Confidential Computing Is Not Broken: A Calm Look at the RA-TLS Attestation Flaw
In January, security researchers presented a formal-methods result to the IETF SEAT working group. A…
Read more →Insights and updates from the Privasys team.
In January, security researchers presented a formal-methods result to the IETF SEAT working group. A…
Read more →Two earlier posts set out where Enclave Vaults had reached. In the v0.19 redesign the vault became a…
Read more →For as long as the internet has asked us to prove things about ourselves, it has asked us to do it t…
Read more →Key rotation is one of those security expectations everyone agrees on and few enjoy implementing. Au…
Read more →A loan application is declined. A payment is flagged and frozen. A patient record is summarised, and…
Read more →Agents are being built at an extraordinary pace. Frontier models have made it cheap to assemble serv…
Read more →When we wrote about our CVM base images in April, the punchline was that a hardened, immutable image…
Read more →A confidential application is never finished. It needs the same things every other piece of software…
Read more →We have written before about the plumbing of confidential AI: the GPU ceremony that brings an H100 i…
Read more →A few weeks ago we wrote about rethinking secrets management for the age of confidential computing. …
Read more →Confidential computing makes a strong promise. The hardware can prove, cryptographically, what code …
Read more →The previous post in this series described the base images we build for confidential VMs: minimal Ub…
Read more →Every confidential workload we run starts from the same boring artefact: a few hundred megabytes of …
Read more →In our last post we introduced Privasys Wallet, a mobile authenticator that verifies enclave attesta…
Read more →Authentication has always been a one-way street. You prove who you are to the server. The server tel…
Read more →One of the things we love about WebAssembly is that it finally gives us a proper type system at the …
Read more →Every secrets management system, from a €100,000 HSM appliance to a HashiCorp Vault cluster, faces t…
Read more →Intel TDX and AMD SEV-SNP encrypt a virtual machine's memory so that even the hypervisor and cloud p…
Read more →Remote attestation is the mechanism that makes Confidential Computing trustworthy. Without it, a TEE…
Read more →For the past decade, Confidential Computing has focused on one core promise: protect data while it i…
Read more →The Trust Problem in Confidential Computing Confidential Computing promises that data stays encrypte…
Read more →It has been ten years since the introduction of Confidential Computing with Intel SGX. As someone wh…
Read more →Artificial intelligence is transforming every industry, but it comes with a critical challenge: how …
Read more →