4 ms·
Yup, we added this feature to Varnish Cache a few years ago, random key encryption. It generates a random key at startup and encrypts all memory with it. Since
by reza_n 7y ago
Yup, we added this feature to Varnish Cache a few years ago, random key encryption. It generates a random key at startup and encrypts all memory with it. Since this kind of memory is only resident for the lifetime of the process, it works. We stored the random key in the Linux kernel using the crypto API [0] just because its not safe storing any kind of keys in a memory space used for caching (Cloudbleed [1]). We then use the key to generate a per object HMAC, so each piece of data ends up with its own key, which further prevents something like Cloudbleed. Since we used kernel crypto, overhead was about 50%. If you stay completely in user space, its probably much lower.
[0] https://www.kernel.org/doc/html/v4.17/crypto/userspace-if.html https://www.kernel.org/doc/html/v4.17/crypto/userspace-if.ht...
[1] https://en.wikipedia.org/wiki/Cloudbleed https://en.wikipedia.org/wiki/Cloudbleed
- Koffiepoeder 7y agoCould you point me to the relevant source code? Am highly interested to take a look at it during the weekend.
- deleted 7y ago[deleted]
- reza_n 7y agoClosed source, write up would be here: https://info.varnish-software.com/blog/introducing-varnish-total-encryption https://info.varnish-software.com/blog/introducing-varnish-t...
- ris 7y ago> Closed source Ah, so we'll just have to trust you that it's doing anything at all, then.
- dang 7y ago"Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- vageli 7y ago> "Please respond to the strongest plausible interpretation of what someone says, not a weaker one that's easier to criticize. Assume good faith." > https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html Forgive me but can we not be skeptical of claims made about a commercial product?
- dang 7y agoOf course you can, and there are plenty of ways to do so that don't break the site guidelines. Cheap, snarky one-liners are not the way. If someone's posting about their own work, there's no need to be disrespectful. It's also not helpful to post such a clichéd dismissal of what someone else says or their work. That's in the site guidelines too. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- isatty 7y agoIsn’t his reply valid and an exception to the rule given the context?
- reza_n 7y agoWe have no problem sharing our codebase with customers, especially if there are concerns like this. Shoot me a msg if you are genuinely interested in anything you have read.
- AnaniasAnanas 7y agoNo offense, I am genuinely curious, why would anyone use any closed source software for anything related to security after the Snowden revelations?
- peteretep 7y agoJust to clarify my understanding, the reason for doing this is so that random sampling / leakage of the contents of the RAM stops being useful, you need to specifically get the key (and then presumably a whole chunk of encrypted RAM to decrypt?)?
- reza_n 7y agoYup. When something goes wrong in these kinds of applications, you sometimes tend to just randomly dump memory, which is a huge data leak. Or even worse, if someone figures out a way to force a data leak, then your are completely compromised. Having each piece of data with its own key and that key is a combination of data outside of the process address space drastically lowers the chances of data leakage and total compromise.
- thijsvandien 7y agoCould this be implemented at the OS level, i.e. whenever a proces launches, the OS generates a key that it will keep to itself and use to transparently encrypt all memory allocated by that process?
- blattimwind 7y agoTechnically yes, but practically no, because mediating all memory reads through the kernel would be very slow. SME/MKTME add hardware support for this.
- simias 7y agoYou'd probably want a hardware module to do that lest performance plummets. Memory controllers can already deal with ECC efficiently, adding a simple cypher on top of it should definitely be feasible.
- AlgorithmicTime 7y agoWouldn't this be functionally similar to AMD's SEV and SME? https://developer.amd.com/sev/ https://developer.amd.com/sev/
- reza_n 7y agoPossibly, but memory is accessed using plain CPU instructions, so it would be hard to transparently encrypt all memory for an application at the kernel level. You do have virtual memory, but I dont think that could be leveraged for this. But who knows whats possible there, maybe if you align and address each memory value at the page boundaries and always force a page fault you could have a really poor implementation :) Transparent disk encryption, not a problem since devices have filesystems which can implement encryption at that layer.