Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Onidel Cloud's Thread - Announcements, Feedbacks and Discussions!

191011121315»

Comments

  • MannDudeMannDude Patron Provider, Veteran
    edited May 22

    Just wanted to say that @onidel has been great and we've migrated some of our production off-site stuff over to them.

    Just using the Singapore and Amsterdam locations now. Particularly happy that they use @RoyaleHosting as an upstream in Amsterdam since we also use them for for DDoS protection of production stuff. Currently our WAF is hosted there with some backend stuff now with Onidel. Keeps things snappy.

    I guess I should have checked this thread for coupons or something now that I've gotten 6 VMs with them and two block storage addons.

  • DPDP Administrator, The Domain Guy

    Me waiting for a HF-1 in SG :smiley:

    Thanked by 2Smigit admax
  • olokeoloke Member, Host Rep

    Good morning :)

    I'm happy to announce Onidel now fully supports Measured Direct Boot with SEV-SNP in all locations where SEV-SNP is supported. This allows customers to verify the integrity of core system components (uefi/ovmf, kernel, kernel parameters and initramfs) enabling confidential computing workloads.

    To make use of this feature, you'll need to enable SEV-SNP on your VM, then create an Unified Kernel Image (UKI) and upload it to our platform. This way the hash of UKI can be included in special OVMF section and later measured by the trusted AMD Secure Processor.

    More details here:
    https://kb.onidel.com/hc/kb/articles/1781997293-amd-sev_snp-expected-launch-measurement-verification

    If you run into any issues, please ensure your guest OS/kernel supports SEV-SNP and if that doesn't solve the problem, then let us know via ticket.
    Feedback regarding this feature is also very welcome :3

  • rpqurpqu Member

    @oloke said:
    Good morning :)

    I'm happy to announce Onidel now fully supports Measured Direct Boot with SEV-SNP in all locations where SEV-SNP is supported. This allows customers to verify the integrity of core system components (uefi/ovmf, kernel, kernel parameters and initramfs) enabling confidential computing workloads.

    To make use of this feature, you'll need to enable SEV-SNP on your VM, then create an Unified Kernel Image (UKI) and upload it to our platform. This way the hash of UKI can be included in special OVMF section and later measured by the trusted AMD Secure Processor.

    More details here:
    https://kb.onidel.com/hc/kb/articles/1781997293-amd-sev_snp-expected-launch-measurement-verification

    If you run into any issues, please ensure your guest OS/kernel supports SEV-SNP and if that doesn't solve the problem, then let us know via ticket.
    Feedback regarding this feature is also very welcome :3

    I thought the key was some kind of dildo.

  • tentortentor Member, Host Rep

    @oloke said:
    Feedback regarding this feature is also very welcome :3

    What about implementing UKI upload via API? https://developers.onidel.com/ currently lacks this.

  • MurvMurv Member, Megathread Squad

    @oloke said:

    I'm happy to announce Onidel now fully supports Measured Direct Boot with SEV-SNP in all locations where SEV-SNP is supported.

    Thansk, I can finally store my goon stash sicurely

  • olokeoloke Member, Host Rep

    @tentor said:

    @oloke said:
    Feedback regarding this feature is also very welcome :3

    What about implementing UKI upload via API? https://developers.onidel.com/ currently lacks this.

    Thank you for pointing this out. We will add an API for uploading and managing uki kernel images soon.

  • forestforest Member

    @oloke said: If you run into any issues, please ensure your guest OS/kernel supports SEV-SNP and if that doesn't solve the problem, then let us know via ticket.
    Feedback regarding this feature is also very welcome :3

    This is awesome!

    One small suggestion is that you may want to disclaim that it does not protect entirely against physical compromise, which is something a lot of users of confidential computing technology don't fully realize.

    Thanked by 2oloke buggedout
  • tentortentor Member, Host Rep

    @forest said:
    One small suggestion is that you may want to disclaim that it does not protect entirely against physical compromise, which is something a lot of users of confidential computing technology don't fully realize.

    I fail to understand if this attack is DDR5-only or researchers just skipped DDR4?

  • forestforest Member
    edited 6:30AM

    @tentor said:

    @forest said:
    One small suggestion is that you may want to disclaim that it does not protect entirely against physical compromise, which is something a lot of users of confidential computing technology don't fully realize.

    I fail to understand if this attack is DDR5-only or researchers just skipped DDR4?

    It'll work with DDR4 too. In fact, DDR4 is probably easier since it runs at a lower speed. It'll work as long as the memory can be run with an interposer (which can be done with DDR5 all the way to SDR).

  • tentortentor Member, Host Rep

    Oh yeah I completely missed the link to https://batteringram.eu/

  • forestforest Member
    edited 6:39AM

    @tentor said:
    Oh yeah I completely missed the link to https://batteringram.eu/

    It works with such a cheap interposer because you can configure even DDR5 to run at very low speeds. The BatteringRAM attack only works on DDR4, but could in theory be modified to support DDR5.

    This attack does require cooperation with whoever is running the node, though. You can't just splice an interposer into a running system without interrupting it. But if you do have access to the system and root on the node, it allows you to bypass the protections that are supposed to ostensibly prevent anyone at all from accessing the guests unauthorized.

    Thanked by 2tentor rpqu
Sign In or Register to comment.