The body of the secret

2026-06-04 · 6,253 words · Singular Grit Substack · View on Substack

On why information security is, in the last analysis, physical security — every cipher resting on a secret that has a location, every trustless system on a root of trust one can hold, burn, or steal,

On why information security is, in the last analysis, physical security — every cipher resting on a secret that has a location, every trustless system on a root of trust one can hold, burn, or steal, and every chain of trust ending, at the bottom, in matter and in flesh


Keywords: information security; physical security; side-channel attacks; the root of trust; tamper resistance; trusted hardware; key extraction; trusting trust; rubber-hose cryptanalysis; the trust surface; the physical substrate of cryptography.

Abstract. The three essays that precede this one celebrated a set of achievements — the honest game without a dealer, the scarce digital good one may truly own, and the relocation of social power that both imply — and each of them rested, quietly and without remark, upon a foundation it did not examine: the secret key, and the assumption that a secret key can be kept. This essay examines that foundation, and finds it made not of mathematics but of matter. Cryptography presents itself as the most disembodied of disciplines, a fortress built of pure number whose strength is a theorem and whose security is independent of the grubby physical world; and as an account of ciphers on paper this is true and beautiful. But a cipher on paper protects nothing. The instant a key is used it re-enters the physical world — as charge in a register, as a voltage, as a duration, as heat, as sound, as the electromagnetic breath of a wire — and the physical world leaks. I argue that the entire history of practical attack is the history of breaking the matter rather than the mathematics: that keys have been pulled from the time a computation takes, the power a chip draws, the radiation a screen emits, the very sound a laptop makes; that the modern remedy of trusted hardware merely relocates the secret into a physical object which, being physical, can be frozen, glitched, and read out; that the chain of trust, followed honestly to its end, terminates not in a proof but in a fabricated artifact and the human hands that made it; and that the last keeper of every secret is a human body, which can be deceived, compelled, or simply struck with a five-dollar wrench. The lesson for the trustless world is exact and sobering: there is no security in the abstract, the trust surface always includes atoms, and the honest claim is never that a secret cannot be taken but that taking it has been made expensive, accountable, and bounded. To build well is to honour the body of the secret, and to stop pretending it has none.


I. The cryptographer’s clean dream

There is no discipline that has fallen more deeply in love with its own abstraction than cryptography, and the love is not foolish, for the abstraction is genuinely beautiful. The dream took its clearest form when a great theorist proved that a message could be enciphered with perfect secrecy — that with a key as long as the message and used but once, the ciphertext betrays nothing whatever about the plaintext, not to the cleverest adversary, not to one with infinite computation, not ever; the secrecy is not merely hard to break but mathematically impossible to break, a property of information itself [1]. Here was security promoted from an art to a theorem, lifted out of the contingent world of locks and guards and made a thing one could prove. And around this central jewel a whole architecture of beautiful results arose. An earlier principle, older than the theorem by two generations, had already insisted that the strength of a system must reside entirely in its key and never in the secrecy of its design — that one must assume the enemy knows the machine, and rest everything on the one secret number [2]. Then came the discovery that two strangers who had never met could establish a shared secret over a channel an enemy was listening to, and that a message could be sealed with a key made public to all the world and opened only with a key kept private — the security of the whole resting on the supposed difficulty of certain problems in number theory, the taking of a discrete logarithm, the factoring of a large integer into its primes [3, 4].

Observe what these achievements promised, and why the promise was so seductive. They promised that security could be made a property of pure mathematics — that if the theorem held and the problem was hard, the secret was safe, and safe in a way that owed nothing to the physical circumstances of its keeping. The fortress was to be built of proofs, and proofs do not rust, do not tire, do not have doors that can be forced; they are true in all possible worlds, indifferent to the room one computes in and the hands that hold the machine. It is the most natural thing in the world for a mind that has tasted this to conclude that the physical has been transcended — that with mathematics of sufficient strength one need no longer trouble oneself with the vulgar questions of guards and walls and bodies, since the secret is protected now by the structure of number itself. This conclusion is false, and the falseness of it is the entire subject of this essay; but one must begin by granting how reasonable the error is, and how lovely the dream from which it springs. The cryptographer dreams in numbers, and numbers do not bleed. That is the source of the dream’s beauty, and it is also, precisely, the source of its lie.

