15 ms·
Virtual Machine as a core Android Primitive
- ForkMeOnTinder 3y agoSo on desktop, if I spin up a VM with networking disabled I feel pretty confident I can run anything safely, even malware is not going to escape. What's the current state of the art for Android virtualization? Let's assume we're talking about the newest Pixel and newest Android version. Is there any way to safely run malware or the Facebook app in some sort of air-gapped container and throw it away when you're done?
- heavyset_go 3y agoPretty sure Android already uses Linux containers/namespaces for app isolation.
- saagarjha 3y agoIt uses separate UIDs mostly.
- phone8675309 3y agoAlong with SELinux
- seabrookmx 3y agoYou're thinking of ChromeOS I think, which uses a combination of containers and virtualization (via the same VMM in this article) for Linux and Android apps..
- heavyset_go 3y agoYeah, apparently Android uses users and namespaces, but not containers as we typically know them like ChromeOS does.
- fleventynine 3y ago> if I spin up a VM with networking disabled I feel pretty confident I can run anything safely, even malware is not going to escape. You are putting too much faith in your VM monitor to keep you safe. There's a lot of attack surface in (for example) QEMU peripherals, and there's plenty of examples of VM escape [1]. CrosVM is probably the only publicly available VMM I'd be willing to trust, and even then I'd be nervous running state-sponsored malware on a machine with important data. [1] https://www.google.com/search?q=qemu+vm+escape https://www.google.com/search?q=qemu+vm+escape
- monocasa 3y agoI'd probably trust firecracker too since it was designed specifically to avoid qemu's attack surface and runs in production for Amazon.
- ClassyJacket 3y ago*malware like the Facebook app
- jmprspret 3y ago> Is there any way to safely run malware or the Facebook app in some sort of air-gapped container and throw it away when you're done? User profiles can be used in this exact way. Guest user if you intend to install+wipe it right away (though this will prove cumbersome eventually due to having to reinstall the app every time, etc). There is a significant isolation benefit to them, though not currently virtualized. With the isolation can come usability issues. Like transferring files from one profile to another. They can very slow however (slow to load+setup, and switch between, I mean. when you're inside its effectively a separate, fresh, OS install).
- tripdout 3y agoWhy does the tutorial for creating a demo app, https://source.android.com/docs/core/virtualization/writeavfapp https://source.android.com/docs/core/virtualization/writeavf..., only work on Cuttlefish (emulator)? Nevermind, only the demo app, not the tutorial, so who knows what its doing.
- saagarjha 3y agoMaybe because it requires a platform signature to use?
- deleted 3y ago[deleted]
- rstat1 3y agoIts annoying that I can't use this without greater-than-normal-user access.
- 3abiton 3y agoIt is still baffling that root is so shunned upon in the Android communities. Imagine not having root access to your linux laptop. Magisk users are persecuted and punished by Google for getting root access, which is the bare minimun for a device you own.
- pjmlp 3y agoEasy, that is how many of us use UNIX like OSes, macOS, Windows devices on corporate environments. Not everyone gets to be root, and even for devs there are IT management tools that only allow root for specific use cases, or time boxed.
- codedokode 3y agoNo, I think the reason is that not letting user have full control over hardware is more profitable for manufactures, government and economy as a whole.
- pjmlp 3y agoAnyone that misuses their root account to have an exploit taking place inside the organization gets shown the door.
- themoonisachees 3y agoAnd what is "getting shown the door" with your own device? A Fullscreen message telling you you are now banned from the device you spent a months wages on?
- pjmlp 3y ago
- Shoop 3y agoHow does two way isolation work? How do you prevent the host kernel (which presumably has full control of the hardware?) from inspecting the guest VM?
- darig 3y ago[dead]
- ReactiveJelly 3y agoIt must be relying on a TPM somehow, right? That isn't possible with any normal software VM
- transpute 3y agoThis eschews hardware-based TEE (like TrustZone or TPM) in favor of hardware support for nested virtualization, plus open-source L0 hypervisor code. In the best case future, this will offer security properties based on a small OSS attack surface, rather than black box TEE firmware.
- haltist 3y agoYou can inspect their hypervisor code and verify the host kernel can not access the VM after creation but if you are running as root then you can obviously inspect whatever process is under host/hypervisor control.
- jbott 3y agoIt looks like the host kernel is not in full control – there is a EL2-level hypervisor, pKVM [1] that is actually the highest-privilege domain. This is pretty similar to the Xen architecture [1] where the dom0 linux os in charge of managing the machine is running as a guest of the hypervisor. 1. https://source.android.com/docs/core/virtualization/architecture#hypervisor https://source.android.com/docs/core/virtualization/architec... 2. https://wiki.xenproject.org/wiki/Xen_Project_Software_Overview https://wiki.xenproject.org/wiki/Xen_Project_Software_Overvi...
- 3y ago
- kmeisthax 3y agoThe use of the word "privileged" seems to imply that only system apps will be able to use this - i.e. no installing virtual machines off Google Play anytime soon. Bleh.
