Next up, 'TEE.fail: Breaking Trusted Execution Environments via Memory Bus Interposition', presented by Christina Garman and Daniel Genkin
#realworldcrypto
Q: You believe these protections only got removed bc of performance?
A: Yes I do, we talked to the engineers, they were so upset and repeatedly saying "I told you so" etc
#realworldcrypto
Really want boring simple cryptography with few assumptions; used Rust bc strong typing enabled misuse-resistant API design, and performance came for free
#realworldcrypto
Secure elements are great tools...except they don't expose auth attempt counters, nor enforce timeouts (they are reserved for the operating system)
#realworldcrypto
Q: Diff from SecureDrop?
A: Focused on the first contact experience; using Tor is a red flag/signal; we don't support sending files, pivot elsewhere for that
#realworldcrypto
Speaking of SecureDrop, next up is 'SecureDrop Next Generation: Lessons from a Decade of Deployment', presented by Rowen Shane, Shannon Veitch
#realworldcrypto