the checker/inside the enclave/the census

Glassbox

Confidential computing asks you to trust a black box. This one you can see into.

Some apps on Flare handle your private data inside a sealed chip, where nobody can read it, not even the people running the server. That's the promise. Glassbox is how you find out whether it's true.

The claim

An app tells you your data was handled inside a sealed chip, isolated from the machine around it.

The proof

The chip signs a certificate describing itself and the exact code it was running.

The check

Glassbox reads that certificate, then asks Flare whether the code is the approved one.

94% of the enclaves registered on Flare are simulators. See the census of every one of them, and which run real hardware.
Advanced

Nothing you paste here goes anywhere. Google's root certificate is built into the page, the checking happens on your own machine, and Flare's registry is read straight from the blockchain.

Result

Load a certificate above, then press Check it.

What this doesn't prove

Reading the result

Not authentic. A signature or a certificate check failed. The certificate is fake and proves nothing at all.

Authentic, not accepted. The certificate is genuine, but either it has expired or the code it describes isn't the code you were expecting. An out-of-date certificate isn't a forgery; it was true when it was issued, it just isn't evidence about that machine today.

The second case is the interesting one, because a real sealed chip running the wrong code produces a certificate that looks flawless. The way to catch it is to compare the code against what Flare recorded on-chain, which is the check this page adds.

What is being verified?

Checking a certificate only matters if something is running behind it. The other half of this project is a Flare compute extension that prices a private portfolio against live oracle feeds inside the enclave and answers one question, disclosing nothing else. Here is a real request and what came back.

Look inside the enclave →

How common is any of this?

That's one certificate. The same question can be asked of every app on Flare at once: which of them have registered real sealed hardware, and which are running a simulator? Right now it's 18 registrations out of 308.

See the census →

Certificate contents

  

Built for Flare Summer Signal. Open source, MIT. Also here: the TEE census, every enclave registered on Flare and which run real hardware. Set in Satoshi and Anton. Flare's own display face is Manuka.