5 ms·
"Retpoline ... modifies programs to ensure that execution cannot be influenced by an attacker. With Retpoline, we could protect our infrastructure at compile-ti
by jaflo 9y ago
"Retpoline ... modifies programs to ensure that execution cannot be influenced by an attacker. With Retpoline, we could protect our infrastructure at compile-time, with no source-code modifications"
I am confused, doesn't this mean that Retpoline needs to sit in the compiler and won't protect from already-compiled binaries?
- itcmcgrath 9y agoYes. We deploy new code binaries all the time so it's not a big deal.
- hhw 9y agoThat was my question also. How could they guarantee that nobody else using a VM on the same physical machine isn't using binaries compiled elsewhere?
- puzzle 9y agoGoogle doesn't run VMs. Or, rather, even VMs that make up GCE are actually running in containers. From the Borg paper: https://pdos.csail.mit.edu/6.824/papers/borg.pdf https://pdos.csail.mit.edu/6.824/papers/borg.pdf VMs and security sandboxing techniques are used to run external software by Google’s AppEngine (GAE) [38] and Google Compute Engine (GCE). We run each hosted VM in a KVM process [54] that runs as a Borg task. There might be a few machines here and there running actual VMs on bare metal, but those are going to be very special cases. Using Infrastore, it's easy to find which teams are running which containers whose binaries were built before the new compiler defaults. https://github.com/kubernetes/kubernetes/issues/44095 https://github.com/kubernetes/kubernetes/issues/44095
- cthalupa 9y agoI don't understand how you think that answers his question, as being in a container wouldn't magically add any more protections against these exploits than being in just a KVM VM. I'm also not sure that "Borg task" means it's in a container, vs. just being something scheduled by Borg, but it isn't particularly important either way. If the question is 'How do they guarantee their customers aren't using bad binaries', the answer is they don't, and has nothing to do with VMs vs VMs in containers, etc.
- puzzle 9y agoI should have been clearer: their external customers can and will use bad binaries inside their VMs, but everything else, especially anything at the boundaries between VMs, will not: it will have the appropriate mitigations in place. Running a VM in a Borg task (container) does not add extra security in this case, but it does help with auditing and catching the snowflakes and stragglers that invariably end up taking a disproportionate amount of time with changes like this. That kind of auditing can be easily done organization-wide, instead of having every team reinvent the wheel their own way.
- foota 9y agoIt's my understanding that Spectre needs to share some address space with the victim, which isn't the case on containers, other than the host address space?
- ithkuil 9y agoYou just need a shared cache.
- foota 9y agoI'm not understanding, isn't a shared cache exactly the problem here?
- cthalupa 9y agoYou can share a cache on a physical CPU without having shared address space. KVM virtual machines making use of Extended Page Tables or Nested Page Tables do not share an address space with their host or other guests, however, they are susceptible to Spectre v2, for example. (This was the PZ PoC for variant 2)
- ithkuil 9y agoyes, I meant that to suffer from spectre you just need a shared cache; it's not necessary to share address space. It follows from what a cache is. You have a large set of numbers (memory addresses) mapping into a smaller set of numbers (cache lines); my necessity there will be a collision. The mapping is deterministic and you can recover information by looking at these clashes. Some intel high end CPUs have a feature called CAT which was designed to avoid that different workloads interfere too much by stomping on each other's cache lines, but I think it's meant mostly as a performance feature not a security feature (although there is some research about how to use it to defend from cache-based side channels, see http://palms.ee.princeton.edu/system/files/CATalyst_vfinal_correct.pdf http://palms.ee.princeton.edu/system/files/CATalyst_vfinal_c... and https://arxiv.org/pdf/1708.09538.pdf https://arxiv.org/pdf/1708.09538.pdf). Another possible approach is to make it harder to predict the mapping between a physical address (or an address delta) and a cache line. I don't know if using a cryptographic-grade mapping for hardware cache would be even remotely feasible nor whether it would actually solve the problem of information leak.
- cthalupa 9y agoThey don't, but it doesn't matter. Something compiled with retpoline is resilient from it's execution being impacted. Once KVM is recompiled with retpoline, guests cannot attack it via spectre variant 2, and as such, cannot attack other guests. The hypervisor being compiled with retpoline, however, does nothing to protect from intra-guest attacks - if you have untrusted code running in your VM, and you don't have IBRS and the other microcode features on, or your sensitive apps compiled with retpoline, you are still vulnerable internally. Just not from other guests
- cm2187 9y agoEffectively both Linux and Windows Server need to be fully recompiled. Hope someone hasn’t lost some source code. I am not super familiar with google’s offering but I suspect they don’t just offer VMs. Anything that runs in a shared infrastructure (serverless design/websites hosting) runs on top of a Linux box I presume. Google would need to get those Linux binaries recompiled too, not just the hypervisor.
- dx034 9y agoI'm pretty sure that Microsoft can easily recompile Windows. Probably even Windows 95 with some prep time.
- cm2187 9y agoA hack they used in a recent update (I believe for the equation editor) suggests that's probably not the case.
- joshuamorton 9y agoI believe that the equation editor was third party coffee to which Ms never had the source code.
- cm2187 9y agoThe point is they can’t recompile it.
- boulos 9y agoDisclosure: I work on Google Cloud. We've already patched the host (for a long while now). You can also recompile your binaries in your guest, and/or get an updated kernel. retpoline performs much better than the brute force hammers you've seen reported.
- Tomte 9y agoWhat does "retpoline" stand for? ret for the ret instruction, I suppose, but the rest?
- niftich 9y agoThe name “retpoline” is a portmanteau of “return” and “trampoline.” It is a trampoline construct constructed using return operations which also figuratively ensures that any associated speculative execution will “bounce” endlessly. (If it brings you any amusement: imagine speculative execution as an overly energetic 7-year old that we must now build a warehouse of trampolines around.) [1] [1] https://support.google.com/faqs/answer/7625886 https://support.google.com/faqs/answer/7625886
- UncleMeat 9y ago"Trampoline". The term actually shows up with some frequency among compiler people.
- Tomte 9y agoI actually know that word in the compiler meaning, I think I just never got the connection, because I was pronouncing it in my head as ret-poh-line, not ret-poh-leen. Thanks!