Re: [liberationtech] PrivateCore and secure hosting

2013-06-22 Thread Steve Weis
Hi Maxim. This area is a bit murky since there is a lot of overlap between the notions of secure boot, trusted boot, and measured boot. If it had to venture an answer, I'd say the benefit of TXT is that it provides finer-grained measurements and visibility into the secure boot process. I don't kno

Re: [liberationtech] PrivateCore and secure hosting

2013-06-22 Thread Maxim Kammerer
Hi Steve, a technical (and perhaps stupid) question: On Sat, Jun 22, 2013 at 1:49 AM, Steve Weis wrote: > The host H will have a trusted platform module (TPM). When H boots up, it > will measure all software state into platform control registers (PCRs) in > the TPM. See Intel Trusted Execution Te

Re: [liberationtech] PrivateCore and secure hosting

2013-06-21 Thread Steve Weis
Hi Eleanor. tl;dr: Today we bootstrap from the TPM. "To have a secure channel between two processes/compartments (in this case, the CPU of the hosted machine and the remote, non-service-provider-controlled system), they must share a secret." This is a good question since it's not necessarily clea

Re: [liberationtech] PrivateCore and secure hosting

2013-06-21 Thread Eleanor Saitta
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 2013.06.20 22.55, Steve Weis wrote: > Hi Eleanor. I am a co-founder of PrivateCore and happy to answer > questions. I'll keep it non-commercial and focus on the technical > answers for this mailing list: Thanks for responding! > "[It isn't] cl

Re: [liberationtech] PrivateCore and secure hosting

2013-06-20 Thread Steve Weis
Hi Eleanor. I am a co-founder of PrivateCore and happy to answer questions. I'll keep it non-commercial and focus on the technical answers for this mailing list: "[We] were talking about secure hosting" PrivateCore's technology is currently packaged as a hypervisor, so is targeted at environments

[liberationtech] PrivateCore and secure hosting

2013-06-20 Thread Eleanor Saitta
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 So, a bunch of us were talking about secure hosting in Tunis. At one point in a side conversation, PrivateCore came up as a tool that might be interesting when you're looking at aggressive malware. It's designed to allow you to perform certain kind