-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Patrick Schleizer:
> Recent security research shows that soundcards support surreptitiously
> switching line-out jacks into line-in by modifying the software stack.
> The way modern speakers and headphones are designed makes them readily
> usable as microphones. The Intel High Definition (HD) Audio standards
> which all modern consumer soundcards are based mandates this.
> 
> https://arxiv.org/ftp/arxiv/papers/1611/1611.07350.pdf
> 
> Does anyone know if XEN's emulated sound devices follow this standard?
> If yes then a malicious guest that can modify the virt sound hardware
> can turn PC speakers into surveillance devices even if the microphone is
> disabled on the host.
> 
> Asked on xen list:
> https://lists.xen.org/archives/html/xen-users/2016-12/msg00008.html

I don't know how other virtual sound support for Xen works. Qubes uses a
custom PulseAudio based solution which streams raw audio data via vchan.
A VM has (or should have) no control over the sound card configuration in
dom0 there. See gui-{daemon,agent-linux}/pulse
-----BEGIN PGP SIGNATURE-----

iQJDBAEBCgAtFiEEqieyzvOmi9FGaQcT5KzJJ4pkaBYFAlhEaQ8PHGh3NDJAaXBz
dW1qLmRlAAoJEOSsySeKZGgWkEIP+QEJ4nOHL0TjPhCms2k9i7Cnxq8j59skAEBG
sO5Pg9iH3bBWVYhEFa0qtWSWsc3IjFfu6RUOvDJNrsW/5wkxqcyOIYPDq4KBlq1+
XApfXhiQ7dZy6SzcmrCJbZi/GWZJ88AWuzqFxJm4T+iP2rmaHn0IigxCsqh/zX1o
l40wZMUq8QILS2CkwLy1gOY2U0/Xc5GNxZDu+Jst8GDq/fJ3n40sJaSzroXgSYbX
IjTHBsGmMmCe7qfQESK9+DJA9C4gvEzUwgRs+ztEmil7Z4vD7f3/fu8VPZuQbl/S
sQP1xU+Drwa2s2Hl3yQWgTzBWHtil44UguQnFgWZVtEEUJqSI8CIoKJXkXm6TitK
CYNvJ0Ar404lJx2OiR9MnXGB5r9W8eIIEUxOAYNhtJUoBsk5X0hXYi+Mi0hoRS1p
utRObmqczsxiXfK44e8tADSEuACpl3UsEJ2YHk/Qq7DlJqm4XXYfi88PJQ9Q+/DL
ycghxOv6272V6GT91KDqHiX0rP3CjhSGxa/JeBtKxss9giBnWLCJ02a1Dc7YDcmr
jDxBVm2wvAOXuRMt8VnR08jXMHTXyr1FVXjrUpimH0mwfRJmEijTStS3v0cL0jOx
MvsTVU3SwWAa/nAcTTNP9Z/qUm4odJqGHCDsKje0mrYwk7lS+gJi9ZE+Vuo7v3Ri
WDTE1UTs
=rWJM
-----END PGP SIGNATURE-----

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-devel" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-devel/8923b937-ac27-741d-9641-5953ceb327f3%40ipsumj.de.
For more options, visit https://groups.google.com/d/optout.

Reply via email to