- transpute 3y agoHopefully standard tooling will appear in time. Patreon PoC of unprivileged VMs, https://www.xda-developers.com/nestbox-hands-on/ https://www.xda-developers.com/nestbox-hands-on/ > On the Pixel 7, the most configuration you'll need to do is similar to Shizuku. You connect to your own phone over wireless adb, configure the maximum container size, and then choose your Linux distribution. It'll download, configure, and then execute the virtual machine.
- jeffrallen 3y agoAnother salvo in the war on general purpose computing.(https://lwn.net/Articles/473794/ https://lwn.net/Articles/473794/)
- transpute 3y agoIf Android phones can run non-Android VMs of the user's choice, the phones will gain new purpose.
- jeffrallen 3y agoOk cool. But you and I both know that this feature was designed for the DMCA-lovin' Hollywood types and the control-freak enterprise IT BOFHs, not for your cool hack. Let's use their tools of oppression against them! (fist emoji)
- transpute 3y agoMedia and Enterprise already have TrustZone, Knox, Intune, etc. which work "enough". Newer markets include cashless (CBDC) payments and digital identity anchored in human biology, demanding more security than legacy content. > Biometrics: By deploying biometric trusted applets in an isolated virtual machine, developers will have the isolation guarantee, access to more compute power for biometric algorithms, easy updatability regardless of the Trustzone operating system, and a more streamlined deployment. Fortunately, OSS can enable N-party transaction transparency, we don't have to settle for one-way mirrors and WeChat clones.
- robertwt7 3y agoAlthough this is very exciting. Surely performance is not the benefit here? It won’t perform better than android app built not on top of the virtualisation tdchnology?
- ips1512 3y agoAndroid apps performs better if built natively, Google might take some steps to enhance its performance.
- omeid2 3y agoAndroid apps are already running on top of a Virtualisation Technology", both current ART (Android Runtime) and the previous one, Delvik, runtimes are virtual machines, process level virtual machines, but they do bytecode translation/JIT nonetheless. If AVF allows running native code, it might actually be cheaper than the current arrangement.
- glacia01 3y agoI'm not Android expert in any way, but VM have nothing to do with virtualization. I think you're confusing something.
- walteweiss 3y agoWhat do you mean? Literally, the title: ‘Virtual Machine as a core Android Primitive’ and the very first sentence: ‘The Android Virtualization Framework (AVF) will be available on upcoming select Android 14 devices.’
- fragmede 3y agowhat does VM stand for?
- IAmLiterallyAB 3y agoAndroid apps can already run native code, so there's no performance benefit. Also, Java "virtual machines" and native virtual machines are two very different things, they shouldn't be equated.
- Animats 3y agoSo what is something running in this virtual machine allowed to do? Talk to the Internet? Talk to the screen? Talk only to whatever started it? How much of this is closed source?
- saagarjha 3y agoI think the design is intended so that you mostly only get to do the last one.
- keepamovin 3y agoPossibly one cybersecurity-related thing you could do is run a headless browser inside this VM, and bridge the network requests to the host network (a little bit like Docker). Using my open-source BrowserBox^0 project then you could have a "bit more isolated" Browser running on your Android device that would add "VM escape" to any zero-day exploit chain that might be a risk. This is speculation tho, I don't know if it's actually feasible based on the Android reality right now, but assuming the capabilities that are provided are like a regular headless VM, then it should be. :) 0: https://github.com/BrowserBox/BrowserBox https://github.com/BrowserBox/BrowserBox
- codedokode 3y agoWhy do you need VM for isolation? ARM architecture already provides tools for isolation, like MMU and privilege levels. Why do you need another kernel, emulation of hardware devices? It is completely wrong method.
- keepamovin 3y agoFor sure, ARM's MMU and privilege levels are solid for base isolation. But consider the VM for a headless browser as an extra layer of defense, especially in the wild and crazy web threat landscape. Yes, it involves another kernel and some hardware emulation, but modern VMs, particularly with Android's AVF, are designed to be lightweight and efficient. With AVF, we're looking at tailored isolation, where a VM can be as minimal or as comprehensive as needed. This flexibility means we can create a highly controlled environment for the browser, enhancing security against web-specific exploits. It's about using ARM's strengths and adding a VM where it makes sense for focused, web-centric security. The idea's to mix and match security layers for the best defense, especially with Android's new AVF making VMs more streamlined. I guess you could say the goal here is to tailor the security approach to the specific risks associated with web browsing, making the system resilient against a broader range of exploits.
- usrusr 3y agoBack at university one lecture included an infographic about how CPU and operating system features like MMU, increasing register width and the like all started at mainframe-scale installations and trickled down to desktop scale systems and later to handheld devices at a surprisingly consistent pace. It was the time w2k was trying to make NT features mainstream and J2ME arrived on phones. I extrapolated a little and made a joke about multi-user concepts arriving on phones and a few years later Android was right on schedule (when that happened, repurposing Linux users as units of app isolation was the headline feature in tech news). By that measure, virtualization is long overdue, but I really can't claim that I'm not surprised.
