I'm really glad these guys valued their reputation higher than the extra money they could have gotten from selling these exploits on the blank market, but this makes me wonder how many such vulnerabilities are available that hasn't been published.
I'm really glad these guys valued their reputation higher than the extra money they could have gotten from selling these exploits on the blank market, but this makes me wonder how many such vulnerabilities are available that hasn't been published.
Hate to break this to you, but it's been shown time and time again that due to how caching and CPU pipelining works in modern processors, any "isolation" including full-on VM which is not "physical isolation" is leaky: https://pdfs.semanticscholar.org/e544/00824814fed2ef52bb8415... (overview of attacks)
Here is a particularly nice paper (proper methodology, well-explained intro, etc.) showing one example (a more or less regular cache timing attack, but with actual private info extraction from host, etc.): https://arxiv.org/abs/1702.08719 - these come up several times a year for various VMs, etc.
Of relevance to Edge exploitation, Microsoft are currently working on a Qubes-like sandboxing model for Edge, based on Hyper-V (though it looks like it'll be aimed towards enterprise customers rather than consumer): https://blogs.windows.com/msedgedev/2016/09/27/application-g.... Will be interesting to see if that's part of the challenge in Pwn2Own 2018. Somewhat surprisingly, Hyper-V wasn't successfully exploited at this year's contest.
And this is VMware Workstation, not ESXi; which many people on this thread seem to be confusing.
Otherwise if I installed those VMware tools on my physical computer and exploited them... to where do I escape? Alternate reality?
:-)
Not ever physical security is organized like that.
At best you can design for a certain level of determination of the attacker, and thats it. Any attacker that is more determined will eventually get past.
Question is what are you protection against.
Your garden variety identity scammer?
NSA?
Sometimes it feels like _sec has developed NSA myopia.