Your Confidential Cloud Data Isn’t Secure. The Fix Might Not Exist.
Confidential computing promises to protect data in use by using hardware-based secure enclaves. But the root of trustβthe attestation mechanism that proves your code is running securelyβis implemented in opaque, unfixable firmware. Researchers have shown these systems can be spoofed, and because the flaw is in the hardware, no software patch can fix it. You’re trusting a black box that has already been broken.