- deleted 3y ago[deleted]
- VierScar 3y agoYou can't claim you're not surprised? So you can claim you are surprised? You're surprised by this. I feel like I'm trying to understand double negatation logic in code haha
- hiatus 3y agoIt's the same as saying "I can't say I'm not surprised"—meaning they are unsurprised.
- juicypt 3y agoIt seems to me that they're not unsurprised, and so they're actually surprised.
- deleted 3y ago[deleted]
- VierScar 3y agoI think that's saying they're surprised. The saying in other contexts: "I can't say I'm not impressed" -> I'm impressed. "I can't say you didn't try" -> you tried. I think you mean "I can't say I'm surprised" -> this is not at all surprising. But that's just one negative.
- londons_explore 3y agoHow lightweight are these? Can I start 100 Vm's to render content from 100 web origins in a secure web browser?
- codedokode 3y agoLooks like something absolutely overengineered and unnecessary. Why do you need a virtual machine with a separate kernel? Why do you need to protect it from kernel? I guess, it is made mostly for playing DRM content?
- helloooooooo 3y agoOne prime example is to protect credentials. Windows already uses this in a feature called credential guard.
- berkes 3y agoA use-case I can imagine is e.g. a password vault, a banking app, or a secure messaging app that you want isolated from everything. Even when running. And where "everything" includes infected apps, an infected host or even physical access. Not sure if this architecture can handle that, nor of it's the best architecture to solve this problem, though.
- jonathanlydall 3y agoYes, yes, yes... those are all "legitimate" and likely good uses of this technology, but they're most likely just additional/bonus tertiary use cases to the main use case which motivated Google to expend effort on this feature: DRM. It's much like how web browsers' incognito/private mode is really useful for web developers and certain kinds of troubleshooting, but those are tertiary uses to the primary consumer use case for which it was originally built: browsing porn without leaving history behind.
- eptcyka 3y agoI'd love to be able to use a Qubes like OS on my phones. There's so much vile garbage I need to run on my phone yet at the same time, I want my phone to have access to my passwords and email. Segregating apps is long overdue.
- anthk 3y agoNot Qubes, mayube something like Unikernels from NetBSD.
- fidotron 3y agoI wonder if this has anything to do with RISC-V and them needing TrustZone equivalent functionality in that environment.
- kramerger 3y agoOn the contrary, this is about support for new virtualization model in ARMv9, which the latest Pixel use.
- josephcsible 3y agoTwo-way isolation seems like it'd only be useful for DRM and Treacherous Computing.
- nl 3y agoThis is such a bad take. I'd love the easy ability to run confidential computing loads with fine grained control over the data it gets access to. You can do this now on the desktop using SGX (etc) but on mobile it's really hard. As a specific example of this, it'd be great to be able to run Whisper continually and have strong, system level guarantees about what can read the data.
- refulgentis 3y agoI used to work at Google adjacent to this stuff and A) you wouldn't boot up a whole VM for this, on a phone, that'd be very wasteful B) there's much simpler ways to provide the same guarantee. So in general, just would avoid labeling the quality of other people's takes. You never know who is reading yours
- somanytta 3y ago[flagged]
- nl 3y agoI agree there are currently better ways of doing this (because as you mention the resource/protection trade off for this technology on this application is sub-optimal), but the context here is as an example on HN where the data privacy is obvious so I didn't have to write a whole paper explaining it.
- refulgentis 3y agoIts "not even wrong", if you had a million monkeys on a million typewriters with a million trillion millenia, still, none would come up with a paper long enough to explain how that'd help anything (ex. trivially, microphone)
- awoimbee 3y agoWill this allow running linux VMs on any Android device ? Via something like nestbox: https://www.patreon.com/posts/74333551 https://www.patreon.com/posts/74333551 ?
- heavyset_go 3y agoThis is already possible if your phones ship with the KVM kernel module, like on some Pixel devices, but reading the article suggests that KVM will become standard on all Android devices to enable this. edit: according to this[1], yes, the pKVM functionality that's standard in Android exposes KVM functionality so that you can run VMs on Android. [1] https://www.xda-developers.com/android-13-dp1-google-pixel-6-kvm-virtual-machine/ https://www.xda-developers.com/android-13-dp1-google-pixel-6...
- walteweiss 3y agoWhich Pixel devices? Is it something new or not-so-new?
- heavyset_go 3y agoI couldn't tell you, sorry. Just going off what I've read in some articles like the one I posted.
- angm128 3y agoA full linux environment (with external monitor support) sounds awesome. I hope that enabled KVM becomes standard Would graphics acceleration work properly?
- anthk 3y agoYou can already to that with termux, XSDL and some scripts. No virtualization needed.
- heavyset_go 3y agoDepends on the kind of acceleration you want. VirGL is available on Linux host/Linux guest setups with recent kernels, not sure if QXL/SPICE will be available or can be added to the userland. Can't imagine a hardware passthrough situation making sense on a phone/tablet, either.
- 7e 3y ago[flagged]