Joanna Rutkowska @rootkovska
Correct. Most ppl tend to think that RA can tell apart instances of the same SGX enclave (hash-wise) running on dif… https://t.co/9B0kdmG551 — PolitiTweet.org
Matthew Green @matthew_d_green
@octal @pzb So if people write software to trust any SGX instance that can attest, you can potentially do a lot of damage with one instance.