🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. https://t.co/ule9gaXzc1
Tinfoil (@TinfoilAI) lets you build verifiably private AI applications in the cloud.
Replace legal agreements, PII redaction, and “pinky promises” with fully verifiable end-to-end security powered by NVIDIA’s hardware-backed confidential computing mode.
https://t.co/EdjwNIZwmt
Congrats on the launch, @t0nyav, @julesdrean, @sachaservan and @natesales!
@traviscline@sachaservan@grittygrease@projectsigstore Reproducibility is rough. It shouldn’t block “softer” supply chain security in the interim, but will always be stronger than deferring trust to the build environment.
@traviscline@SachaServan@grittygrease Secure enclaves + in-band verification needs to be the standard.
Reproducible builds and TLS channel binding need to happen too, but TEEs and @projectsigstore are here today to link source code to a running service.
SEV-SNP isolates a VM from the hypervisor and encrypts VM memory with a key stored on the CPU. This prevents host based attacks on private data within a VM. (2/n)
@ntdvps There are also a few convenience features that depend on real-time access to BIRD - automatic rollbacks, annotated error logs, and a status command that combines the authoritative config with the current session state.
@ntdvps You could run Pathvector without BIRD and copy the configs over externally, but the primary use case is to run it directly on the network device. It can do route optimization and such so needs to be on device.