Earlier quoted context omitted.
> VMs are bad because they make it much easier for an attacker to get a process on the same CPU as yours; nothing more, nothing less. The paper cites less than 25% of the time which is specific to EC2. With more cores on the host this attack rapidly becomes impossible as domUs rarely share cores. Which is why I asked for actual evidence of cryptographic compromise in the wild and not yet more papers. You suffer from…
To your last question: yes. To your inevitable followup question: no, I'm not going to talk to you about it. To your overarching point: if you are on a cloud platform that promises you will never share hardware with any other company – which virtually nobody is – you are still at greater risk simply being on a nanosecond-timeable switched network with your attackers. But local crypto timing attacks are far more power…
Or did you violate it to tell me 'yes'?