Re: [liberationtech] PrivateCore and secure hosting

2013-06-22 Thread Maxim Kammerer
Hi Steve, a technical (and perhaps stupid) question: On Sat, Jun 22, 2013 at 1:49 AM, Steve Weis stevew...@gmail.com wrote: The host H will have a trusted platform module (TPM). When H boots up, it will measure all software state into platform control registers (PCRs) in the TPM. See Intel

Re: [liberationtech] PrivateCore and secure hosting

2013-06-22 Thread Steve Weis
Hi Maxim. This area is a bit murky since there is a lot of overlap between the notions of secure boot, trusted boot, and measured boot. If it had to venture an answer, I'd say the benefit of TXT is that it provides finer-grained measurements and visibility into the secure boot process. I don't

Re: [liberationtech] PrivateCore and secure hosting

2013-06-21 Thread Eleanor Saitta
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 2013.06.20 22.55, Steve Weis wrote: Hi Eleanor. I am a co-founder of PrivateCore and happy to answer questions. I'll keep it non-commercial and focus on the technical answers for this mailing list: Thanks for responding! [It isn't] clear

Re: [liberationtech] PrivateCore and secure hosting

2013-06-21 Thread Steve Weis
Hi Eleanor. tl;dr: Today we bootstrap from the TPM. To have a secure channel between two processes/compartments (in this case, the CPU of the hosted machine and the remote, non-service-provider-controlled system), they must share a secret. This is a good question since it's not necessarily

[liberationtech] PrivateCore and secure hosting

2013-06-20 Thread Eleanor Saitta
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 So, a bunch of us were talking about secure hosting in Tunis. At one point in a side conversation, PrivateCore came up as a tool that might be interesting when you're looking at aggressive malware. It's designed to allow you to perform certain

Re: [liberationtech] PrivateCore and secure hosting

2013-06-20 Thread Steve Weis
Hi Eleanor. I am a co-founder of PrivateCore and happy to answer questions. I'll keep it non-commercial and focus on the technical answers for this mailing list: [We] were talking about secure hosting PrivateCore's technology is currently packaged as a hypervisor, so is targeted at environments