Based on 2 Xen exploits in just the last 1 year, QUBES 4.0 is moving over to using SLAT / EPT for memory isolation, and to using HVM/PVH rather than PV.
Certainly, in the last 2 Xen exploits, it has only affected PV and not HVM. However, is it possible that using Intel's EPT is even riskier..? Intel ME is said to be insecure by Joanna Rutkowska due to its insecure implementation, and not being able to look at the code, because it is closed-source. Well, couldn't the same be said for Intel's EPT..? Surely this is closed-source too..? No..? At least with Xen, we can actually see the code and fix the bugs, whereas surely with Intel we have no chance. Or am I missing something here..? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/fb61e544-740e-4e7a-a837-898e507d2711%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.