2 ms·
VT-x itself is not the main attack surface. It's all the interfaces between the inside and the outside of the VMs, for example graphics hardware emulation, netw
by Retr0spectrum 6y ago
VT-x itself is not the main attack surface. It's all the interfaces between the inside and the outside of the VMs, for example graphics hardware emulation, network hardware emulation, etc. etc. There have been many of these bugs, on qubes/xen, and basically every other popular hypervisor. I have personally found a kernel memory disclosure vulnerability affecting xen, which I tested under qubes (it wasn't a very useful bug, but the point is, they exist and they are plentiful).
Furthermore, the "blue pill" attack is not a vulnerability in VT-x itself. In fact, it does not exploit any vulnerabilities at all - it simply works off the idea that code running in ring n can hide itself from code running ring+1 (the bluepill hypervisor being ring -1).
- fsflover 6y agoThose bugs of course exist, but I would not say "There have been many of these bugs, on qubes/xen... they exist and they are plentiful": https://www.qubes-os.org/security/xsa/ https://www.qubes-os.org/security/xsa/. The actual number is 67 in ~10 years: https://www.qubes-os.org/security/xsa/ https://www.qubes-os.org/security/xsa/, which is more secure than anything else AFAIK. Note, this is counting older Qubes versions, where the virtualization was much less secure.