AMD memory encryption technologies
AMD memory encryption technologies
Posted Sep 12, 2016 19:25 UTC (Mon) by davidstrauss (subscriber, #85867)In reply to: AMD memory encryption technologies by Cyberax
Parent article: AMD memory encryption technologies
> The problem is with the client code that checks this certificate. It can easily be patched to accept fake certs.
Yes, but the guest would probably need to be restarted so the attacker can MitM the negotiation. If gaining malicious control of the hypervisor requires restarting guests to gain access, the attack still becomes a lot more noisy, which is still an improvement over today. I support making systems more tamper-evident even when we can't make them fully tamper-resistant.