II. The key has a body

For the number, however pure in contemplation, must in use come down out of the heaven of abstraction and take up residence somewhere, and the somewhere is always a physical thing. A key that is merely contemplated protects nothing; to do its work it must be computed with, and to be computed with it must exist as a pattern of charge in the cells of a memory, as a configuration of voltages moving through the gates of a processor, as a sequence of operations that occupy time and consume power and warm the silicon and stir the air. The secret has a location. It is in this register at this instant; it is on this disk; it is in this chip; it is, at the last, in the memory of some human being who can recite it. And the moment the abstraction becomes a location, it becomes a target, for a location is a thing in the world, and things in the world may be observed, measured, disturbed, and seized.

This is the hinge on which everything turns, and it is worth stating with full force, because the whole romance of disembodied security depends on forgetting it. There is no such thing as using a secret without embodying it. The plaintext must, at some instant, exist in the clear, somewhere, in some physical medium, or it is of no use to its rightful reader either. The private key must, at the instant of signing or decrypting, be present in some circuit, or no signature is made and no message read. Mathematics can guarantee that the ciphertext reveals nothing; it cannot guarantee anything whatever about the chip in which the key resides while it does its work, for that chip is not a mathematical object but a physical one, governed not by the axioms of number theory but by the laws of physics — by thermodynamics, by electromagnetism, by the stubborn fact that every real computation is a physical process and every physical process radiates some trace of itself into the world around it. The cipher is abstract and the attack is physical, and they meet at the one unavoidable point where the abstract secret must wear a physical body in order to be of any use at all. To secure the mathematics and neglect the body is to lock the vault and leave the key glowing on the table; and the history of cryptographic attack, to which we now turn, is very largely the history of reading what the body of the secret could not help but emit.

III. The attacker breaks the matter, not the math

Consider, then, the catalogue of what the body betrays, for it is a catalogue that should be read by anyone tempted to believe that a sound cipher is a safe one. It was shown, with elegance and to general consternation, that the mere time a cryptographic computation takes can reveal the secret key: because the operations performed depend on the bits of the key, and different operations take different durations, an attacker who measures how long the machine takes to respond can, with patience and statistics, reconstruct the key one bit at a time, though the algorithm itself remain mathematically impeccable [5]. It was shown next that the power a chip draws while it computes is a still richer confession — that by recording the minute fluctuations in current consumption as a processor performs a private-key operation, and subjecting the traces to statistical analysis, one may extract the key from a device one holds in one’s hand, a technique so effective against the smartcards of the day that the entire industry was forced to redesign around it [6]. It had been shown, earlier still, that the electromagnetic radiation leaking from a video display could be captured at a distance and the screen’s contents reconstructed by an eavesdropper in a van across the street, so that what a man read in the supposed privacy of his office was legible to anyone with the right antenna — a discovery that gave its name to a whole governmental discipline of shielding [7].

And lest these seem the exhausted tricks of a former age, consider the most striking of all, and the most recent. It was demonstrated that the sound a computer makes — the faint high-pitched whine of its components vibrating as it works — carries enough information to extract a full four-thousand-and-ninety-six-bit private key from a standard encryption program, the recording made by nothing more exotic than an ordinary mobile telephone laid beside the machine, or a better microphone four metres away [8]. One should pause over the exquisite irony of the thing: the cipher in question is among the strongest in practical use, its mathematics entirely unbroken; and one of the very authors who first gave that cipher to the world is among those who showed that its key could be lifted out of the air, through the noise of a labouring laptop, while the mathematics stood serene and useless as a sealed door in a wall that has been walked around. To this acoustic confession the same work added that one might equally read the secret from the electrical potential of the machine’s chassis, obtained by the simple expedient of touching it with one’s bare hand. And there is a darker variant still, in which the attacker does not merely listen but interferes — inducing a fault in the computation, a glitch of voltage or a flipped bit, and reading the secret out of the erroneous result, for it was proven that a single faulty signature from certain widely-used schemes is sufficient to lay the entire private key bare [9].

And one must not imagine this catalogue a closed or exhausted list, for it is in the nature of the thing that it cannot be. Every physical computation has a physical footprint — it occupies time, it moves charge, it radiates fields, it warms its surroundings, it emits faint light and fainter sound — and any such footprint is, in principle, a channel down which the secret may flow to one ingenious enough to read it. The defender who silences the timing channel finds the power channel open; who flattens the power channel finds the electromagnetic; who shields the electromagnetic finds the acoustic, and after it the thermal, and after that perhaps the optical flicker of a status light dutifully blinking out the rhythm of the work. This is not a war that is won and concluded but an arms race without a final victory, because the leakage is not a flaw of any particular design that a better design might cure, but a property of physical computation as such. The secret, once embodied, cannot be made to do its work in perfect silence; it can only be made to whisper more quietly than the adversary can hear, and the adversary’s hearing improves.

The pattern across the whole catalogue is the thing to seize, for it is invariant and it is the heart of the matter. In not one of these attacks is the mathematics broken. The theorem holds. The problem remains hard. The cipher, considered as an object of pure thought, stands exactly as strong after the attack as before it. What gave way was never the mathematics; it was the matter in which the mathematics was made to live — the time, the power, the radiation, the sound, the very voltage of the chassis, all of them physical emanations of a physical process, none of them addressed by any proof about number. Security in the abstract is perfect and worthless. The war is fought in the concrete, where the secret has a body, and the body, doing its honest work, cannot help but speak.

IV. The root of trust is a physical thing you can hold, burn, or steal

To this predicament the modern age has fashioned an answer of great ingenuity, and the answer is worth examining closely, because it represents the best the discipline can do and because, examined closely, it confirms rather than refutes the thesis. If the danger is that the secret leaks from the ordinary, observable, interferable hardware of a general-purpose machine, then let us build a special piece of hardware whose one purpose is to keep secrets — a fortified enclave within the processor, a vault of silicon that holds the key and performs the sensitive computation inside itself, refusing to disclose the secret even to the operating system, even to the owner of the machine, even to one who has every administrative privilege the software can confer; and let this enclave further be able to attest, by a chain of cryptographic evidence rooted in a key burned into the chip at manufacture, that it is genuine and that it runs exactly the code it claims [10, 11, 12]. Here, it seems, the secret has at last been given a body strong enough to keep it: a tamper-resistant stronghold from which the leaking emanations of the ordinary machine have been sealed away.

But notice what has actually been accomplished, for it is not the abolition of the physical problem but its concentration. The trust has not been dissolved into mathematics; it has been poured into a thing — a particular chip, with a particular secret fused into its particular silicon — and a thing, however cunningly fortified, remains a physical object in a physical world, and physical objects can be attacked by physical means. The people who understand these devices best are the first to insist on the distinction that the marketing elides: tamper-resistant is an honest word, and tamper-proof is not. A celebrated cautionary note, written by engineers who had spent their careers opening supposedly unopenable hardware, set out a long and humbling litany of how the strongholds had fallen — to acid and to lasers, to careful abrasion and clever probing, to attackers patient and well-funded enough to peel the fortress open layer by layer and read the secret from the bared circuit [13]. Nor must one even breach the fortress to defeat it. It was shown that the secret, having been used, lingers in the ordinary memory of the machine as a fading pattern of charge that does not vanish when the power is cut but persists for seconds, longer if the chips are chilled — so that an attacker may cut the power, snatch the memory, and read out the key that the running system believed safe, defeating the leading disk-encryption products with no special equipment at all [14]. And the enclave itself, the very stronghold, was breached on its own ground: a transient-execution attack showed that the fortified processor’s own habit of guessing ahead at its work could be turned against it to spill the enclave’s sealed secrets and forge its attestations, the keys to the kingdom extracted through a flaw not in the vault’s lock but in the speculative machinery of the silicon beneath it [15]. The honest conclusion is not that trusted hardware is useless — it raises the cost of attack enormously, and that is a real and valuable thing — but that it relocates the secret into an object rather than removing the secret’s body, and that the object, given an adversary with time and money and physical access, is in the end a thing that can be held, frozen, glitched, abraded, and read. The honest claim is never the secret cannot be extracted. It is only, ever, the secret is expensive to extract.

