This means bugs in secure enclaves can last forever. Worse, if the keys for a secure enclave ever leak, then there's no way to update all the secure enclaves out there in the world - millions or billions of them - to fix it.

Well, it's happened.

The keys for the secure enclaves in #MicroStarInternational (AKA #MSI) computers, a massive manufacturer of work and gaming PCs - have leaked and shown up on the "#ExtortionPortal" of a notorious crime gang:

https://arstechnica.com/information-technology/2023/05/leak-of-msi-uefi-signing-keys-stokes-concerns-of-doomsday-supply-chain-attack/

46/

Leak of MSI UEFI signing keys stokes fears of “doomsday” supply chain attack

With no easy way to revoke compromised keys, MSI, and its customers, are in a real pickle.

Ars Technica