Implementation · Tinfoil model identity (Modelwrap)
Inherits attacks on the underlying TEEs
On this page
Evidence scope
Critical when model identity must hold against an operator with physical access to an affected host. Tinfoil documents physical attacks as an enclave limitation 2. These are hardware-class demonstrations, not a published break of Modelwrap or Tinfoil's deployed verification chain.
Tinfoil's model commitment and boot-time GPU check depend on the CPU attestation 3. The TEE findings distinguish Intel TDX forgery on DDR5, AMD SEV-SNP forgery on DDR4 in Battering RAM, and software-only RMPocalypse on platforms lacking AMD's fixes 6 7 8 9. TEE.fail recovered a guest OpenSSL key on AMD, not an AMD attestation key 6. Its GPU relay demonstration used an H100 with forged TDX evidence; it does not establish the same result for Tinfoil's H200 or B200 configurations 2 6.
Response
Tinfoil acknowledges the physical-access boundary. The TEE.fail authors report that Intel and AMD treat interposer attacks as outside their threat models and recommend physically secure servers 2 6. AMD reports firmware fixes for RMPocalypse 9.