Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Please explain to me why an OS level signed and encrypted database isn’t secure


Why is a padlock with the key stuck right into it secure? The encrypted data and the decryption key is on the same physical device.

Sure, memory isolation techniques may serve as a deterrent with extreme care. But if Microsoft increases the attack surface by sloppily integrating that feature everywhere in Windows, the yet-to-be-implemented-if-at-all encryption is going to be ineffective. And that’s going to happen more likely than not.


Maybe the learning and inference can happen in a VM and the apps can only have access to a query API. (Take the equivalents if it's not all ML.)


That's exactly the kind of thing I was referring to when I wrote "memory isolation techniques." Even if you gate access with an API, you can still retrieve data from it and that's the problem.

Also, it should be clear by now that government agencies are going to demand access to this data once this becomes widespread. VMs aren't going to protect against further assault on our civil liberties.


How does that work? Can authorities compell Microsoft to surreptitiously have only my computer randomly unencrypt and submit stuff? If so, couldn't the authorities just tell MS to activate a tool like recall anyway?



Also, Windows Store apps seem to have an identity and limited permissions, so you can probably have some kind of smartphone OS-like isolation.


The same reason banks get occasionally robbed, despite all security cameras, delayed openings, biometrics, armed security, and everything else put in place.

When there is a will, there is eventually a way, for anyone with enough resources.


Researchers on Twitter are saying that it’s just a plaintext SQLite.


Because it needs to be decrypted at some point?


People made it, people will break it

Please explain to me how anything achieved infallible nature. Consider the natural vacuum is space.


When has windows ever been a safe or secure OS environment? Seems to me, many an exploit has been installed by the user while trying to get device drivers working




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: