Damus

Recent Notes

lobo :nix_snowflake_logo: profile picture
https://www.youtube.com/live/AcOPLWc-_UE?si=02njYCVqRZpj9SEN

In the second video from #EuroBSDCon, the presentation focused on Confidential Computing and bringing #AMD #SEV (Secure Encrypted Virtualization) support to FreeBSD’s native hypervisor, `bhyve`. The talk broke down how hardware-enforced memory encryption isolates guest virtual machines from untrusted cloud providers and malicious host hypervisors.

The speaker walked through the zero-trust threat model, where an AES encryption engine built directly into the CPU's memory controller encrypts every byte of guest RAM on the fly.

By leveraging an isolated ARM-based co-processor the AMD Secure Processor encryption keys reside strictly within the hardware silicon throughout the VM's entire lifecycle. The host hypervisor acts as nothing more than an untrusted message router, meaning even a fully compromised host with root access sees only encrypted ciphertext when trying to dump guest memory.

To guarantee that the VM is running on genuine AMD hardware and untampered firmware, the implementation incorporates a robust remote attestation pipeline. Using the `sevctl` utility over a dedicated Unix domain socket exposed by `bhyve`, guest owners establish a secure Diffie-Hellman channel directly with the AMD Secure Processor.

They verify AMD's official certificate chain, validate a cryptographic measurement hash of the UEFI boot firmware (`OVMF`), and inject runtime secrets such as disk decryption keys—directly into encrypted guest RAM before the VM finishes booting.

A major technical highlight was overcoming multi-core (SMP) stability issues. In AMD SEV, a VM's encryption key is bound to a hardware Address Space Identifier (ASID). Standard hypervisors assign a fresh ASID when migrating a virtual CPU to a new physical core, which automatically clears out old Translation Lookaside Buffer (TLB) entries.

Because SEV keeps the exact same ASID across core hops, virtual CPUs were hitting stale memory mappings on old physical cores, causing frequent kernel crashes. The solution was implementing a targeted TLB flush for that specific ASID every time a virtual CPU migrates to a new core.
+++
lobo :nix_snowflake_logo: profile picture
They're going to miss the days when the topic was how annoying it's to correctly indent #YAML configurations (I feel that technical discussions) are gonna disappear very soon. Mainly because I suspect there is an absurd range of material being produced entirely by AI on the internet (people doing this to engage at any cost).
lobo :nix_snowflake_logo: profile picture
TODO MUNDO que usa o argumento (equilíbrio da economia) primeiro, ao tratar sobre o fim da escala 6x1, não faz a menor ideia do que está falando. Nunca leu nenhum anuario sobre o assunto. Nem sequer os dados da melhoria de qualidade de vida e economia que isso gera.
lobo :nix_snowflake_logo: profile picture
A turma ta deixando de fazer checagem de config/lógica e assumindo como verdade o que as LLms inferem. Mais do que isso, estão deixando de ler doc e delegando a leitura às llms. Às LLMs não se tornaram muleta. Se tornaram às pernas, o cerebro dessa galera. A firma em 100 anos acumulou erros criticos que estão sendo resolvidos (cerca de 350 mil).

Deste montante, em apenas um ano 15 mil erros criticos foram gerados inteiramente por llm só este ano. Ou seja, em 100 anos se continuar nesse ritmo, seria mais que o triplo de 350 mil com sobra. .
TracketPacer 🚀 · 51w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnddaehgu3wwp6kyqpqdw9kza63z9hsavfksqn60rw6gjdu0mqwyyh6w35qk49d4ukqvrpsh0jtex well thank you very much!