Live data from Hacker News

Virtual Machine as a core Android Primitive

android-developers.googleblog.com

91–100 of 177 posts

Re: Virtual Machine as a core Android Primitive

#91
post #42

Earlier quoted context omitted.

While QEMU uses C, which is not great, it has on its side 15+ years of hardening by the KVM developers. The problem with QEMU is not so much insecurity, it's that it contains the kitchen sink. However, most of the exploits you'll find in QEMU are against configurations that are never used in real world virtualization scenarios where guests are untrusted. You can recognize them because hardware not commonly used with…

> You can recognize them because hardware not commonly used with untrusted guests does not get a CVE. This is not true. Even non default configuration of any software or hardware that contains a security vulnerability can get a CVE. It has in the past and will again in the future. Source: I have assigned over 2000 cves for the kernel.

Yes, and the policy of QEMU is to not assign CVEs for bugs that would generally be hit only when QEMU is used as a development platform, as opposed to using it to offer virtualization services.

https://www.qemu.org/contribute/security-process/

We are colleagues by the way. :)

Re: Virtual Machine as a core Android Primitive

#92
Back at university one lecture included an infographic about how CPU and operating system features like MMU, increasing register width and the like all started at mainframe-scale installations and trickled down to desktop scale systems and later to handheld devices at a surprisingly consistent pace. It was the time w2k was trying to make NT features mainstream and J2ME arrived on phones. I extrapolated a little and made a joke about multi-user concepts arriving on phones and a few years later Android was right on schedule (when that happened, repurposing Linux users as units of app isolation was the headline feature in tech news).

By that measure, virtualization is long overdue, but I really can't claim that I'm not surprised.

Re: Virtual Machine as a core Android Primitive

#93
post #88
post #78

Earlier quoted context omitted.

Where in my comment did I refer explicitly to KVM feature set, or that it is used by cloud vendors?

KVM is pretty much the only hypervisor that cloud vendors use these days. So it's true that "most cloud workloads run on type 1 hypervisors" (KVM is one) but not that most cloud vendors/workloads run on microkernel-like hypervisors, with the exception of Azure.

You definitly didn't understood my commment.

Re: Virtual Machine as a core Android Primitive

#94

Earlier quoted context omitted.

If Android phones can run non-Android VMs of the user's choice, the phones will gain new purpose.

Ok cool. But you and I both know that this feature was designed for the DMCA-lovin' Hollywood types and the control-freak enterprise IT BOFHs, not for your cool hack. Let's use their tools of oppression against them! (fist emoji)

Media and Enterprise already have TrustZone, Knox, Intune, etc. which work "enough".

Newer markets include cashless (CBDC) payments and digital identity anchored in human biology, demanding more security than legacy content.

> Biometrics: By deploying biometric trusted applets in an isolated virtual machine, developers will have the isolation guarantee, access to more compute power for biometric algorithms, easy updatability regardless of the Trustzone operating system, and a more streamlined deployment.

Fortunately, OSS can enable N-party transaction transparency, we don't have to settle for one-way mirrors and WeChat clones.

Re: Virtual Machine as a core Android Primitive

#95
post #93
post #88

Earlier quoted context omitted.

KVM is pretty much the only hypervisor that cloud vendors use these days. So it's true that "most cloud workloads run on type 1 hypervisors" (KVM is one) but not that most cloud vendors/workloads run on microkernel-like hypervisors, with the exception of Azure.

You definitly didn't understood my commment.

Then can you explain how cloud workloads is the revenge of the microkernel, since there is exactly 1 major cloud provider that uses a microkernel-like hypervisor?

Re: Virtual Machine as a core Android Primitive

#96
post #79

So what is something running in this virtual machine allowed to do? Talk to the Internet? Talk to the screen? Talk only to whatever started it? How much of this is closed source?

Possibly one cybersecurity-related thing you could do is run a headless browser inside this VM, and bridge the network requests to the host network (a little bit like Docker).

Using my open-source BrowserBox^0 project then you could have a "bit more isolated" Browser running on your Android device that would add "VM escape" to any zero-day exploit chain that might be a risk.

This is speculation tho, I don't know if it's actually feasible based on the Android reality right now, but assuming the capabilities that are provided are like a regular headless VM, then it should be. :)

0: https://github.com/BrowserBox/BrowserBox

Re: Virtual Machine as a core Android Primitive

#97
post #95
post #93

Earlier quoted context omitted.

You definitly didn't understood my commment.

Then can you explain how cloud workloads is the revenge of the microkernel, since there is exactly 1 major cloud provider that uses a microkernel-like hypervisor?

By not running monolithic kernels on top of bare metal, rather virtualized, or even better with nested virtualization, thus throwing out the door all the supposedly performance advantages in the usual monolithic vs microkernel flamewar discussions, regarding context switching.

Additionally to make it to the next level, they run endless amount of container workloads.

Re: Virtual Machine as a core Android Primitive

#98

Earlier quoted context omitted.

Websites will require digital ID just to use them, along with remote attestation. They will also be able to ban or block you in an actually effective and comprehensive way. There will be a chilling effect because people won't want to upset their Google/Microsoft/Apple/Meta etc overlords by saying or doing the wrong thing, and then get locked out of services they need to exist in society, do their job, spend money, et…

Digital ID exists and is widely used, yet I only need to use my digital ID to authenticate with government services. Remote attestation is the norm for many types of apps already yet I can use my bank app on my rooted phone just fine, or use my phone to authenticate with my government's SSO system. I'm no fan of the modern dependence on Play Services or Google's attempts to kill adblockers through remote attestation,…

Digital ID is safe from abuse by our ad overlords as long as it only happens in insular implementations for markets smaller than California. Things would look wildly different if digital ID was a thing in the USA (I find it rather amusing how they claim to have no ID at all, yet a decade in Europe seems to involve less presenting of ID than a month in the US involves presenting their driver's license ID substitute)

But I don't disagree, I'd rather have a rooted phone with a few islands out of my (and the software that I run!) control for sensitive authentication use cases than a phone where I'm not in control at all. Or than two phones, because only one of them can be rooted.

Re: Virtual Machine as a core Android Primitive

#99
post #52

How does two way isolation work? How do you prevent the host kernel (which presumably has full control of the hardware?) from inspecting the guest VM?

I don't know about Android, but AMD CPUs support encrypting regions of physical memory with different keys which are accessible only to one particular VM running, but also not accessible to the host:

AMD Secure Encrypted Virtualization (SEV)

https://www.amd.com/en/developer/sev.html

Re: Virtual Machine as a core Android Primitive

#100

Earlier quoted context omitted.

Maybe banking apps would let you run them on rooted phones if they were in an isolated VM

Every app will want to run in isolated VMs and rooting will mean nothing. It's like SafetyNet today, you can't run a good amount of apps on unapproved platforms already, even apps that don't handle confidential data.

In an ideal world, you could opt-out of isolation without giving the code in the container a way to know. You wouldn't want to opt-out your banking TAN generator just like you wouldn't want to put the password in your email footer, but a Facebook client would likely be a popular target (despite the hypothetical risk of an attacker destroying your reputation by posting in your name).
Post reply on HN