Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not false sense of security: suspending VMs to disk. The contents of previously used, free memory that has not been reused by the kernel are written to disk. Now it has a lifetime far longer than RAM.


So you're essentially trying to protect against a hypervisor attack? That's never going to work unless you put the primitives in the hypervisor. Assuming you own it.


No, I'm trying to protect against somebody grabbing my laptop off the table and scraping the hard drive for suspended VM RAM contents from last month.


That's exactly the threat full disk encryption is designed for.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: