Gentoo Archives: gentoo-hardened

From: Jesco Freund <jesco.freund@×××××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Mini Gentoo in VMWare
Date: Sat, 04 Nov 2006 22:16:49
Message-Id: 454D10C0.6070308@my-universe.com
In Reply to: [gentoo-hardened] Re: Mini Gentoo in VMWare by Kwon
1 Kwon wrote:
2 >> Considering that VMware server uses kernel modules for operation on the
3 >> host system. Also that it likes to run as root (I haven't checked to see
4 >> if it can run as an unprivileged user) and that it wants to use
5 >> xinetd... I would say that you should at least be careful with it.
6 >
7 > Yes! Indeed! My conclusion is that white box hardware costs are so cheap
8 > these days (CAD$300 to CAD$500 a box). I would rather have different
9 > physical systems in a DMZ rather than a software solution using VMWare.
10 >
11
12 100% ACK - there's nothing safer than separate hardware boxes. And yes,
13 there are practical issues that keep me away from using VMWare in a
14 high-risk production environment (i. e. stand-alone webserver, proxy,
15 firewall...)
16
17 But as far as I remember the original question was whether a para- or a
18 full virtualization provide more security - from the theoretical point
19 of view I still stick to the full virtualization as the more secure
20 solution. In real life, there may still be additional things to be
21 considered (such as resource needs, quality of the implementation...)
22
23 Just my $0,02
24 --
25 gentoo-hardened@g.o mailing list