Researchers steal data from CPU cache shared by two VMs
A group of researchers say they can extract information from an
Amazon Web Services virtual machine by probing the cache of a CPU it
shares with other cloudy VMs.
A paper titled Hello from the Other Side: SSH over Robust Cache Covert Channels in the Cloud (PDF)
explains the challenges of extracting data from CPU cache, a very
contested resource in which the OS, the hypervisor and applications all
conduct frequent operations. All that activity makes a lot of noise,
defying attempts to create a persistent communications channel.
Until now, as the researchers claim they've built “a
high-throughput covert channel [that] can sustain transmission rates of
more than 45 KBps on Amazon EC2”. They've even encrypted it: the
technique establishes a TCP network within the cache and transmits data
using SSH.
The results sound scarily impressive: a Black Hat Asia session detailing their work promised to peer into a host's cache and stream video from VM to VM.
The paper explains that this stuff is not entirely
new, but has hitherto also not been entirely successful because it's
been assumed that “error-correcting code can be directly applied, and
the assumption that noise effectively eliminates covert channels.”
The authors knock both of those arguments over, the
first by figuring out a way to handle errors and the second with a
method of scheduling communication between two VMs.
The paper details those efforts extensively, names them a “Cache-based Jamming Agreement” and offer you working code on GitHub so you can build your own all-in-cache covert channel, either on-premises or in the cloud.
Tuesday, April 18, 2017
Friday, April 14, 2017
Don't expect the FTC to help with Net Neutrality, Privacy, or anything else related to Telecom
In a nutshell:
1. FTC is really really busy
2. They don't know anything about network
4. Oh the courts told them THEY CAN'T
Don't expect Google to herlp either - Techdirt has a really good article about it,
Wednesday, September 28, 2016
Yet another reason Verizon...
From Ars Technica...
Employee breached customer trust, profited from private phone data for years.
An Alabama man who worked as a Verizon Wireless technician has agreed to
plead guilty to a federal hacking charge in connection to his illegal
use of the company's computers to acquire customer calling and
location data. The man, Daniel Eugene Traeger, faces a maximum five
years in prison next month. He admitted Thursday that he sold customer
data—from 2009 to 2014—to a private investigator whom the authorities
have not named.
Great!
Tuesday, August 30, 2016
Was Hillary's server used for State Dept Business? While it was infected? It just keeps getting worse...
Oh I don't know - how did the State Department treat it? As a priority? Then maybe...
WASHINGTON (AP) — State Department staffers wrestled for weeks in December 2010 over a serious technical problem that affected emails from then-Secretary Hillary Clinton's home email server, causing them to temporarily disable security features on the government's own systems, according to emails released Wednesday.Techdirt calls it more frankly -
The emails were released under court order Wednesday to the conservative legal advocacy group Judicial Watch, which has sued the State Department over access to public records related to the presumptive Democratic presidential nominee's service as the nation's top diplomat between 2009 and 2013.
The emails, reviewed by The Associated Press, show that State Department technical staff disabled software on their systems intended to block phishing emails that could deliver dangerous viruses. They were trying urgently to resolve delivery problems with emails sent from Clinton's private server.
"This should trump all other activities," a senior technical official, Ken LaVolpe, told IT employees in a Dec. 17, 2010, email. Another senior State Department official, Thomas W. Lawrence, wrote days later in an email that deputy chief of staff Huma Abedin personally was asking for an update about the repairs. Abedin and Clinton, who both used Clinton's private server, had complained that emails each sent to State Department employees were not being reliably received.
After technical staffers turned off some security features, Lawrence cautioned in an email, "We view this as a Band-Aid and fear it's not 100 percent fully effective."
Emails Show Hillary Clinton's Email Server Was A Massive Security Headache, Set Up To Route Around FOIA Requests
from the breaking-badly dept
More bad news for Hillary Clinton and her ill-advised personal email server. Another set of emails released by the State Department shows the government agency had to disable several security processes just to get its server to accept email from Clinton's private email address.
Tuesday, August 9, 2016
Are the Democrats *REALLY* accusing Wikileaks?! Bernie?! and Trump?!?! of being RUSSIAN SPIES!?
From the Intercept
Is Hillary getting worried?
From Drudge
OTOH, the New York Times, has an interesting article..
Cash Flowed to Clinton Foundation Amid Russian Uranium Deal
...
Beyond mines in Kazakhstan that are among the most lucrative in the world, the sale gave the Russians control of one-fifth of all uranium production capacity in the United States. Since uranium is considered a strategic asset, with implications for national security, the deal had to be approved by a committee composed of representatives from a number of United States government agencies. Among the agencies that eventually signed off was the State Department, then headed by Mr. Clinton’s wife, Hillary Rodham Clinton.
Tuesday, July 26, 2016
Will the FCC PLEASE SCHWACK COMCAST!?
According to ARS, On the Comcast cable box - Netflix won't be exempt from data caps, unlike Comcast content, which is.
Here's the link:
http://arstechnica.com/information-technology/2016/07/netflixs-cable-box-deal-with-comcast-wont-exempt-it-from-data-caps/
DOES NO ONE UNDERSTAND TEXTBOOK ANTI-COMPETITIVE BEHAVIOR BY A PROTECTED UTILITY?!?!?!
CAN I BE ANY CLEARER?
PLEASE?!?!
Here's the link:
http://arstechnica.com/information-technology/2016/07/netflixs-cable-box-deal-with-comcast-wont-exempt-it-from-data-caps/
DOES NO ONE UNDERSTAND TEXTBOOK ANTI-COMPETITIVE BEHAVIOR BY A PROTECTED UTILITY?!?!?!
CAN I BE ANY CLEARER?
PLEASE?!?!
Yes, Malvertising is real
Hello all - I was getting slow response on Firefox ( Maybe the Intel I5 is showing its age - Nah ), so I followed the instructions to reset. Unbeknownst to me, UBlock Origin was deleted =:-O.
Visiting Drudge a little while later, I got this:

Zooming in:

So this probably isn't a real Firefox patch
Be careful out there folks.
Visiting Drudge a little while later, I got this:

Zooming in:

So this probably isn't a real Firefox patch
Be careful out there folks.
Subscribe to:
Posts (Atom)