V. Trust must bottom out in matter

If the stronghold can be opened, one is tempted to push the trust further down — to trust not the chip alone but the chain that produced it, to verify the silicon, to audit the design, to inspect the very tools of inspection. And here one meets the deepest result of all, stated long ago in a short and quietly devastating lecture by a master of the craft, which every architect of trustless systems ought to have committed to memory. Its argument was this: one cannot fully trust a program one did not write entirely oneself, for a malicious alteration might lurk in it; but neither can one trust the compiler that built the program, for the compiler might insert the malice; and one cannot escape by inspecting the compiler’s own source and recompiling it, for the compiler used to do that might itself be corrupt, and might reproduce the corruption invisibly while erasing every trace of it from the source — so that the betrayal lives not in any text a man can read but in the tools beneath the tools, propagating itself silently down the generations of machines [16]. The moral the author drew is the moral of this entire essay: the regress of trust does not terminate in a proof. You cannot verify your way to the bottom, because the bottom is not made of verifiable abstractions. The bottom is made of a physical artifact you did not fabricate and cannot fully inspect, and of the human beings who designed and built it.

The trusted enclave of the previous section is the perfect illustration, for its very mechanism of attestation makes the physical root explicit and then invites us to forget it. When the enclave proves that it is genuine, it does so by means of a key burned into the silicon at the moment of manufacture, and the chain of evidence it offers is believable only to one who trusts the manufacturer who burned that key — trusts that the manufacturer guarded the master secrets of its attestation infrastructure, that its fabrication line was not subverted, that the design it certified harboured no deliberate flaw and no careless one. To rely on the enclave’s word is therefore to relocate one’s trust onto a particular corporation, its particular vaults, its particular factories, and the particular human beings who run them. The cryptographic guarantee, chased to its origin, dissolves into a guarantee about the physical and institutional security of a chipmaker — which is to say, once more, a guarantee about matter and the hands that shape it, and not about number at all.

This is not a paradox to be dissolved by cleverness; it is a structural fact about trust, and it has a physical address. Beneath the application is the compiler; beneath the compiler is the operating system; beneath that the firmware; beneath that the processor; and the processor was laid out by engineers one did not supervise and fabricated in a foundry one has never seen, from designs and equipment and materials supplied by a chain of hands stretching back through the whole industrial world. Somewhere in that descent the auditable runs out and the simply-trusted begins, and the simply-trusted is not a theorem but a factory — a building, a process, a set of people, a supply chain of matter. There is always, at the foundation of every secure system however “trustless” it proclaims itself, an irreducible trusted party, and that party is physical: a fab in a particular country, a machine of a particular make, an engineer who laid out a particular block of silicon, a courier who carried a particular wafer. The trustless system has not abolished this root. It has only pushed it down, out of the protocol and into the matter, where it is harder to see and therefore easier to forget. To follow the chain of trust honestly all the way to its end is to arrive, every time, not at a proof but at atoms, and at the hands that arranged the atoms. The disembodied fortress, inspected to its foundations, is found to be standing on a floor of physical things made by people one has chosen, knowingly or not, to believe.

VI. The body as the last key, and the wrench

There remains the final embodiment, the one the whole apparatus exists to serve and the one it can least protect, which is the human keeper. For when the cipher is sound and the chip is hard and the supply chain is, against all odds, clean, the attacker who wants the secret does not despair; he simply redirects his attention to the one component of the system that was always made of flesh. The point has been made more memorably by a single cartoon than by any treatise: in the imagination of the security enthusiast, the villains confront the encrypted laptop and lament that they must build a million-dollar machine to crack its formidable cipher; in reality, they observe that the man knows the password, and propose instead to strike him with a five-dollar wrench until he tells it to them [18]. The joke is funny because it is the truth that the discipline most wishes to forget. The key in the head is reached through the head, and through the body that carries the head; and against this most ancient form of cryptanalysis no proof about number offers the slightest defence. The strongest cipher in the world protects a secret only up to the threshold of its keeper’s pain, or his love for those who can be threatened, or his simple weariness; and the keeper has a body, and bodies can be coerced.

