> PKCS11 doesn't allow you to attest that the key is resident in the PKCS11 provider, which as you say, the author alludes to, but doesn't cover.
You don’t need that if you include quote in CSR and then CA validates the quote and writes the validation result in the certificate. Certificate then contains proof that private key is in TPM.
I think your central thesis is that at the time of TLS establishment, why not use PKCS11 (with a cert signed by a CA that has validated a TPM certification), and I agree: services should probably integrate via PKCS11.
I just read your original comment "is this any conceptually different from using PKCS11 provider for TPM in OpenSSL?" and yes, I agree it's not conceptually different.
> through every scandal, Zuckerberg’s net worth has climbed to nearly $200bn, according to Forbes. Fines mean nothing to those with wealth like his, so the first step to safeguard society is to give Meta a fresh start without Zuckerberg’s influence on future products.
It’s The Guardian - they just propose left-wing hyperbolic noise with no connection to the real world rather than offer any kind of solutions. Not even aware that Zuck is the biggest shareholder and has all the voting rights, it’s his baby and he owns it, he doesn’t have to resign to make the world a better place in The Guardian’s favour.
Read the last paragraph it calls on the shareholders to push back on Mark Zuckerberg. He owns most of the voting rights so its effectively calling on him to push back on himself.
This might oversell the agency that practicioners have.
Sandboxed zero-install delivery will outcompete anything with more frictionful installs.
It's probably not the right model for a pacemaker though.
Web/JS has been a double-edged sword for FOSS: sure, I can run a free OS, but if most of my "apps" happen to be JS that I can't practically control, then I have won a battle and lost a war.
I wish Haketilo [1] would have caught on more. There's so many free JavaScript apps but we're mostly just missing a way to actually control which version or derivative of the JavaScript is run.
There's also the problem of most free apps not doing a good job of providing license info and a link to source code, but this could be sidestepped by a trusted repository which provides license info itself.
> even if you don't have the keys you may still control the implementation
The sorts of places that care about remote attestation also care about insider risk.
reply