Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sweis
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
151.
▲
by
sweis
13y ago
You can run on bare-metal providers like SoftLayer, which allows you run your own trusted hypervisor or OS. This, as you said, isn't currently possible on AWS. Incidentally, PrivateCore has a trusted, remotely-attested hypervisor that
152.
▲
by
sweis
13y ago
OpenSSL has a GCM implementation which is very fast and I believe is not susceptible to timing attacks due to using vpclmulqdq: http://git.openssl.org/gitweb/?p=openssl.git;a=blob;f=crypto... You can debate whether it&
153.
▲
Intel SGX for Dummies
(software.intel.com)
2 points
by
sweis
13y ago
|
0 comments
154.
▲
by
sweis
13y ago
Here's a video of a malicious PCIe device extracting both plaintext and encrypted main memory: http://www.youtube.com/watch?v=chvJpEmXvDk
155.
▲
by
sweis
13y ago
Hi. PrivateCore has implemented encrypted RAM as part of a secure hypervisor. Our product is currently in a private beta, but you can check out our website at: http://www.privatecore.com . We gave a talk on some of the vulnerabil
156.
▲
by
sweis
13y ago
TRESOR still leaves all the code and data exposed in memory. You can modify the code that's being executed in order to divulge the contents of the debug registers. We're working on solving the malicious device and cold boot proble
157.
▲
by
sweis
13y ago
IOMMU with VT-d is present, but not utilized by some major commercial operating systems and hypervisors. There are also some implementation vulnerabilities in specific OSes which are not yet publicly disclosed.
158.
▲
Thoughts on Intel's upcoming Software Guard Extensions (Part 2)
(theinvisiblethings.blogspot.com)
2 points
by
sweis
13y ago
|
0 comments
159.
▲
by
sweis
13y ago
Hi Josh. I'm a PrivateCore co-founder. Our initial customers are primarily enterprises or service providers, which have varying requirements with respect to source availability. Some code will be open sourced, though some parts will re
160.
▲
Prof. Matthew Green asked to remove NSA post by JHU dean
(twitter.com)
6 points
by
sweis
13y ago
|
2 comments
161.
▲
by
sweis
13y ago
SGX adds the ability to attest and seal individual enclaves, with a root attestation key in the CPU die: https://docs.google.com/file/d/0B_wHUJwViKDaSUV6aUcxR0dPejg/... This key has some similarities to a TPM
162.
▲
by
sweis
13y ago
SGX is a very interesting development. I agree with Johanna Rutkowska that "SGX might profoundly change the architecture of the future operating systems". Enhanced Privacy IDs are particularly interesting, since it will allow you
163.
▲
Debian/Ubuntu root privilege escalation
(blog.cmpxchg8b.com)
8 points
by
sweis
13y ago
|
1 comments
164.
▲
by
sweis
13y ago
Hi. We're aware of TPM vulnerabilities. The one you link to is not relevant. However, there are attacks to extract EK private keys, which we know the cost of conducting. It's significantly higher than other low-cost attacks. We&#x
165.
▲
ZMap: Internet scanner maps all of IPv4 in 45 minutes
(zmap.io)
207 points
by
sweis
13y ago
|
63 comments
166.
▲
by
sweis
13y ago
You must first remotely attest the hypervisor using TXT before deploying a VM to run on it. Today, that attestation process relies on a TPM and a signed certificate chain baked in by the TPM manufacturer. This is standard stuff out of the T
167.
▲
by
sweis
13y ago
Today we rely on the TPM to measure the state of the system using Intel TXT. These measurements are stored in platform configuration registers (PCRs) on the TPM device. There are known TPM and LPC bus vulnerabilities. That is why long-term
168.
▲
by
sweis
13y ago
We're working on a similar problem at PrivateCore: Protecting VM data in-use on outsourced infrastructure. We're running a high-assurance, remotely attestable hypervisor inside the CPU cache and encrypting all access to main memor
169.
▲
"Inside the Dropbox" attack to hijack Dropbox accounts
(github.com)
2 points
by
sweis
13y ago
|
0 comments
170.
▲
Australian Department of Defence denies ban on Lenovo PCs
(news.defence.gov.au)
2 points
by
sweis
13y ago
|
0 comments
171.
▲
by
sweis
13y ago
Regarding entropy sources for guest virtual machines, the host can expose a random number generator device to the VM. This is an option in KVM: http://libvirt.org/formatdomain.html#elementsRng Modern Intel x86 processors no
172.
▲
Top security & crypto papers from the last 5 years
(saweis.net)
6 points
by
sweis
13y ago
|
1 comments
173.
▲
Start-ups lean hard on CPU-based security to protect virtual environments
(networkworld.com)
2 points
by
sweis
13y ago
|
0 comments
174.
▲
by
sweis
13y ago
EPID is slated to ship in upcoming x86 architectures. It's interesting because it provides strong hardware-based authentication, but with support for of pseudoanonymity or anonymity.
175.
▲
Intel Enhanced Privacy ID
(csrc.nist.gov)
2 points
by
sweis
13y ago
|
1 comments
176.
▲
by
sweis
13y ago
Here are a few for a start: - "Cross-VM Side Channels and Their Use to Extract Private Keys" http://www.cs.unc.edu/~reiter/papers/2012/CCS.pdf - "Cache-timing attacks on AES" http:/&
177.
▲
by
sweis
13y ago
I am working on securing virtual machines against physical attacks (which yes, does sound impossible). Our approach requires code changes on the hypervisor level, which currently rules outs Amazon but is viable for bare-metal cloud provider
178.
▲
by
sweis
13y ago
I think you're missing a key point. Yes, you can test AES at one moment in time. But when you're talking backdoors, they aren't necessarily active all the time. Backdoors could wait for a specific trigger from outside input.
179.
▲
by
sweis
13y ago
I inadvertently spawned this discussion by pointing out that many open source security projects like Linux, OpenSSL, GnuTLS, libgcrypt, dm-crypt, etc. all depend on closed-source crypto implementations [1]. This was followed by one of the L
180.
▲
Upcoming talk on hijacking Dropbox accounts
(usenix.org)
39 points
by
sweis
13y ago
|
13 comments
More ›