Browsing Posts in vDesign

Reading Time: 3 minutes Storage management is something unique and quite depending by the storage vendor. Solutions like VMware Virtual Volumes can simplify it by providing a common interface, but it’s more on the usage and consuming part, rather than the storage management part. The SNIA (Storage Network Industry Association) Swordfish specification is a standard that helps to provide a unified approach for the management of storage and servers in hyperscale and cloud infrastructure environments, making it easier for IT administrators to integrate scalable solutions into their data centers.

Reading Time: 4 minutes Datrium announced the shipment of DVX 4.0 Software, the third major software release in less than a year. Datrium DVX converges Tier 1 hyperconverged infrastructure (HCI) with scale-out backup and cloud disaster recovery (DR) and Cloud-Native Data Services. Datium promises that DVX enables up to 10 times more VMs to run at lower latency than HCI, enables 10 times faster VM restores than scale-out backup products, and with Cloud DVX, offers backup to cloud with up to 10 times lower AWS fees than many cloud backup providers, all in the same simple converged system.

Reading Time: 2 minutes Now that Meltdown and Spectre vulnerabilities are almost fixed, there is a new critical vulnerability for several Intel CPU called BranchScope, discovered by some researchers from four universities. It’s again a speculative execution issue, in the method a processor uses to predict where its current computational task. By exploiting this flaw, attackers with local access could pull data stored from memory that’s otherwise inaccessible to all applications and users.

Reading Time: 4 minutes Altaro is a fast-growing software company with easy to use and affordable (also for the price) backup solutions for small- to medium-sized businesses, specializing in backup for virtualized environments. After a beta period, with several different build, they have now officially released the new version 7.6.4.

Reading Time: 3 minutes VMware has released (on Feb, 15th) a new vCSA version: vCenter Server 6.5 U1f, with build number 7801515. This release patches the vCSA operating system (Photon OS) mainly against two vulnerabilities: bounds-check bypass (Spectre-1, CVE-2017-5753) and rogue data cache load issues (Meltdown, CVE-2017-5754). As of now, there is still no patch for branch target injection vulnerability (Spectre-2, CVE-2017-5715). VMware has also updated the security advisory dealing with all of its virtual appliances updates for Spectre and Meltdown vulnerabilities, VMSA-2018-0007. But note that VMSA-2018-0004.2 has not been updated yet, and it still report that the suggested version for […]

Reading Time: 2 minutes We are still far from a solution for the Meltdown and Spectre, considering the delay of the microcode releases and the complexity of the possible Spectre fixes… And now, some security researchers from NVIDIA and Princeton have discovered new variants of the Meltdown and Spectre flaws that may be more difficult to be fixed (but also to be exploited) than the originals.

Reading Time: 6 minutes The mitigations for Meltdown and Spectre issues have involved a combination of different type of fixes: some software based, such as Microsoft and Linux versions of the “kernel page table isolation” protection, but also fome hardware based, like the Intel’s microcode updates (part that is still missing in most cases). Both type of patches can cause performance overheads and have some kind of impact on your environment. But how can you estimate it (before apply the patches) and how can you measure it (when the patches have been applied)?

© 2024-2011 vInfrastructure Blog | Disclaimer & Copyright