It is worse, not better, than this, for the fashion of our age is to make the body itself the key — to unlock the secret with a fingerprint, a face, an iris, the geometry of a hand — and the body is the most treacherous key-store of all, for two reasons that ought to be far more widely understood than they are. The first is that a bodily credential, once compromised, cannot be revoked: a stolen password may be changed in an instant, but a man cannot change his fingerprints when an impression of them has been lifted, nor grow a new face when his old one has been captured, so that the breach of a biometric is not a temporary embarrassment but a permanent condition. The second is that the body can be compelled in ways the mind cannot: a man may, in many a jurisdiction, lawfully refuse to disclose the passphrase in his memory, invoking his right not to testify against himself, while that same law will permit his finger to be pressed to the sensor or his face to be held before the camera, the secret extracted from his body precisely because his body, unlike his mind, can be moved by other hands. The body is the last secret-store and the most coercible, and every chain of cryptographic trust, followed faithfully to its terminus, ends in a human being who can be deceived with a forgery, seduced with a bribe, broken with a threat, worn down with patience, or simply compelled with the lawful or unlawful application of force to the flesh. The fortress of proofs has, at its innermost keep, a person; and a person is not a theorem.

VII. What the physical means for the trustless world

Let us now bring this home to the achievements with which the series began, for the bearing is direct and it is the reason this essay had to be written. The game that needs no dealer, the file that can be truly owned and given, the keys we forge to relocate the power of the old intermediaries — every one of them, however immaculate its protocol and however elegant its cryptographic construction, rests in the end upon a private key, and a private key is neither more nor less than a physical secret with a location. It lives in a chip, or on a disk, or on a folded sheet of paper in a drawer, or in the perishable memory of a human being. The protocol that proclaims itself trustless has not, in truth, abolished the root of trust; it has concentrated that root into the custody of a secret, and made the security of the entire edifice depend, exactly and without remainder, on the physical security of that one secret. The man who holds the key holds everything; and to hold a key is to keep a physical object out of other hands, which is the oldest physical-security problem in the world, unchanged in its essence since the first treasure was buried and the first guard was posted over it.

And the custody is of a peculiarly unforgiving kind, harsher than the custody the old world demanded. The money that needs no bank made the private key into a bearer instrument of a purity the physical world had never quite managed: to hold the key is to hold the value, wholly and finally, and to lose the key — or to have it quietly taken — is to lose the value outright, with no registrar to petition, no account to be frozen and made whole, no authority anywhere empowered to reverse the loss [19]. The very abolition of the trusted intermediary that freed the holder from the bank’s permission stripped him also of the bank’s protection, and left him alone with a secret whose physical safekeeping has become the whole of his security and the whole of his recourse at once. The disintermediated world does not merely depend, as every world has, upon the physical custody of secrets; it raises the stakes of that custody to the absolute, having removed every human institution that once stood ready to soften the consequences of a key misplaced or a key stolen. What was a recoverable misfortune becomes a final one, and the burden falls back, undivided, upon the matter in which the secret is kept and the keeper who keeps it.

The conclusion follows with the force of arithmetic, and it is the conclusion the romance of digital security exists to deny: there is no security in the abstract. There is only security in some particular room, on some particular morning, around some particular secret that some particular keeper has not yet been made to surrender. The trust surface of any real system — the full set of things that must hold for the secret to remain secret — always, in the end, includes atoms: the silicon that computes, the wire that carries, the memory that retains, the room that shields, the body that remembers. A security analysis that stops at the mathematics has not finished; it has merely declared the interesting part out of scope and gone home before the war began. And the honest engineer, who knows all this, makes a different and a humbler claim than the salesman of fortresses. He does not say that the secret cannot be taken, for he has read the catalogue and he knows it can. He says only that he has made the taking of it expensive — costly in money, in time, in skill, in physical access, in risk of detection — and accountable, so that the taking leaves a trace, and bounded, so that the taking of one secret does not unravel all the others. Expensive, accountable, bounded: these are the true goods that security can deliver, and they are physical goods, won in the matter and not in the mathematics. Impossibility is not on the menu, and the man who promises it is either deceived or deceiving.

