| ▲ | coffe2mug 13 hours ago | |||||||||||||||||||||||||
article poorly written (may be by AI). > generate a key that’s stored in this fortress. It refers to the private key that is resident inside SecureEnclave. (During manufacturing) See further. Dont just read one or two lines. “The attacker can’t steal the private key from the device because the TPM / Secure Enclave will not release it. That is the core protection here,” Scott Helme, a researcher and founder of Report URI who blogged about the new protections on Tuesday, told Ars. “The attacker can steal the cookie, but they can’t answer a DBSC challenge by signing it with the private key, which is still safe on your device.” Read https://support.apple.com/en-gb/guide/security/sec59b0b31ff/... | ||||||||||||||||||||||||||
| ▲ | maratc 12 hours ago | parent [-] | |||||||||||||||||||||||||
I don't think it matters whether Chrome can add keys to TPM/Secure Enclave (as the article argues) or if it can only read the keys already in TPM/Secure Enclave (as you argue). In my understanding: both ways the key (either new or existing) could be attributed to the hardware owner, and not even an OS reinstall will help. Hence, my question. | ||||||||||||||||||||||||||
| ||||||||||||||||||||||||||