I’ve been exploring how remote attestation works and wanted to understand it more deeply, so I built a simple prover–verifier system in Python. It uses TPM-style PCR hash extension, nonces for freshness, and Docker to simulate real-world isolation. The verifier has a web UI where you can upload files to define trusted state, and the prover measures those files and submits a signed quote.
It’s not production-grade, but I’d love feedback if you’re into systems security or want to learn a bit about how attestation works under the hood.