3 ms·
> seeing cracks that allows a virtualised system to break out to the is scary Hate to break this to you, but it's been shown time and time again that due to ho
by wfn 10y ago
> seeing cracks that allows a virtualised system to break out to the is scary
Hate to break this to you, but it's been shown time and time again that due to how caching and CPU pipelining works in modern processors, any "isolation" including full-on VM which is not "physical isolation" is leaky: https://pdfs.semanticscholar.org/e544/00824814fed2ef52bb84151b2fc04c863e99.pdf https://pdfs.semanticscholar.org/e544/00824814fed2ef52bb8415... (overview of attacks)
Here is a particularly nice paper (proper methodology, well-explained intro, etc.) showing one example (a more or less regular cache timing attack, but with actual private info extraction from host, etc.): https://arxiv.org/abs/1702.08719 https://arxiv.org/abs/1702.08719 - these come up several times a year for various VMs, etc.
- edejong 10y agoAnd even physical separation might not be enough due to EM radiation and power usage.
- jnwatson 10y agoThose problems can and have been resolved with appropriate power filters and shielding.
- jacquesm 10y agoIt is many orders of magnitude harder to get data from a computer that is in the vicinity than from one VM on the same machine to the host or another VM on that same machine.
- edejong 10y agoI agree, but VM security and exploits also get orders of magnitude more attention. Besides, physical separation does not just apply to the data-center. Consider EM radiation from phones and laptops.