Glassbox

Confidential computing asks you to trust a black box. This one you can see into.

Some apps on Flare handle your private data inside a sealed chip, where nobody can read it, not even the people running the server. That's the promise. Glassbox is how you find out whether it's true.

The claim

An app tells you your data was handled inside a sealed chip, isolated from the machine around it.

The proof

The chip signs a certificate describing itself and the exact code it was running.

The check

Glassbox reads that certificate, then asks Flare whether the code is the approved one.

Advanced

Nothing you paste here goes anywhere. Google's root certificate is built into the page, the checking happens on your own machine, and Flare's registry is read straight from the blockchain.

Result

Load a certificate above, then press Check it.

What this doesn't prove

Reading the result

Not authentic. A signature or a certificate check failed. The certificate is fake and proves nothing at all.

Authentic, not accepted. The certificate is genuine, but either it has expired or the code it describes isn't the code you were expecting. An out-of-date certificate isn't a forgery; it was true when it was issued, it just isn't evidence about that machine today.

The second case is the interesting one, because a real sealed chip running the wrong code produces a certificate that looks flawless. The way to catch it is to compare the code against what Flare recorded on-chain, which is the check this page adds.

Certificate contents

  

Built for Flare Summer Signal. Open source, MIT. Set in Satoshi and Anton. Flare's own display face is Manuka.