Attested TLS Was Supposed to Be the Last Trust Boundary. It Isn't. Formal Methods Show How.
A wax seal proves a document is genuine. It does not prove the seal is still attached to the document it was originally stamped onto. Medieval forgers knew this and exploited it for centuries: cut a real seal off one charter, reattach it to a fake one, and the forgery passes inspection, because the seal really is authentic. It's just authenticating the wrong thing.
Confidential computing has just been shown to have the exact same flaw, a thousand years later, in software. Researchers at TU Dresden formally proved that the cryptographic proof a secure cloud enclave gives you, called remote attestation, isn't reliably tied to the actual connection you're using. An attacker who steals one key can silently reroute your "secure" session to a machine they control, and every check on your end still comes back valid, the same way a genuine seal still looks genuine sitting on the wrong...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE