Jonathan S. Shapiro wrote: > The question was: what can the operating system enforce?
OK - I think this question deserves two answers -- one for a TPM backed system, and one for systems without TPM. (Maybe this gets boring, but i'd like to sort this one out, finally). Iff there is no TPM: In the eyes of a software "vendor": Even a system claiming to support opaque memory cannot be trusted: in effect the hardware owner got full control (not necessary the system administrator). Every mechanism which tries to enforce opaqueness and which is embedded into the OS can be defeated easily. The special case of hardware-owner and software-vendor being the same person is not very interesting. The same situation in the eyes of a hardware-owner: It's not very important whether my OS supports opaque storage or not. If i'm interested in its content nothing will stop me. Everybody agrees? j.
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ L4-hurd mailing list [email protected] http://lists.gnu.org/mailman/listinfo/l4-hurd
