- It's the applications, stupid
- Will a whitelist save personal computing?
- Thousands of Web sites under attack
- To solve the unsolvable problem
- Re-thinking the security of virtual machines
- Security Development Lifecycle trumps code complexity
- Is your Web site FIPS compliant?
- Computer security: Why have least privilege?
- Strategic security: Get a handle on authentication
- Control user installs of software
August 12, 2006 | Comments: (0)
Blue Pill is a Myth?
Excellent expert and counterpoint article to the Blue Pill technique.
Essentially says that Blue Pill can always be detected, and is very difficult to pull off.
Sent to me by my friend, steve@securityappraisers.net
Posted by Roger Grimes on August 12, 2006 01:23 PM
RATE THIS ARTICLE:
-

- COMMENTS
More blog postings against the indefensibility and viability of a Blue Pill attack vector.
http://www.vmware.com/vmtn/blog/
http://x86vmm.blogspot.com/2006/08/blue-pill-is-quasi-illiterate.html
Even our own Tom Yager has an excellent post on this.
http://weblog.infoworld.com/yager/archives/2006/06/blue_pill_is_an.html
While I'm posting the counterpoints to the Blue Pill hypothesis, I want to defend the Blue Pill's founder, Joanna Rutkowska, a bit.
1. She's one of the good hackers. She came up with the Blue Pill, but most of the hype isn't created by her
2. She even states it isn't rocket science to create.
3. So far, the only misconception she has spread is that it can't be detected. Heck, who hasn't ever been wrong before.
4. She presented her original paper and asked for feedback.
5. She was asked to make the presentations, not the other way around.
6. She doesn't hate AMD, it's just the platform she's working at the moment with her real job.
Counterpoint articles are helpful in furthering the discussion. It's helping to counteract the hype. Just don't blame the author for everything. This thing has blown way past her own control. She's been helpful and open to arguments since day 1.
TOP STORIES
Hyperconnected users growingSteve Jobs to keynote WWDC
CSC settles kickbacks case
MS previews SMB software
What does HP-EDS really mean?
Mac Office 2008 SP1 released
HP buys EDS for $13.9 billion
Corporate IT spending slows
MS targets smartphone market
Sun to clarify JavaFX plan
ADDITIONAL RESOURCES

- Application Security: Threats and How to Counter Them
- Why Linux Threats Mean Business
- Minding the Machines: PC Disaster Recovery for the Enterprise

- Protect Your Data with SSL
- Prevent Your Next Microsoft Exchange Outage
- 11 Myths About Microsoft Exchange Backup & Recovery





