On Wed, 24 Oct 2007, L. V. Lammert wrote:
>Virtualization provides near absolute security - DOM0 is not visible to
In theory, you're correct.
In practice there are (at least) four questions which all must be
answered in the affirmative for this to be true:
1) Does the hardware architecture provide all of the hooks needed to
implement virtualization?
2) Does the specific hardware correctly implement that architecture?
3) Does the virtualization software architecture properly implement
virtualization?
4) Does the specific software correctly implement that architecture?
Answering any of those questions takes both a lot of work and, all too
often, access to information which is not generally available. And if
any of the answers is 'no', the security of anything run under that
virtualization may be fatally compromised -- no matter how secure that
software may be when run standalone.
Dave
--
Dave Anderson
| Linus Torvalds | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Mike Galbraith | Re: regression: CD burning (k3b) went broke |
| Con Kolivas | Re: -mm merge plans for 2.6.23 |
git: | |
| Gerrit Renker | [PATCH 24/37] dccp: Processing Confirm options |
| Linus Torvalds | Re: [GIT]: Networking |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| David Woodhouse | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
