26BRABnerqonwLHMc/200w.gif " /></div>

#### Top Trending Post Today in:
>#iexec
#enigma 
#cybersecurity
#crypto
#crypto-news



<center>*It is a success, you truly deserved. It is an achievement you have truly earned. **Well Done.***</center>
๐Ÿ‘  
properties (23)
authorhappypeople
permlinkre-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180225t202358030z
categoryiexec
json_metadata"{"tags":["iexec","enigma","cybersecurity","crypto","crypto-news"],"image":["https://media.giphy.com/media/26BRABnerqonwLHMc/200w.gif "],"app":"steemit/0.1"}"
created2018-02-25 20:23:57
last_update2018-02-25 20:23:57
depth1
children1
last_payout2018-03-04 20:23:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length340
author_reputation175,845,374,616
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,416,841
net_rshares2,794,569,264
author_curate_reward""
vote details (1)
@p2port.com ·
One of the best investment opportunities in crypt asset! RLC! Watch and learn! ;-)
๐Ÿ‘  
properties (23)
authorp2port.com
permlinkre-happypeople-re-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180302t101044005z
categoryiexec
json_metadata{"tags":["iexec"],"app":"steemit/0.1"}
created2018-03-02 10:10:45
last_update2018-03-02 10:10:45
depth2
children0
last_payout2018-03-09 10:10:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length82
author_reputation6,985,285,620
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id41,601,045
net_rshares612,728,829
author_curate_reward""
vote details (1)
@kouba01 ·
Yes Exactly, I agree with that the real essence of cloud computing is to provide a decentralized network of computers around the world with remote users being able to leverage their resources or pay for them as part of the network.
properties (22)
authorkouba01
permlinkre-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180225t105443043z
categoryiexec
json_metadata{"tags":["iexec"],"app":"steemit/0.1"}
created2018-02-25 10:54:45
last_update2018-02-25 10:54:45
depth1
children0
last_payout2018-03-04 10:54:45
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length231
author_reputation40,349,470,265,666
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,309,209
net_rshares0
@markzuckerbergs ·
iExec relies on XtremWeb-HEP, a mature, solid, and open-source Desktop Grid software which implements all the needed features : fault-tolerance, multi-applications, multi-users, hybrid public/private infrastructure, deployment of virtual images, data management, security and accountability, and many more.
properties (22)
authormarkzuckerbergs
permlinkre-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180225t105231247z
categoryiexec
json_metadata{"tags":["iexec"],"app":"steemit/0.1"}
created2018-02-25 10:52:33
last_update2018-02-25 10:52:33
depth1
children2
last_payout2018-03-04 10:52:33
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length306
author_reputation3,365,667,565,848
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,308,839
net_rshares0
@dana-edwards ·
But not privacy of the data. All of that is fine but don't expect the computation to be anything secret or private.
properties (22)
authordana-edwards
permlinkre-markzuckerbergs-re-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180225t105620279z
categoryiexec
json_metadata{"tags":["iexec"],"app":"steemit/0.1"}
created2018-02-25 10:56:18
last_update2018-02-25 10:56:18
depth2
children0
last_payout2018-03-04 10:56:18
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length115
author_reputation353,623,611,191,427
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,309,458
net_rshares0
@dana-edwards ·
Lei Zhang in my opinion is basing his choice on an assumption. That assumption is that Intel will get it's act together and release a future version of SGX which is not vulnerable to the current attacks which render the current versions of SGX insecure. So yeah of course it's a bet on Intel, but I think iExec needs a backup plan because it's not wise to pin all bets in one company.

I even tend to agree that sooner or later Intel will get SGX right, but this will be in a future chip which isn't released yet. iExec will not be able to guarantee data privacy with current SGX in my opinion.
properties (22)
authordana-edwards
permlinkre-markzuckerbergs-re-dana-edwards-iexec-will-be-supporting-intel-sgx-secure-enclave-promising-to-allow-for-private-software-execution-in-the-decentralized-cloud-20180225t110156753z
categoryiexec
json_metadata{"tags":["iexec"],"app":"steemit/0.1"}
created2018-02-25 11:01:57
last_update2018-02-25 11:01:57
depth2
children0
last_payout2018-03-04 11:01:57
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length594
author_reputation353,623,611,191,427
root_title"iExec will be supporting Intel SGX (Secure Enclave) promising to allow for private software execution in the decentralized cloud"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id40,310,415
net_rshares0