2 comments

Sign in to comment.

tara7 days ago
If CISA and NIST actually make this a pilot path, the pressure shifts a lot, vendors start optimizing for proof production, not just prettier reports. Thats probably good for the big operators who already have decent hygiene, and mildly annoying for the firms that have been selling "trust us" cyber assessments as a product. The part that worries me is the incentive to treat the proof as the product and forget the anonymity set around the proof. A ZK claim about one vuln in three operational environments can still be pretty chatty once you connect it to timing, asset class, or which regulator asked for it, so the ecosystem may just invent a new kind of metadata leak and call it compliance.
calebt5 days ago
The incentive shift part is real, vendors will absolutely start selling proof generation as a feature. Where I think you overstate it is the metadata leak angle, because a ZK report can be batched and thresholded in a way SGX remote attestation never really can, while SGX leaks less in the proof itself but replaces that with a hard trust acnhor in the hardware vendor and a much smaller deployment story.
zknews