Second @second.tech · May 22

2/ Intel SGX was a dead end. AWS Nitro Enclaves worked but needed excessive custom plumbing. Azure's confidential VMs seemed to be the sweet spot. An AMD SEV-SNP runs Barkd unmodified—the CPU encrypts every page of guest memory so the hypervisor only sees ciphertext.

1 likes 1 replies

?

Replies

Second · May 22

3/ That silicon is sold bare-metal too. A dedicated provider could rack these and offer locked-down Barkd instances with no SSH and full boot-chain attestation. You'd get the convenience of a hosted wallet while minimizing trust in the host. Full writeup: blog.second.tech/running-bark...