logoalt Hacker News

essephyesterday at 3:47 PM4 repliesview on HN

But can you trust the hardware encryption to not be backdoored, by design?

That's my point, this sounds like a way to create a backdoor for at-rest data.


Replies

cassonmarsyesterday at 4:07 PM

You can if the manufacturer has a track record that refutes the notion, and especially if they have verifiable hardware matching publicly disclosed circuit designs. But this is Intel, with their track record, I wouldn't trust it even if the schematics were public. Intel ME not being disable-able by consumers, while being entirely omitted for certain classes of government buyers tells me everything I need to know.

jayd16yesterday at 7:02 PM

By design, you don't trust it. You never hand out the keys so there's no secret to back door. The task is never unencrypted, at rest or otherwise.

bilekasyesterday at 4:43 PM

> That's my point, this sounds like a way to create a backdoor for at-rest data.

I get the feeling honestly it seems more expensive and more effort to backdoor it..

anon291yesterday at 7:53 PM

Well yeah... You do the initial encryption yourself by whatever means you trust