[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] RAM security


  • To: Jonathan Tripathy <jonnyt@xxxxxxxxxxx>
  • From: George Dunlap <George.Dunlap@xxxxxxxxxxxxx>
  • Date: Mon, 6 Dec 2010 14:49:20 +0000
  • Cc: xen-devel@xxxxxxxxxxxxxxxxxxx
  • Delivery-date: Mon, 06 Dec 2010 06:50:24 -0800
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:date :x-google-sender-auth:message-id:subject:from:to:cc:content-type; b=NXJppFJvEVfRRpzGE07URpj6y4mIu358fp9YN6ySBX67apT27Z68rHd5XACh5z2p7T qD9pyXgWUxWel95sP8lyxU2ju3tFn18YGy2HnpbIPQB+K/ZI086SrPay/j8VhYmQiko/ LLuuEKlqOo0ya7FLXhn2tXMqHT1x67Kwtu2RU=
  • List-id: Xen developer discussion <xen-devel.lists.xensource.com>

I looked into this sometime this last year.  I believe the answer is
"no": the domain destruction routines will zero memory before handing
it back to Xen.

One potential data leak, however (last time I looked at this), is that
Xen does not scrub memory handed back by the balloon driver.  So if
the guest OS hasn't scrubbed it, and it contains sensitive
information, it may end up being assigned to another domain as-is
(either via ballooning or start-of-day domain creation).  At the
moment that's considered the guest's responsibility.

 -George

On Mon, Dec 6, 2010 at 2:35 PM, Jonathan Tripathy <jonnyt@xxxxxxxxxxx> wrote:
> Hi Everyone,
>
> In Xen, is a DomU able to access data in RAM which a previous DomU has
> stored in the past, but didn't "zero" it?
>
> I understand that this is a problem with physical disks (using phy:/), just
> wondering if the same stands with RAM
>
> Thanks
>
> _______________________________________________
> Xen-devel mailing list
> Xen-devel@xxxxxxxxxxxxxxxxxxx
> http://lists.xensource.com/xen-devel
>
>

_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.