Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
nellydpa
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
nellydpa
6y ago
The keys used to encrypt the confidential VM memory is kept in the hw registers and not accessible and extractable by any sw, google or AMD. The keys are per a VM, ephemeral, so not stored anywhere. RE: storage level, you can encrypt your
2.
▲
Why Confidential Computing Is a Game Changer
(darkreading.com)
107 points
by
nellydpa
6y ago
|
42 comments
3.
▲
by
nellydpa
6y ago
The answer to your question: The AES mode AMD SEV uses is similar to XEX. AMD computes a tweak value based on the physical memory address and performs an xor-encrypt-xor operation. The tweak algorithm used on Rome (2nd gen EPYC) is based
4.
▲
by
nellydpa
6y ago
Actually, the integrity of the AMD microcode can be verified using Google stackdriver as part of VM audit logs, together with the integrity of the VM kernel.
5.
▲
by
nellydpa
6y ago
AES 128bits
6.
▲
by
nellydpa
6y ago
But everything else is not actually confidential... Confidentiality means limited visibility, when you process your data, the memory is in clear without this tech, or Intel SGX that offer confidentiality and integrity.
7.
▲
by
nellydpa
6y ago
You can access memory within a VM, not outside of a VM. Host machine with a hypervisor is not within a VM instance, so it will not be able to read your VM memory. The memory is encrypted all the time, but when the instruction has to be exec
8.
▲
by
nellydpa
6y ago
You are right, data is private and confidential when it is ingested to the cloud and/or stored in the cloud, not when processed. Encryption of "data-in-use" is the 3rd leg in data protection of sensitive data, and it became p
9.
▲
by
nellydpa
6y ago
Quite a few: protect sensitive data in the cloud from the tenants and cloud providers, protect my clients sensitive data, address some requirements of the regulated markets, mitigate some privacy regulations, and a few new: collaborative co
10.
▲
by
nellydpa
6y ago
SEV is targeted to the VM instances, with a single key per VM. SME is applicable to the entire server, similar to total memory encryption with a single key for all host kernel/machine. SME is not super applicable to the cloud, more su
11.
▲
by
nellydpa
6y ago
Unless you run a database in the Confidential VM, can run mySQL, postgresql, MariaDB. Google managed db service, say GCP CloudSQL is not supported...
12.
▲
by
nellydpa
6y ago
GCP does not have root access to the customers VMs. Confidential VMs with AMD SEV create an additional cryptographic isolation layer (in addition to virtualization one) between tenants and Google infra, mitigate 0days guest escapes, make ob
13.
▲
by
nellydpa
6y ago
Homomorphic encryption enables computation to be performed on encrypted data without the need to decrypt it on the CPU. Compared to Confidential Computing approaches, the processing complexity of FHE is quite high, especially for tasks that
14.
▲
by
nellydpa
6y ago
SEV: No changes are required to the apps, better performance, but bigger TCB. GCP mitigate this with Shielded VMs, in particular integrity of the kernel in your trusted boundary, notifications to users if the integrity state changed from th
15.
▲
GCP advancing confidential computing to lure enterprises to consider cloud
(cloud.google.com)
3 points
by
nellydpa
8y ago
|
0 comments
16.
▲
Google explained how Shielded VMs work and video
(cloud.google.com)
2 points
by
nellydpa
8y ago
|
0 comments
17.
▲
by
nellydpa
9y ago
AWS and Azure most likely (not publicly announced) are working on hardening their servers. Based on http://ca.reuters.com/article/technologyNews/idCAKCN1B22D6-O... : "Neither Amazon.com nor Microsoft - which
18.
▲
by
nellydpa
9y ago
Great question. We are working on it. LOAS is about server or device credentials that only will be issued if Titan will pass the validation of bios firmware. re: Niels paper, out of my control.
19.
▲
by
nellydpa
9y ago
Hey there, I am one of the authors behind this blog. How about we will share our Titan earrings swag instead for your close examination? We fixed captions on the blog, thanks for pointing it out.
20.
▲
by
nellydpa
10y ago
You are right, some instructions are not suitable for userspace due to their performance implications and have to stay in the kernel. We identified a small set of them, for example, some parts of IOAPIC support have to stay put.
21.
▲
by
nellydpa
10y ago
Hey folks, thanks for great comments, keep them coming.I am one of the article authors, AMA.