Epyc fail? We can defeat AMD's virtual machine encryption, say boffins

Epyc fail? We can defeat AMD's virtual machine encryption, say boffins

7 years ago
Anonymous $CLwNLde341

https://www.theregister.co.uk/2018/05/25/amd_epyc_sev_vm_encryption_bypass/

German researchers reckon they have devised a method to thwart the security mechanisms AMD's Epyc server chips use to automatically encrypt virtual machines in memory.

So much so, they said they can exfiltrate plaintext data from an encrypted guest via a hijacked hypervisor and simple HTTP requests to a web server running in a second guest on the same machine.