undu

joined 1 month ago
[โ€“] undu@discuss.tchncs.de 27 points 2 weeks ago (1 children)

Xcp-ng might have the edge against bare metal because Windows uses virtualization by default uses Virtualization-Based Security (VBS). Under xcp-ng it can't use that since nested virtualization can't be enabled.

Disclaimer: I'm a maintainer of the control plane used by xcp-ng

[โ€“] undu@discuss.tchncs.de 5 points 3 weeks ago

But the individual network packets are usually at most 1500 byes long, and applications encrypt the content. Hashing doesn't prevent jack squat. It's more likely to be DNS + IP blocks