3 ms·
> This is what the entire public cloud is built on. Well... The entire public cloud except Azure. They've been caught multiple times for vulnerabilities stemmi
by flaminHotSpeedo 2y ago
> This is what the entire public cloud is built on.
Well... The entire public cloud except Azure. They've been caught multiple times for vulnerabilities stemming from the lack of hardware backed isolation between tenants.
- richardwhiuk 2y agoAzure has the same level of isolation for VMs at a hardware level as AWS.
- flaminHotSpeedo 2y agoHow Azure isolates VM's is completely unrelated, because containers are not VM's. And if you meant to assert that Azure uses hardware assisted isolation between tenants in general, that was not the case for azurescape [1] or chaosDB [2]. [1] https://unit42.paloaltonetworks.com/azure-container-instances/ https://unit42.paloaltonetworks.com/azure-container-instance... [2] https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-v...
- richardwhiuk 2y agoIt is the case for VMs that customers create. It hasn't always been the case for manged services, but I don't think that's true for AWS either.
- flaminHotSpeedo 2y agoUnmanaged VM's created directly by customers still aren't relevant to this discussion. The whole point here is that everyone else uses some form of hardware assisted isolation between tenants, even in managed services that vend containers or other higher order compute primitives (i.e. Lambda, Cloud Functions, and hosted notebooks/shells). Between first and second hand experience I can confidently say that, at a bare minimum, the majority of managed services at AWS, GCP, and even OCI use VM's to isolate tenant workloads. Not sure about OCI, but at least in GCP and AWS, security teams that review your service will assume that customers will break out of containers no matter how the container capabilities/permissions/configs are locked down.