On Mon, Nov 14, 2016 at 2:42 PM, Jean-Philippe Ouellet wrote:
> On Mon, Nov 14, 2016 at 5:49 AM, Sec Tester wrote:
>> Could open up a vulnerability if not done carefully.
>>
>> VM could use it to query and identify other VMs in existence on the system.
>
> There are already several timing side-ch
On Mon, Nov 14, 2016 at 5:49 AM, Sec Tester wrote:
> Could open up a vulnerability if not done carefully.
>
> VM could use it to query and identify other VMs in existence on the system.
There are already several timing side-channel ways to do that.
Example:
AppVM$ time /usr/lib/qubes/qrexec-cli