
Mac Admins Podcast Episode 370: Jedda Wignall on Managed Device Attestation
8 snips
Jul 2, 2024 Jedda Wignall, an expert in Managed Device Attestation and a vital contributor to the Mac Admins community, dives deep into trust in device management. He explains the intricacies of managed device attestation and its critical role in maintaining security through trust protocols and secure enclaves. The discussion covers Apple's collaboration with Google on device identity management and addresses the challenges faced during implementation. Jedda also shares insights on recent updates impacting security models, emphasizing the importance of rigorous device management.
AI Snips
Chapters
Transcript
Episode notes
VM Spoofing and Device Enrollment
- A Duo Security document in 2018 revealed how VMs could spoof enrolled devices, highlighting a security risk.
- This vulnerability allowed unauthorized access, emphasizing the need for stronger device trust.
VMs and Attestation
- Virtual machines cannot undergo managed device attestation.
- They lack a secure enclave, a critical component for the attestation process.
Google and the Genesis of Device Attestation
- Google, facing challenges in attesting Apple devices within its BeyondCorp program, collaborated with Apple.
- This led to Device Attest 01, a specification enabling Apple device attestation using ACME servers.
