Live data from Hacker News

XSA-108 Advisory

xenbits.xen.org

1–10 of 97 posts

Re: XSA-108 Advisory

#6
It will be interesting to see which providers didn't get the embargoed release.

So if you get a reboot announcment from your xen vps provider after today 12:00Z, you should list them here.

Re: XSA-108 Advisory

#8
post #6

It will be interesting to see which providers didn't get the embargoed release. So if you get a reboot announcment from your xen vps provider after today 12:00Z, you should list them here.

Pre-disclosure list is at the bottom of this page.. http://www.xenproject.org/security-policy.html

Re: XSA-108 Advisory

#9
post #3

I assume this is why AWS forcefully rebooted many of their VMs recently?

There is no need to assume anything.

""" Yesterday we started notifying some of our customers of a timely security and operational update we need to perform on a small percentage (less than 10%) of our EC2 fleet globally.

AWS customers know that security and operational excellence are our top two priorities. These updates must be completed by October 1st before the issue is made public as part of an upcoming Xen Security Announcement (XSA). Following security best practices, the details of this update are embargoed until then. The issue in that notice affects many Xen environments, and is not specific to AWS. """

[0] http://aws.amazon.com/blogs/aws/ec2-maintenance-update/

Re: XSA-108 Advisory

#10
Well looks like Mr De Raadt was right again:

'x86 virtualization is about basically placing another nearly full kernel, full of new bugs, on top of a nasty x86 architecture which barely has correct page protection. Then running your operating system on the other side of this brand new pile of shit.

You are absolutely deluded, if not stupid, if you think that a worldwide collection of software engineers who can't write operating systems or applications without security holes, can then turn around and suddenly write virtualization layers without security holes.'

Source: http://marc.info/?l=openbsd-misc&m=119318909016582

Personally, I have hope for things like cgroups/jails and MAC/SELinux over virtualization.

Post reply on HN