Zum Hauptinhalt springen
Windows Tipps & SecurityApple soll Rückkehr ins Servergeschäft planen - Swiss IT Magazine(18.09.2026 um 07:04 Uhr)
Linux Tipps & HardeningSecurity: Denial of Service in nodejs-undici (Fedora)(18.09.2026 um 08:45 Uhr)
Linux Tipps & HardeningSecurity: Zwei Probleme in gnatcoll (Fedora)(18.09.2026 um 08:45 Uhr)
Linux Tipps & HardeningSecurity: Denial of Service in nginx-mod-fancyindex (Fedora)(18.09.2026 um 08:48 Uhr)
Linux Tipps & HardeningSecurity: Denial of Service in nginx-mod-brotli (Fedora)(18.09.2026 um 08:48 Uhr)
Linux Tipps & HardeningSecurity: Denial of Service in nginx (Fedora)(18.09.2026 um 08:48 Uhr)
Windows Tipps & SecurityApple soll Rückkehr ins Servergeschäft planen - Swiss IT Magazine(18.09.2026 um 07:04 Uhr)
Linux Tipps & HardeningSecurity: Denial of Service in nodejs-undici (Fedora)(18.09.2026 um 08:45 Uhr)
Linux Tipps & HardeningSecurity: Zwei Probleme in gnatcoll (Fedora)(18.09.2026 um 08:45 Uhr)
Linux Tipps & HardeningSecurity: Denial of Service in nginx-mod-fancyindex (Fedora)(18.09.2026 um 08:48 Uhr)
Linux Tipps & HardeningSecurity: Denial of Service in nginx-mod-brotli (Fedora)(18.09.2026 um 08:48 Uhr)
Linux Tipps & HardeningSecurity: Denial of Service in nginx (Fedora)(18.09.2026 um 08:48 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Black Hat Europe 2025 | Bootstrapping Trust: From Isolated Build Machines to Enclaved CI Pipelines

Author: Black Hat - Bewertung: 2x - Views:16

This session presents a production-ready approach to securing CI build pipelines against compromised infrastructure by anchoring trust in a physically isolated build machine and leveraging enclave-based builders. The isolated machine compiles and signs a minimal enclave image, which becomes the only entity allowed to build software artifacts in the cloud. The builder enclave image runs inside AWS Nitro Enclaves and enforces strict policy checks such as requiring signed commit hashes before proceeding. Remote attestation is used to verify the AWS Nitro enclave's (the builder) integrity by an Intel SGX enclave verifier before provisioning the build secret, with the SGX enclave serving as a root of trust by encrypting its database with the processor's sealing key.

We'll detail the threat model, including attackers with SSH or root on CI runners, and walk through a complete enclave build pipeline, showing how trust is rooted in the isolated, air-gapped machine and propagated via the SGX enclave to the Nitro enclave builder. The session includes a demo of a real-world implementation that protects production infrastructure from build tampering and secret exfiltration, even under active adversary conditions.

Attendees will learn how to design CI pipelines with isolation guarantees similar to air gapped machines but with the build and deployment velocity they are used to in modern cloud environments, integrate enclave attestation into automated builds, and establish a root of trust for critical workloads.

By:
Ben Liderman | System Architect, Fireblocks
Maayan Keshet | System Architect, Fireblocks

https://blackhat.com/eu-25/briefings/schedule/?#bootstrapping-trust-from-isolated-build-machines-to-enclaved-ci-pipelines-49023

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Black Hat Europe 2025 | Bootstrapping Trust: From Isolated Build Machines to Enclaved CI Pipelines

Thematisch verwandte Begriffe: Black, Europe, 2025, Bootstrapping · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
News ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

↗ Original-Quelle