Comment by KaiserPro

19 hours ago

Also to your point: "can't we just encrypt it?"

Its someone else's computer. The TPM is controlled by someone else. You can't really process on a machine that has a compromised urandom/TPM

Also the bigger issue is having all your access revoked over night. Thats the bigger fear.

> You can't really process on a machine that has a compromised urandom/TPM

Naive question: does zero knowledge proof solutions help with this?

  • If you can process your stuff inside a zero knowledge wrapper then yeah. But most things can't be done like that sadly.

Exactly - it's about availability. If someone with remote access could knock out your business operations, how long would it take to adapt? How much economic cost could that incur, perhaps at a critical time?

What? Storing encrypted data doesn’t mean you have to encrypt it on hardware you don’t own