4 ms·
> I don't see how it protects against meltdown, wouldn't the memory still get decrypted by the escalated access? No. A particular VM's memory is decrypted by t
by theevilsharpie 6y ago
> I don't see how it protects against meltdown, wouldn't the memory still get decrypted by the escalated access?
No. A particular VM's memory is decrypted by that VM's key.
Assuming that AMD's CPUs were vulnerable to a hypothetical attack similar to Meltdown, either a VM or a guest would be able to dump the machine's memory, but the memory contents belonging to other VMs would be encrypted and unintelligible.
- eloff 6y agoI think my edit and your comment passed each other on the wire. That makes sense, it gives hardware protection from privilege escalation between VMs on the same host. Be it through a hardware exploit or hypervisor vulnerability.