Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
xca-attacks.github.io
Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
1–10 of 30 posts
Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
#2Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
#3I wonder how much more expensive it is to rent the whole physical machine at all times for confidential computing purposes, compared to the losses incurred by a breach.
Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
#4I wonder how much more expensive it is to rent the whole physical machine at all times for confidential computing purposes, compared to the losses incurred by a breach.
A lot more expensive and this is required for any classified data. I honestly don't think you can truly securely share a CPU with a hostile tenant because their are just too many side-channels.
Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
#5Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
#6More evidence that "confidential computing" is just a trick to convince people to hand over control of their computing to "someone else's machine". Never trusted the clown, and never will.
Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
#7Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
#8I wonder how much more expensive it is to rent the whole physical machine at all times for confidential computing purposes, compared to the losses incurred by a breach.
Not having a multi-tenant system is something else. There you're trying to be protected from other customers, not the provider. Excluding other tenants still wouldn't protect you against the provider, especially on systems with proprietary and potentially exploitable ring -1 hardware they could already be silently in control of even when the entire machine is allocated to you.
Meanwhile for anything on the scale of an organization, having physical possession of the machine yourself isn't that expensive. People got hoodwinked when virtualization first came around because they compared the cost of having a mostly-idle physical server for each of their applications to having that many cloud VMs, and the cloud VMs were cheaper, but that isn't the right comparison. You don't compare having 100 physical machines to having 100 VMs, even if people used to use 100 physical machines for that in 2005. You compare it to having three physical machines that can each run 100 VMs, and then having physical possession of your own hardware is frequently less expensive.
Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
#9More evidence that "confidential computing" is just a trick to convince people to hand over control of their computing to "someone else's machine". Never trusted the clown, and never will.
A vulnerability is a trick? All complex systems have them, but eventually they will all be formally verified and secure. Progress marches on. Unless you’d rather make your own processors along with the moonshine in your shed, of course.
If there is a vulnerability in a system controlled by an untrusted party that already has your sensitive data on it, you're pwned.