Privacy you can verify. For any chain, any application, any builder.

You have spent the week getting hardware to prove things about itself. Go find a person and ask them to just tell you something, no proof required. It will feel almost reckless. It is also, most days, still the better way to live.

ALT Will Ferrell Lol GIF

8
6
80
7,515
1/ A compliance report tells you what was true on the day the auditor visited. That is not a criticism. It is the honest shape of the instrument, and most of enterprise security policy is built on instruments shaped exactly like this.
7
21
107
9,491
2/ Certifications are periodic, sampled rather than exhaustive, backward looking by the time you read them, and commissioned and paid for by the company being certified. Everyone in the room knows this. It rarely makes it into the actual conversation.
2
2
29
1,238
3/ Attestation is not a replacement for that process, and nobody serious is claiming it should be. It is the one layer that gets checked at the moment data actually moves, by the party receiving it, rather than reviewed once a year by someone the other side is paying.
2
26
828
Discord trivia tonight, 21:00 CET Fitting, since it's the one night a week we ask you to prove you know something instead of asking a piece of hardware to prove it for us. discord.gg/62zG63WJ6v
4
11
82
8,799
1/ Decoded: the handshake Last week we published the guest list, everything a confidential system trusts before it does anything at all. Publishing a list is the easy part. The actual problem is proving to a total stranger that the list matches what is running right now, not what was running when the diagram was drawn.
5
17
105
7,553
2/ When a TEE starts, the hardware measures the exact code and configuration and produces a quote, a report signed by a key that only genuine hardware holds, burned in at manufacture. A verifier checks that signature back to the chipmaker, then compares the measurement inside the quote to the hash of the code that is supposed to be running. A match means specific, known code produced that quote inside real hardware. Not a description of it, a check of it.
1
2
32
1,499
3/ That is remote attestation. It turns "trust me, that is what is deployed" into something a machine confirms before a single byte of data moves. A guest list you can read is good. A guest list you can verify against the door itself is the actual point.
2
29
807
Oasis 🌹 retweeted
I had the great honor and pleasure of sitting down with @JeffDean for his first public talk since leaving Google, where he spent an extraordinary 27 years. Few people have shaped modern computing and AI as profoundly - from MapReduce and Bigtable to TensorFlow, Mixture-of-Experts, TPUs, and Gemini. Our conversation covered some of the biggest questions shaping the future of AI: • How do you recognize a foundational idea before everyone else does? • How do you choose a research problem worth spending 5 years on? • What can coding teach us about building better reasoning models? • What might recursive self-improvement (RSI) actually look like? • What happens when the scientific discovery loop itself becomes increasingly automated? (and how is Jeff’s new startup going to contribute in this space?) • As AI becomes increasingly autonomous, how do we keep it safe and secure? • What should the next generation of researchers be working on? Here are some key insights and highlights for anyone building the future of AI. 🧵1/8
9
20
134
52,551
It is Monday, which means every message in every inbox is currently unverified. Sender claims it is urgent. Nobody can check that against reality until at least Wednesday. We call this a trust assumption. Everyone else calls it email.
3
10
95
8,797
Food for thought: a system nobody can audit is not simple, it is just quiet. The complexity did not go anywhere. It moved somewhere you are not allowed to look.
3
20
124
9,535
Five days of arguing with systems that do precisely what you asked and nothing you meant. The weekend is full of people who do the opposite, which is annoying in a much more nourishing way. Go and be misunderstood by somebody who cares.
3
10
97
9,544
1/ There are two kinds of privacy commitment and they get written in the same font. One is we will not look at your data. The other is we cannot. They read almost identically in a sales deck and they behave nothing alike in year three.
5
17
93
10,289
2/ We won't is a policy. It depends on the current leadership, the current incentives, the current jurisdiction and the current owner, all four of which are more temporary than the data you handed over.
1
2
28
2,045
3/ We can't is a property of the architecture. It survives acquisitions, subpoenas, a change of strategy and a bad quarter, because nobody involved has the capability in the first place. Ask which one you are being sold. The answer is usually available, just not volunteered.
2
24
961
Builders, a question if we may: which part of your system currently works only because everyone involved agreed to behave? Not the part that would be embarrassing if it broke, but he part that would be impossible to prove had broken at all.
4
11
86
9,509
1/ Decoded: the guest list. Every secure system has a list of things it trusts completely. Most descriptions of secure systems do not include the list, which is a bit like being told the party is exclusive without being told who is already inside.
2
14
83
9,100
2/ For confidential compute, the list is roughly: the processor and its manufacturer, the firmware and microcode underneath, the code running inside the enclave, the build process that produced that code, and whoever signs the measurement you check it against.
1
1
31
1,780
3/ Attestation does not empty that list. It publishes it, and lets you verify that what is running is what was published. A short list you can read beats an empty list somebody described to you over a call.
1
27
867