<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8992811497323121233.post2634856051835919127..comments</id><updated>2010-04-26T15:07:36.668-07:00</updated><category term='ASLR'/><category term='sandbox'/><category term='Virtualisation'/><category term='the sky is falling'/><category term='VMware'/><category term='Linux'/><category term='vulnerability'/><category term='Presentation'/><category term='seccomp'/><category term='TSC'/><category term='Windows'/><category term='Security'/><category term='NetBSD'/><category term='Java'/><category term='Apple'/><category term='side-channel'/><title type='text'>Comments on cr0 blog: Time-stamp counter disabling oddities in the Linux...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.cr0.org/feeds/2634856051835919127/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/2634856051835919127/comments/default'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/05/time-stamp-counter-disabling-oddities.html'/><author><name>Julien Tinnes</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-3372580533240061653</id><published>2009-06-08T17:52:15.077-07:00</published><updated>2009-06-08T17:52:15.077-07:00</updated><title type='text'>I agree.
If you can already execute code on the ho...</title><content type='html'>I agree.&lt;br /&gt;If you can already execute code on the host, RDTSC is not a flaw, it&amp;#39;s a tool you might use to exploit flaws.&lt;br /&gt;&lt;br /&gt;Removing access to it would only make sense if it could not be easily replaced, which is very likely not the case: I expect real-life exploitable flaws to not need that kind of accuracy anyway.&lt;br /&gt;&lt;br /&gt;Still, I don&amp;#39;t think disabling it in a sandbox is stupid: if you don&amp;#39;t need it, it&amp;#39;s an easier decision to take it away than to decide if you care about it. But removing a useful feature without a proven security benefit should be an option, not something mandatory.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/2634856051835919127/comments/default/3372580533240061653'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/2634856051835919127/comments/default/3372580533240061653'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/05/time-stamp-counter-disabling-oddities.html?showComment=1244508735077#c3372580533240061653' title=''/><author><name>Julien Tinnes</name><uri>http://www.blogger.com/profile/05636781178145883012</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/05/time-stamp-counter-disabling-oddities.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-2634856051835919127' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/2634856051835919127' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-155021837'/></entry><entry><id>tag:blogger.com,1999:blog-8992811497323121233.post-1345167902649469204</id><published>2009-05-31T15:53:20.755-07:00</published><updated>2009-05-31T15:53:20.755-07:00</updated><title type='text'>Side channels are a real problem, but they can oft...</title><content type='html'>Side channels are a real problem, but they can often be exploited remotely, which means that disabling TSC locally does not solve anything. For example, I released an advisory about a timing attack on Google Keyczar &lt;A HREF="http://rdist.root.org/2009/05/28/timing-attack-in-google-keyczar-library/" REL="nofollow"&gt;last week&lt;/A&gt;.&lt;br /&gt;&lt;br /&gt;Besides the RDTSC instruction, you can read the TSC value via MSR 10h. MSRs are privileged though.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/2634856051835919127/comments/default/1345167902649469204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8992811497323121233/2634856051835919127/comments/default/1345167902649469204'/><link rel='alternate' type='text/html' href='http://blog.cr0.org/2009/05/time-stamp-counter-disabling-oddities.html?showComment=1243810400755#c1345167902649469204' title=''/><author><name>Nate Lawson</name><uri>http://www.blogger.com/profile/11280644250533859717</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.cr0.org/2009/05/time-stamp-counter-disabling-oddities.html' ref='tag:blogger.com,1999:blog-8992811497323121233.post-2634856051835919127' source='http://www.blogger.com/feeds/8992811497323121233/posts/default/2634856051835919127' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-89920777'/></entry></feed>
