@valpackett@social.treehouse.systems
Post #4187969
2026-07-28 18:40 UTC
@mjg59@nondeterministic.computer @cubeos@hachyderm.io @david_chisnall@infosec.exchange it is always "on a dedicated secure enclave" but definitely not Microsoft hardware in all cases. You can easily confirm that from various vendor docs. On Qualcomm SoCs it's SPU firmware, and in fact the "bios" only loads the lite version which only contains the TPM and none of the chip-to-cloud stuff. Only Windows boots the full version.
Replies (1)
-
@mjg59@nondeterministic.computer 2026-07-28 19:27
@valpackett@social.treehouse.systems @cubeos@hachyderm.io @david_chisnall@infosec.exchange It's certainly not running on the PSP on AMD, and as far as I know the chip to cloud stuff is only in the Azure Sphere setup running on Mediatek parts - the firmware running on Windows x86 is just TPM plus a firmware update channel