[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread raahelps
I can't find any poc for sound card. I imagine it would be possible though, maybe it depends on the card like probably a plugged in one. But i'm talking out my ass and have no idea what I'm talking about. Maybe in future qubes will be isolating the sound controller as well lol. -- You

[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread raahelps
On Friday, July 15, 2016 at 12:00:57 AM UTC-4, neilh...@gmail.com wrote: > Oh OK. I see you have now updated with a new answer. > > "The main benefit would be to try and prevent dma attacks from the network > card and the netvm, which receives all the packets from the internet" maybe just a

[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread neilhardley
So essentially, this is isolating the network card/Wifi from dom0.. Just like you create a USB qube, to isolate USB from dom0 But still.. no one has ever shown a proof of concept for this... You see plenty of videos of people exploiting browsers with Metasploit... but no videos of anyone doing

[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread raahelps
On Friday, July 15, 2016 at 12:00:11 AM UTC-4, raah...@gmail.com wrote: > On Thursday, July 14, 2016 at 11:57:48 PM UTC-4, neilh...@gmail.com wrote: > > But it's still not clear how these malicious packets can be sent to the > > network card can these be sent after compromising an App VM (via

[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread neilhardley
Oh OK. I see you have now updated with a new answer. "The main benefit would be to try and prevent dma attacks from the network card and the netvm, which receives all the packets from the internet" -- You received this message because you are subscribed to the Google Groups "qubes-users"

[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread raahelps
On Thursday, July 14, 2016 at 11:57:48 PM UTC-4, neilh...@gmail.com wrote: > But it's still not clear how these malicious packets can be sent to the > network card can these be sent after compromising an App VM (via > something like a browser exploit)...?? > > Or can they be sent just

[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread neilhardley
But it's still not clear how these malicious packets can be sent to the network card can these be sent after compromising an App VM (via something like a browser exploit)...?? Or can they be sent just purely over the internet itself to any device connected to the web...? Directly send

[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread raahelps
On Thursday, July 14, 2016 at 10:22:28 PM UTC-4, neilh...@gmail.com wrote: > From the user FAQ: > > https://www.qubes-os.org/doc/user-faq/#can-i-install-qubes-on-a-system-without-vt-d > > "an attacker could always use a simple DMA attack to go from the NetVM to > Dom0" > > So what does this

[qubes-users] Re: Question on DMA attacks

2016-07-14 Thread raahelps
On Thursday, July 14, 2016 at 10:22:28 PM UTC-4, neilh...@gmail.com wrote: > From the user FAQ: > > https://www.qubes-os.org/doc/user-faq/#can-i-install-qubes-on-a-system-without-vt-d > > "an attacker could always use a simple DMA attack to go from the NetVM to > Dom0" > > So what does this