Skip to content

Comment on Ask HN: Idea for privacy-enhanced web appsparent

Comments

Let me try to explain the idea with a very concrete example (it should be then clear why EC2 would not accomplish the same thing):

Imagine a company called Online-Spreadsheets.com that makes a spreadsheet as a web application.

Suppose a big corporation, Big-Car-Company, would like its employees to use the web app provided Online-Spreadsheets.com, but they can't bring themselves to trust Online-Spreadsheets.com with their financial data.

That's where I come in. My company, say, Trusted-Web-App-Systems, would make a program called TrustEnv. When you run TrustEnv on a server, it creates a trusted environment into which you can install a web app.

I give TrustEnv to Online-Spreadsheets.com for free. Online-Spreadsheets.com installs TrustEnv on one of its servers; a trusted environment is created. They then install their web app into this trusted environment.

Online-Spreadsheets.com cannot easily extract any customer data being processed within this trusted environment, despite the fact that it's running on their own server.

Big-Car-Company can now connect to Online-Spreadsheets.com's server (the one running TrustEnv) and use the spreadsheet web app with assurance that their financial data is not easily copied, leaked, or spied on.

I would charge a fee to corporate customers like Big-Car-Company to use web sites protected with TrustEnv. My job would be to write TrustEnv, to convince corporate customers that they need it, and to convince web app providers to install TrustEnv because there is corporate demand for it. I would not run any web apps myself.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.