4 ms·
In terms of a threat model, it includes any machine which acts as a hypervisor and as the old saying goes: If you don't trust the hypervisor, how can you trust
by xrorre 10y ago
In terms of a threat model, it includes any machine which acts as a hypervisor and as the old saying goes: If you don't trust the hypervisor, how can you trust any machine running in that hypervisor?
Antilogging is but one tiny component of defense in depth and worth investigating if you're doing anything interesting with a computer. 'Doing something interesting' although is not to be misconstrued as 'doing something bad'. It just means how can any meaningful work get done if low hanging fruit like keystrokes can (and are) being siphoned off?
It helps to see how machines are actually being compromised like this...I've seen it on my machine and sometimes entire office building are being siphoned like this. I typically report this, but I would much rather get to the root as to how it's possible in the first place :(
- geofft 10y agoHuh, that doesn't match my intuitions at all (at least on UNIX-based OSes), so I'm pretty surprised and want to re-adjust my expectations. You're saying that you regularly see compromised machines that are running kernel-mode keyloggers, but only keyloggers? What has the attack vector been, and do you know where they keys are being logged to?