[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [Publicity] Blog-post RFC: Hardening Xen against VENOM-style attacks
On Thu, May 14, 2015 at 1:40 PM, Lars Kurth <lars.kurth.xen@xxxxxxxxx> wrote: Hi folks, That would be indeed helpful ;) Â
I'll add a discussion on why stubdoms might not be provided by default - tradeoff between memory usage vs security and the fact that everyone should use it on a given host to gain the extra protection. Â @Tamas: Sure. Â
Ack, I'll just say "reevaluate their risks". Â
I know, that's why I felt it would be good to address this. For those paying attention this is not really news. Yes, it needs to be fixed but it's not like it wasn't anticipated in general.. Â
Marketing buzz word for targeted attacks. I'll cut it ;) Â
I completely agree but I still want to highlight that the cloud is not bullet proof. Many people just stare at you blankly when it comes to discussing cloud security and why it's needed (in my experience). It raises the bar. It doesn't solve all your problems and can even introduce new ones. Â
As I said, I kind of want to make people aware that hypervisors have problems too. Maybe "plaguing" is a harsh description though ;) Â
Yea, that makes sense. Red Hat already posted a blog entry saying sVirt protects against this.  > While modern systems come ... Sure.  I think it is worth pointing pout that people use PVHVM (HVM) for performance reasons also. One gets the impression from this paragraph that the only reason Ack.  > Back in 2011, the Blackhat talk on Virtunoid demonstrated such a VM escape attack against KVM, through QEMU. I have a set of footnotes with links that didn't copy in the original email. I'll copy those too in the next revision.  > As a sidenote, KVM allows for similar jailing of the QEMU process via the native SELinux sVirt policies. Yeap, had the link in a footnote.  > Unfortunately, your cloud provider may not allow you to enable this option. Thanks, Tamas  > On 14 May 2015, at 11:59, Stefano Stabellini <stefano.stabellini@xxxxxxxxxxxxx> wrote: --
Tamas K Lengyel Senior Security Researcher 7921 Jones Branch Drive McLean VA 22102 Email Âtlengyel@novetta.com _______________________________________________ Publicity mailing list Publicity@xxxxxxxxxxxxxxxxxxxx http://lists.xenproject.org/cgi-bin/mailman/listinfo/publicity
|
Lists.xenproject.org is hosted with RackSpace, monitoring our |