Re: About Xen: maybe a reiterative question but ..

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Ben Goren
Date: Tuesday, October 23, 2007 - 8:35 pm

On 2007 Oct 23, at 5:57 PM, adam.getchell@gmail.com wrote:

 > Virtualization seems to have a lot of security benefits.

``Seems'' is the key word, here.

On hardware like an IBM mainframe that can acutally support what's
necessary for  secure virtual machines, sure. On  x86? Well, it'll
keep your kid sister out....

Virtualization is  wonderful for simultaneously  running different
operating  systems on  the same  (beefy) computer,  especially for
development or testing purposes. If  you occassionally need to run
something on  an operating system  other than your  preferred one,
it's great -- saves you the extra hardware or the reboot, lets you
do snapshots, etc.

For  Windows,  it's  also  wonderful. You  basically  have  to  be
nuts  to  have  a  single  Windows server*  doing  more  than  one
thing, but virtualization  lets you do exactly  that with relative
impunity. It's like splinting a broken  leg and giving a huge shot
of  painkillers to  the victim  -- you'd  never know  the leg  was
broken.

But that's about it. I suppose running Windows virtual machines on
a real OpenBSD  machine might ``have a lot  of security benefits''
in some perverted sense of the words,  but it's not like the VM is
magically going  to protect the virtual  machines or anything. And
if  the Windows  virtual machines  can still  talk to  the outside
world  or to  each other  (via simulated  network interfaces,  for
example), even those ``security benefits'' won't mean much.

Cheers,

b&

* Yes, the full stop here is appropriate.

[demime 1.01d removed an attachment of type application/pkcs7-signature which had a name of smime.p7s]
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
About Xen: maybe a reiterative question but .., carlopmart, (Mon Oct 22, 1:05 am)
Re: About Xen: maybe a reiterative question but .., Nick Guenther, (Mon Oct 22, 12:11 pm)
Re: About Xen: maybe a reiterative question but .., Jeff Quast, (Mon Oct 22, 3:07 pm)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Tue Oct 23, 12:07 am)
Re: About Xen: maybe a reiterative question but .., Luca Corti, (Tue Oct 23, 1:03 am)
Re: About Xen: maybe a reiterative question but .., Per-Erik Persson, (Tue Oct 23, 2:00 am)
Re: About Xen: maybe a reiterative question but .., Lars Noodén, (Tue Oct 23, 3:45 am)
Re: About Xen: maybe a reiterative question but .., Lars Hansson, (Tue Oct 23, 3:56 am)
Re: About Xen: maybe a reiterative question but .., Henning Brauer, (Tue Oct 23, 5:19 am)
Re: About Xen: maybe a reiterative question but .., Ted Unangst, (Tue Oct 23, 9:39 am)
Re: About Xen: maybe a reiterative question but .., adam.getchell, (Tue Oct 23, 5:57 pm)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Tue Oct 23, 6:14 pm)
Re: About Xen: maybe a reiterative question but .. , Damien Miller, (Tue Oct 23, 6:25 pm)
Re: About Xen: maybe a reiterative question but .., Ben Goren, (Tue Oct 23, 8:35 pm)
Re: About Xen: maybe a reiterative question but .., Adam Getchell, (Tue Oct 23, 10:41 pm)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 6:38 am)
Re: About Xen: maybe a reiterative question but .., Douglas A. Tutty, (Wed Oct 24, 6:58 am)
Re: About Xen: maybe a reiterative question but .., Chris Kuethe, (Wed Oct 24, 7:14 am)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 7:20 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 8:09 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 8:10 am)
Re: About Xen: maybe a reiterative question but .., Artur Grabowski, (Wed Oct 24, 8:25 am)
Re: About Xen: maybe a reiterative question but .., Christoph Egger, (Wed Oct 24, 8:33 am)
Re: About Xen: maybe a reiterative question but .., carlopmart, (Wed Oct 24, 8:45 am)
Re: About Xen: maybe a reiterative question but .., Ted Unangst, (Wed Oct 24, 11:09 am)
Re: Non-x86, Lars Noodén, (Fri Oct 26, 12:54 am)
Re: About Xen: maybe a reiterative question but .. , Carlo Gebhardt, (Fri Oct 26, 3:58 am)
Re: Non-x86, Martin Schröder, (Fri Oct 26, 4:39 am)
Re: Non-x86, mickey, (Fri Oct 26, 4:49 am)
Re: Non-x86, Ted Unangst, (Fri Oct 26, 8:28 am)
Re: Non-x86, Lars Noodén, (Fri Oct 26, 9:17 am)
Re: Non-x86, Martin Schröder, (Fri Oct 26, 9:23 am)
Re: Non-x86, Matthew Szudzik, (Fri Oct 26, 2:03 pm)
Re: Non-x86, Jeff Quast, (Sun Oct 28, 6:59 am)
Re: Non-x86, Douglas A. Tutty, (Sun Oct 28, 8:27 am)
Re: Non-x86, Lars Noodén, (Mon Oct 29, 9:53 am)
Re: Non-x86, Douglas A. Tutty, (Mon Oct 29, 2:47 pm)
Re: Non-x86, Matthew Szudzik, (Tue Oct 30, 11:26 am)