Live data from Hacker News

Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

xca-attacks.github.io

11–20 of 30 posts

Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

#12
post #11
post #10

There are microcode updates for this already https://www.amd.com/en/resources/product-security/bulletin/a...

but is it possible to verify that the cloud provider has applied the update?

/proc/cpuinfo shows the current microcode version

Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

#14
post #11
post #10

There are microcode updates for this already https://www.amd.com/en/resources/product-security/bulletin/a...

but is it possible to verify that the cloud provider has applied the update?

Yes, it is. You do have to have some infrastructure you trust somewhere to validate an attestation report from the confidential VM.

Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

#16
post #11

Earlier quoted context omitted.

but is it possible to verify that the cloud provider has applied the update?

/proc/cpuinfo shows the current microcode version

i don't think the information that unprivilleged VMs can obtain from that is necessarily reliable. for example with Xen as hypervisor only dom0 is privilleged (as management console for the system) and still it needs to call dedicated tooling in order to read or manage CPU features like clock speed or frequency scaling

Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

#17

What purpose does the "news" of finding another way to break "confidential computing" serve, other than proliferate the incorrect assumption that there even was a working concept beforehand?

I guess the reason you provided is the answer to the question.

Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

#18
post #2

I wonder how much more expensive it is to rent the whole physical machine at all times for confidential computing purposes, compared to the losses incurred by a breach.

It's actually several times cheaper to rent a whole physical machine than to rent a single Amazon VM of equivalent compute power.

Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

#19
post #11
post #10

There are microcode updates for this already https://www.amd.com/en/resources/product-security/bulletin/a...

but is it possible to verify that the cloud provider has applied the update?

The SEV-SNP attestation includes the microcode version. https://www.amd.com/content/dam/amd/en/documents/developer/l...

Re: Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

#20
post #2

I wonder how much more expensive it is to rent the whole physical machine at all times for confidential computing purposes, compared to the losses incurred by a breach.

It's actually several times cheaper to rent a whole physical machine than to rent a single Amazon VM of equivalent compute power.

Unless you want that whole machine to support IAM/VPC/EBS/etc and have proximity to your other VMs.
Post reply on HN