Jonathan S. Shapiro wrote:

> The question was: what can the operating system enforce?

OK - I think this question deserves two answers -- one for a TPM backed
 system, and one for systems without TPM. (Maybe this gets boring, but
i'd like to sort this one out, finally).

Iff there is no TPM:

In the eyes of a software "vendor": Even a system claiming to support
opaque memory cannot be trusted: in effect the hardware owner got full
control (not necessary the system administrator). Every mechanism which
tries to enforce opaqueness and which is embedded into the OS can be
defeated easily.

The special case of hardware-owner and software-vendor being the same
person is not very interesting.

The same situation in the eyes of a hardware-owner: It's not very
important whether my OS supports opaque storage or not. If i'm
interested in its content nothing will stop me.


Everybody agrees?


   j.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
L4-hurd mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/l4-hurd

Reply via email to