Hacker News new | past | comments | ask | show | jobs | submit login

Signal relies on Intel's SGX for certain operations (such as who contacts who?). Does that worry anyone else?



Most chat servers simply know who contacts whom. This is an inherent problem (or strategic advantage) in being a chat server. Signal tries to hide the information from themselves by using Intel SGX. So, while SGX may not be perfect, its better than nothing.


But how do you validate that they are actually running SGX server side?


On top of that, even if they do run SGX, whoever hosts the SGX instances can just let the NSA into the server room and nobody would be the wiser. It's not like SGX actually works. It actually makes things worse if it allows signal admins to look the other way in good conscience.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: