Re: About Xen: maybe a reiterative question but ..

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: misc@openbsd.org <misc@...>
Date: Wednesday, October 24, 2007 - 3:29 pm

Can Erkin Acar wrote:

Contrariwise, there is *some* security benefit to running all the
services virtualized, compared to running all the services on the same
machine but *not* virtualized. In that case, though, you're not getting
any improved resource utilization, and you're going with a very
complicated and unaudited system (with arbitrary code execution bugs
coming to light *this month*) to achieve "improved security."

You can achieve a lot of the promises of virtualized servers (with
fewer moving parts, and more code audits) using chroot and login classes
to run many services on a single big machine.
--
Matthew Weigel
hacker
unique@idempot.net

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: About Xen: maybe a reiterative question but .., Can Erkin Acar, (Wed Oct 24, 2:42 pm)
Re: About Xen: maybe a reiterative question but .., Matthew Weigel, (Wed Oct 24, 3:29 pm)
Re: About Xen: maybe a reiterative question but .., Jason Dixon, (Wed Oct 24, 4:27 pm)