VIII. The discipline of the physical

If security bottoms out in matter, then the discipline of security must be, at its foundation, a discipline of matter, and its precepts follow directly from everything said above. The first and governing precept is to design as though the adversary already holds the device in his hands — to assume physical access, not to pray against it, for the whole literature of attack teaches that physical access is the condition under which secrets actually fall, and the standard texts of the engineering of secure systems are built upon exactly this unsentimental assumption [17]. From this first precept the rest descend. Minimise the secret, and minimise its life: the less of it there is, and the shorter the time it spends embodied in any vulnerable medium, the less there is for an attacker to seize and the narrower the window in which he may seize it; a key generated for one purpose and destroyed the moment its work is done cannot be read from a memory it no longer occupies. Refuse to rest the whole of the trust on any single physical root: split the secret across many bodies, so that no one chip, no one disk, no one person, no one room is the entire key, and the attacker is forced to compromise many places at once, in concert, before any of his labour bears fruit — a discipline of distribution that turns the irreducible physical root from a single point of catastrophic failure into a redundancy that must be defeated everywhere or it is defeated nowhere. Shield and isolate what truly must be kept: against the radiation that the screen and the wire emit, against the sound that the labouring components make, against the charge that lingers in the cooling memory, there are physical countermeasures — the shielded room, the air gap, the secret never written to a medium that remembers — and they are not paranoid extravagances but the rational responses of one who has read the catalogue and believes it.

And above all of these, governing them as a constitution governs its laws, stands the precept of honesty: name the physical root. Say, plainly and in the open, which chip, which room, which supply chain, which human keeper the security of the system finally rests upon, so that the trust which can never be eliminated may at least be located, examined, and guarded with eyes open. For the one truly unforgivable error in the engineering of secure things is not that a system has a physical root of trust — every system must — but that it pretends not to, and so leaves that root unnamed, and therefore unwatched, and therefore undefended, while the protocol above it is decorated with the word “trustless” as though the word were a wall. A trust surface unnamed is a trust surface unguarded. The first discipline of the physical, and the last, is simply to stop lying about the body of the secret — to admit that it has one, to say where it is, and to set a faithful guard over it.

IX. Coda: where the secret sleeps

The romance was beautiful, and like most beautiful romances it was a lie told in good faith. It held that the mind had at last built a fortress the body could not betray — that in the clean kingdom of number a secret might be kept by a theorem, beyond the reach of the wrench and the cold and the patient hands in the foundry. One understands the longing in it, for the physical world has always been the place where our keeping fails: where the lock is picked, the guard is bribed, the wall is scaled, the keeper is broken. To escape into mathematics, where nothing rusts and no one bleeds, was to dream of a security that asked nothing of the fallen world of matter. But the dream cannot be had, because a secret that is never embodied is a secret that is never used, and a secret that is used has a body, and a body can be touched. The fortress of proofs, walked all the way around, is found to be a chip in a room; and the room has a door, and the door has a keeper, and the keeper has a body, and the body can be reached.

This is not a counsel of despair but its opposite, for the worst insecurity is always the kind that believes itself secure, and the mind that knows where its secret sleeps can at least keep watch over the place. The reasoning intellect that built the dealerless game and the ownable file and the keys that move the world’s power has done real and admirable work, and the work stands; but it stands, as all such work must, upon a floor of physical things kept faithfully in the dark — upon silicon and shielding and the discipline of human keepers who have not been deceived or compelled. To build well, then, is to honour the body of the secret as carefully as one honours its mathematics: to make the matter as faithful as the proof, to name the place where the secret rests, to set over it a guard proportioned to what it protects, and to remember always, beneath every theorem and every protocol and every confident invocation of the trustless, the single physical fact on which the whole of it depends — that somewhere, on some particular machine, in some particular room, a small and silent pattern of matter is being kept out of the wrong hands, and that this keeping, and not the mathematics, is where security has always, in the end, been won or lost.


