Skip to content

Attestation for GARUDA #3

@p-j-l

Description

@p-j-l

In the Objective section of GARUDA, there’s discussion of various ways to add trust to a server and it looks like there might be a technical way to add trust to one of the options. This is a quote:

It's open source! That is great, and whatever Garuda produces will be open source, but just because something is open source doesn't prove that the system running it is actually running that open source implementation as is — it's pretty easy to cheat.

Remote attestation is a feature of Trusted Execution Environments that can guarantee to a caller that a certain version of the software is running, we’ve explored it a bit here. It could work very nicely with Open Source software by giving browsers, or anyone, a way to guarantee that there’s no cheating by running other software so it might be worth including in the spec as a possibility.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions