Re: About Xen: maybe a reiterative question but ..

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Friday, October 26, 2007 - 6:58 am

Well, this post seems to get a lot of attention throughout the Internet. I
normally do not participate on argumentations about opinions. However, I
feel like I should get involved, as this is the field I am currently
commencing my PhD research in.

First, I think Theo is right when he states, that adding another layer of
software doesn9t increase security. That9s what we all learned painfully in
the past
Chroot and jails come to mind
(One has to dig deeper to find the
problem) It is also true that the x86 was never designed to provide
virtualization, besides, it also lacks proper separation. It wasn9t designed
to be a success
it just happened and we have to live with it. (This reminds
me of Microsoft introducing their extension to DOS, called Windows)
There are A LOT of caveats when it comes to virtualize the x86 architecture.
That9s the reason why Intels VT and AMDs SVM are necessary at all. (SVM
which, btw, stands for secure virtual machine - marketing is also something
we have to live with, whether you believe in it or not.)

It would be desirable to start over, design a new, none backwards
compatible, virtualizable hardware. Best, put an extra abstraction layer on
top of the hardware (put it in the BIOS or Firmware) and only deal with
those interfaces. Add some crypto features
et. voila. **sigh**

Unfortunately, we are not living in a perfect world. So what can
virtualization do for us? Speaking of paravirtualization as in the previous
posts, it may add a little security in comparison to jails, but it adds a
lot of convenience as handling of VMs gets easier.
Which is the main selling point, so the major interest in the near future
will be the handling of those virtual machines, and unfortunately not
security. Security, or the way we (I/some) see it, does not sell as good as
features. I have no doubt that exploiting a VM will become reality sooner or
later.

However, I would like to keep the discussion going, maybe in a less
offensive way?!
Cheers Carlo

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
About Xen: maybe a reiterative question but .., carlopmart, (Mon Oct 22, 4:05 am)
Re: About Xen: maybe a reiterative question but .., Nick Guenther, (Mon Oct 22, 3:11 pm)
Re: About Xen: maybe a reiterative question but .., Jeff Quast, (Mon Oct 22, 6:07 pm)
Re: About Xen: maybe a reiterative question but .., Luca Corti, (Tue Oct 23, 4:03 am)
Re: About Xen: maybe a reiterative question but .., Ben Goren, (Tue Oct 23, 11:35 pm)
Re: About Xen: maybe a reiterative question but .., Douglas A. Tutty, (Wed Oct 24, 9:58 am)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Tue Oct 23, 9:14 pm)
Re: Non-x86, Lars Noodén, (Fri Oct 26, 3:54 am)
Re: Non-x86, Ted Unangst, (Fri Oct 26, 11:28 am)
Re: Non-x86, Lars Noodén, (Fri Oct 26, 12:17 pm)
Re: Non-x86, Martin Schröder, (Fri Oct 26, 12:23 pm)
Re: Non-x86, Lars Noodén, (Mon Oct 29, 12:53 pm)
Re: Non-x86, Matthew Szudzik, (Tue Oct 30, 2:26 pm)
Re: Non-x86, Douglas A. Tutty, (Mon Oct 29, 5:47 pm)
Re: Non-x86, Matthew Szudzik, (Fri Oct 26, 5:03 pm)
Re: Non-x86, Jeff Quast, (Sun Oct 28, 9:59 am)
Re: Non-x86, Douglas A. Tutty, (Sun Oct 28, 11:27 am)
Re: Non-x86, Martin Schröder, (Fri Oct 26, 7:39 am)
Re: Non-x86, mickey, (Fri Oct 26, 7:49 am)
Re: About Xen: maybe a reiterative question but .., Adam Getchell, (Wed Oct 24, 1:41 am)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 9:38 am)
Re: About Xen: maybe a reiterative question but .., Chris Kuethe, (Wed Oct 24, 10:14 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 11:10 am)
Re: About Xen: maybe a reiterative question but .., Artur Grabowski, (Wed Oct 24, 11:25 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 11:33 am)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 11:45 am)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 10:20 am)
Re: About Xen: maybe a reiterative question but .. , Damien Miller, (Tue Oct 23, 9:25 pm)
Re: About Xen: maybe a reiterative question but .. , Carlo Gebhardt, (Fri Oct 26, 6:58 am)
Re: About Xen: maybe a reiterative question but .., Per-Erik Persson, (Tue Oct 23, 5:00 am)
Re: About Xen: maybe a reiterative question but .., Ted Unangst, (Tue Oct 23, 12:39 pm)
Re: About Xen: maybe a reiterative question but .., Lars Hansson, (Tue Oct 23, 6:56 am)
Re: About Xen: maybe a reiterative question but .., Lars Noodén, (Tue Oct 23, 6:45 am)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Tue Oct 23, 3:07 am)
Re: About Xen: maybe a reiterative question but .., Henning Brauer, (Tue Oct 23, 8:19 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 11:09 am)
Re: About Xen: maybe a reiterative question but .., Ted Unangst, (Wed Oct 24, 2:09 pm)