References

[1] C. E. Shannon. “Communication Theory of Secrecy Systems.” Bell System Technical Journal, 28(4):656–715, 1949.

[2] A. Kerckhoffs. “La cryptographie militaire.” Journal des sciences militaires, IX:5–38 (January), 161–191 (February), 1883.

[3] W. Diffie and M. E. Hellman. “New Directions in Cryptography.” IEEE Transactions on Information Theory, 22(6):644–654, 1976.

[4] R. L. Rivest, A. Shamir, and L. Adleman. “A Method for Obtaining Digital Signatures and Public-Key Cryptosystems.” Communications of the ACM, 21(2):120–126, 1978.

[5] P. C. Kocher. “Timing Attacks on Implementations of Diffie-Hellman, RSA, DSS, and Other Systems.” In Advances in Cryptology — CRYPTO ‘96, LNCS 1109, pp. 104–113. Springer, 1996.

[6] P. Kocher, J. Jaffe, and B. Jun. “Differential Power Analysis.” In Advances in Cryptology — CRYPTO ‘99, LNCS 1666, pp. 388–397. Springer, 1999.

[7] W. van Eck. “Electromagnetic Radiation from Video Display Units: An Eavesdropping Risk?” Computers & Security, 4(4):269–286, 1985.

[8] D. Genkin, A. Shamir, and E. Tromer. “RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis.” In Advances in Cryptology — CRYPTO 2014, Part I, LNCS 8616, pp. 444–461. Springer, 2014.

[9] D. Boneh, R. A. DeMillo, and R. J. Lipton. “On the Importance of Checking Cryptographic Protocols for Faults.” In Advances in Cryptology — EUROCRYPT ‘97, LNCS 1233, pp. 37–51. Springer, 1997.

[10] F. McKeen, I. Alexandrovich, A. Berenzon, C. V. Rozas, H. Shafi, V. Shanbhogue, and U. R. Savagaonkar. “Innovative Instructions and Software Model for Isolated Execution.” In Proc. 2nd International Workshop on Hardware and Architectural Support for Security and Privacy (HASP ‘13). ACM, 2013.

[11] I. Anati, S. Gueron, S. P. Johnson, and V. R. Scarlata. “Innovative Technology for CPU Based Attestation and Sealing.” In Proc. 2nd International Workshop on Hardware and Architectural Support for Security and Privacy (HASP ‘13). ACM, 2013.

[12] V. Costan and S. Devadas. “Intel SGX Explained.” Cryptology ePrint Archive, Report 2016/086, 2016.

[13] R. Anderson and M. Kuhn. “Tamper Resistance — a Cautionary Note.” In Proc. 2nd USENIX Workshop on Electronic Commerce, pp. 1–11, 1996.

[14] J. A. Halderman, S. D. Schoen, N. Heninger, W. Clarkson, W. Paul, J. A. Calandrino, A. J. Feldman, J. Appelbaum, and E. W. Felten. “Lest We Remember: Cold Boot Attacks on Encryption Keys.” In Proc. 17th USENIX Security Symposium, pp. 45–58, 2008.

[15] J. Van Bulck, M. Minkin, O. Weisse, D. Genkin, B. Kasikci, F. Piessens, M. Silberstein, T. F. Wenisch, Y. Yarom, and R. Strackx. “Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order Execution.” In Proc. 27th USENIX Security Symposium, pp. 991–1008, 2018.

[16] K. Thompson. “Reflections on Trusting Trust.” Communications of the ACM, 27(8):761–763, 1984.

[17] R. J. Anderson. Security Engineering: A Guide to Building Dependable Distributed Systems. Wiley, 2001.

[18] R. Munroe. “Security.” xkcd, no. 538. https://xkcd.com/538/

[19] S. Nakamoto. “Bitcoin: A Peer-to-Peer Electronic Cash System.” Self-published white paper, 2008.


← Back to Substack Archive