# Flashwares ii: end-to-end useful enclave in Gramine/Python; intro to Controlled Channel attacks

**URL:** https://collective.flashbots.net/t/flashwares-ii-end-to-end-useful-enclave-in-gramine-python-intro-to-controlled-channel-attacks/3432
**Category:** TEE - Trusted Execution Environment
**Tags:** flashwares
**Created:** [May 20, 2024, 4:36pm UTC](https://collective.flashbots.net/t/flashwares-ii-end-to-end-useful-enclave-in-gramine-python-intro-to-controlled-channel-attacks/3432 "2024-05-20T16:36:12Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![socrates1024](https://collective.flashbots.net/user_avatar/collective.flashbots.net/socrates1024/32/1622_2.png) [@socrates1024](https://collective.flashbots.net/u/socrates1024)
#### Post date: [May 20, 2024, 4:36pm UTC](https://collective.flashbots.net/t/flashwares-ii-end-to-end-useful-enclave-in-gramine-python-intro-to-controlled-channel-attacks/3432/1 "2024-05-20T16:36:12Z")

</div>

This week I’ll present the second stream in the “flashwares” series. We’ll get all the way through an end-to-end useful example, then we’ll look at a first “controlled channel” attack.

Time: Tuesday, May 21 2024, 7pm UTC (2pm central us)

[![](https://collective.flashbots.net/uploads/default/original/2X/d/d67c202fa2c32e2d5faac9ff14ca96589e6992fe.jpeg "Flashwares II: Andrew Miller: Useful enclave in Gramine/Python; into to Controlled Channel attacks") ](https://www.youtube.com/watch?v=eUyFUVRessg)

I’ve prepped a couple demos and some explanation. [(slides)](https://docs.google.com/presentation/d/14kYPs_NMNZgc_90xF5HeYrFjgh0GdMZid4ANoHAm0_U/edit?usp=sharing)

First I want to get all the way through an end-to-end useful application in Gramine. We’ll use python for variety. We can write a script that sanitizes a document, or that generates a cryptography trusted setup. Completing the example requires us to deal with remote attestation and document a reproducible build process. We’ll walk through this code example: [GitHub - amiller/gramine-rsademo](https://github.com/amiller/gramine-rsademo)

To steer the topic towards security, I’ll introduce “Controlled Channel attacks” and how to think like a hypervisor or kernel and exploit an enclave. More specifically, we’ll add “spicy printfs” to the untrusted code in Gramine that they use for encrypted files. [python example that opens encrypted file. printf statements on 'pwrit… · amiller/gramine@4763624 · GitHub](https://github.com/amiller/gramine/commit/476362)
