![Tom Dohrmann Profile](https://pbs.twimg.com/profile_images/1712501627871993856/934jNF8o_x96.jpg)
Tom Dohrmann
@13erbse
Followers
205
Following
60K
Statuses
380
Joined February 2015
RT @orange_8361: The detailed version of our #WorstFit attack is available now! 🔥 Check it out! 👉 cc: @_splitline_
0
212
0
@GabrielKerneis @blitzclone Contrast by @EdgelessSystems (built with Kata Containers) works like that. The launch measurements for the firmware and kernel+initrd+cmdline are calculated ahead of time. The kernel command line contains arguments to mount a dm-verity protected disk. Everything's attested :)
1
0
3
@GabrielKerneis @blitzclone I think most people just don't use vTPMs when full attestation is available. If you really want a vTPM, something like COCONUT SVSM or OpenHCL could be used in the future to provide a trusted TPM. More details on the preview:
1
0
0
@blitzclone @GabrielKerneis I mean kinda? It doesn't feel like that for the L2 VM as it's not even aware that it's running as a nested VM, but I certainly see the similarities as well.
0
0
0
@blitzclone @GabrielKerneis Kata Containers (the tech used in this particular preview) uses a fairly minimal kernel config and boot image to cut down on attack surfaces exposed by the guest running inside the confidential L2 VM (It probably could be a bit smaller, though).
0
0
0
@GabrielKerneis @blitzclone In the preview (so likely not plain Azure VMs), the L1 VMs can send requests to the PSP, so CloudHypervisor running on the L1 VM will forward any requests from the L2 VM to the PSP and back:
2
0
0
@npmccallum @SEJeff @_msw_ Azure's confidential containers preview uses Kata Containers with CloudHypervisor to spawn confidential L2 VMs on top of the regular non-confidential Kuberenetes VMs:
0
1
0
@SwiftOnSecurity The latest episode of controlled pod into terrain discusses some of the interactions between WiFi and TDWR (terminal doppler weather radar) and how to prevent them
My CPIT cohosts and I recorded a charity episode to support victims of Hurricanes Helene and Milton: Listen to us talk about search and rescue helicopters and terminal doppler weather radar, with all proceeds going to disaster relief.
0
0
1
@drivsholm @awesomekling I had the same experience. I don't think it really shaped me in any way.
0
0
1
@blitzclone @draskodraskovic @enarxproject @ElasticProject_ @KubeCon_ Is it, though? I have never heard an Intel employee say that, and it's not like SGX has been dead ever since it's been deprecated on client CPUs. They added new features not that long ago. As of today, TDX attestation requires SGX, so until they add other options, SGX can't leave
1
0
0