<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in Side-Channel Detection Attacks Against Unauthorized Hypervisors</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Tue, 04 Sep 2007 10:29:47 -0000</lastBuildDate><item><title>Re: Side-Channel Detection Attacks Against Unauthorized Hypervisors</title><link>http://www.matasano.com/log/930/side-channel-detection-attacks-against-unauthorized-hypervisors/#comment-2323027</link><description>Can we add a pwnie category for best blog post of the year? Anything describing security with sesame street chars is sure to become an instant classic... :)</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">TK</dc:creator><pubDate>Tue, 04 Sep 2007 10:29:47 -0000</pubDate></item><item><title>Re: Side-Channel Detection Attacks Against Unauthorized Hypervisors</title><link>http://www.matasano.com/log/930/side-channel-detection-attacks-against-unauthorized-hypervisors/#comment-2323026</link><description>Wow, that is a fantastic writeup Tom, thanks.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alfred Huger</dc:creator><pubDate>Thu, 23 Aug 2007 14:48:01 -0000</pubDate></item><item><title>Re: Side-Channel Detection Attacks Against Unauthorized Hypervisors</title><link>http://www.matasano.com/log/930/side-channel-detection-attacks-against-unauthorized-hypervisors/#comment-2323025</link><description>Your memory hierarchy diagram is beautiful.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Andrew</dc:creator><pubDate>Mon, 20 Aug 2007 22:09:03 -0000</pubDate></item><item><title>Re: Side-Channel Detection Attacks Against Unauthorized Hypervisors</title><link>http://www.matasano.com/log/930/side-channel-detection-attacks-against-unauthorized-hypervisors/#comment-2323024</link><description>The first link ("all over the place") is not kablamo. Also, the combinatoric cognitive dissonance of the HSAS, Sesame Street, and the memory hierarchy nearly made my head explode this morning.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Matt</dc:creator><pubDate>Mon, 20 Aug 2007 15:33:33 -0000</pubDate></item><item><title>Re: Side-Channel Detection Attacks Against Unauthorized Hypervisors</title><link>http://www.matasano.com/log/930/side-channel-detection-attacks-against-unauthorized-hypervisors/#comment-2323023</link><description>If run from within ring 0 of a guest operating system, of course; it will simply detect the fact that the guest is in fact a guest.&lt;br&gt;&lt;br&gt;But if run from within ring 0 of the host ("ring -1", as it were), it spots unexpected virtualization --- a "smoking gun" when the hypervisor is itself not expected to be virtualized.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Thomas Ptacek</dc:creator><pubDate>Mon, 20 Aug 2007 10:52:43 -0000</pubDate></item><item><title>Re: Side-Channel Detection Attacks Against Unauthorized Hypervisors</title><link>http://www.matasano.com/log/930/side-channel-detection-attacks-against-unauthorized-hypervisors/#comment-2323022</link><description>Excellent explanation Thomas. Still I don't see how it detects only unauthorized hypervisors. Won't legitimate use case of software running in a VM cause false positive?</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">yakov</dc:creator><pubDate>Mon, 20 Aug 2007 09:53:44 -0000</pubDate></item></channel></rss>