Comment 3 for bug 1801733

Revision history for this message
Artom Lifshitz (notartom) wrote :

This is definitely nifty and impressive, but realistically will never be addressed. We recommend folks deploy with TLS on all internal services, including the message queue used for RPC. TLS makes this kind of in-flight RPC hacking even less of a concern in practice - because let's face it, if someone has gained enough access to modify in-flight RPC this way, setting VCPUs to a wrong value is the least of your concerns.