(no title)
hamishwhc | 2 years ago
Also interesting that its implied in the explainer that attesters are just HTTP endpoint dealing with “billion-qps” traffic. Again, point above, but also how can we trust any attester to not use the (completely unobfuscated) information the user agent is sending them?
I guarantee that big websites will host their own attesters, only allow use of their attester, and require attestation for every request, allowing them to fingerprint every single user.
andersa|2 years ago
You can't run your own attester - these are implemented by the companies who provide the hardware, such as Microsoft or Apple.
maxloh|2 years ago