Live data from Hacker News

Unfashionably secure: why we use isolated VMs

blog.thinkst.com

101–110 of 256 posts

Re: Unfashionably secure: why we use isolated VMs

#101

Earlier quoted context omitted.

Thank you for sharing, didn't know that one!

It's from the original Xen team. Subsequently cloned by MS as MDAG (Defender Application Guard).

Cool! I know MDAG and actually it's a pretty neat concept, kinda.

Re: Unfashionably secure: why we use isolated VMs

#102
post #99
post #91

Earlier quoted context omitted.

Not an especially impressive flex, but I'm not above trying to dunk on people for misspelling things either, so I'm not going to high-horse you about it (obviously i am). The history of KVM and hardware virtualization is not an endless clown parade. Find a vulnerability researcher to talk to about OpenBSD sometime, though. https://isopenbsdsecu.re/

OpenBSD is not secure by any measure. That Theo happens to be right about the endless clown parade is independent of his ability to develop a secure operating system. I mean, jeez, even Joanna Rutkowska acknowledges the foundations are iffy enough to only justify claiming “reasonably secure” for Qubes OS. You are making a extraordinary claim of security which stands diametrically opposed to the consensus that things…

So far all I'm seeing here are appeals to the names of people who I don't believe agree with your take. You're going to need to actually defend the argument you made.

Re: Unfashionably secure: why we use isolated VMs

#103
post #58

Earlier quoted context omitted.

>Personally FreeBSD Jails / Solaris Zones are the thing I like to dream are pretty much as secure as a VM and a perfect fit for a sane dev and ops workflow, I didn't dig too deep into this is practice, maybe I'm afraid to learn the contrary, but I hope not Having run both at scale, I can confirm and assure you they are not as secure as VMs and did not produce sane devops workflows. Not that Docker is much better, but…

A sane DevOps workflow is with declarative systems like NixOS or Guix System, definitively not on a VM infra in practice regularly not up to date, full of useless deps, on a host definitively not up to date, with the entire infra typically not much managed nor manageable and with an immense attack surface... VMs are useful for those who live on the shoulder of someone else (i.e. *aaS) witch is ALL but insecure.

I'm not sure what you're referring to here?

Our cloud machines are largely VMs. Deployments mean building a new image and telling GCP to deploy that as machines come and go due to scaling. The software is up to date, dependencies are managed via ansible.

Maybe you think VMs means monoliths? That doesn't have to be the case.

Re: Unfashionably secure: why we use isolated VMs

#104
post #58

Earlier quoted context omitted.

>Personally FreeBSD Jails / Solaris Zones are the thing I like to dream are pretty much as secure as a VM and a perfect fit for a sane dev and ops workflow, I didn't dig too deep into this is practice, maybe I'm afraid to learn the contrary, but I hope not Having run both at scale, I can confirm and assure you they are not as secure as VMs and did not produce sane devops workflows. Not that Docker is much better, but…

A sane DevOps workflow is with declarative systems like NixOS or Guix System, definitively not on a VM infra in practice regularly not up to date, full of useless deps, on a host definitively not up to date, with the entire infra typically not much managed nor manageable and with an immense attack surface... VMs are useful for those who live on the shoulder of someone else (i.e. *aaS) witch is ALL but insecure.

VMs are useful when you don't own or rent dedicated hardware. Which is a lot of cases, especially when your load varies seriously over the day or week.

And even if you do manage dedicated servers, it's often wise to use VMs on them to better isolate parts of the system, aka limit the blast radius.

Re: Unfashionably secure: why we use isolated VMs

#105

As a permanent "out of style" curmudgeon in the last ~15 years, I like that people are discovering that maybe VMs are in fact the best approach for a lot of workloads and the LXC cottage industry and Docker industrial complex that developed around solving problems created by themselves or solved decades ago might need to take a hike. Modern "containers" were invented to make things more reproducible ( check ) and sim…

I've always hated the docker model of the image namespace. It's like those cloud-based routers you can buy.

Docker actively prevents you from having a private repo. They don't want you to point away from their cloud.

Redhat understood this and podman allows you to have a private docker infrastructure, disconnected from docker hub.

For my personal stuff, I would like to use "FROM scratch" and build my personal containers in my own ecosystem.

Re: Unfashionably secure: why we use isolated VMs

#106
post #50

Earlier quoted context omitted.

I had to use eclipse the other day. How the hell is it just as slow and clunky as I remember from 20 years ago? Does it exist in a pocket dimension where Moore's Law doesn't apply?

I think it's pretty remarkable to see any application in continuous use for so long, especially with so few changes[0] -- Eclipse must be doing something right! Maintaining (if not actively improving/developing) a piece of useful software without performance degradation -- that's a win. Keeping that up for decades? That's exceptional. [0] "so few changes": I'm not commenting on the amount of work done on the project…

> without performance degradation

Not accounting for Moore's Law, yikes. Need a comparison adjusted for "today's dollars".

Re: Unfashionably secure: why we use isolated VMs

#107
post #105

As a permanent "out of style" curmudgeon in the last ~15 years, I like that people are discovering that maybe VMs are in fact the best approach for a lot of workloads and the LXC cottage industry and Docker industrial complex that developed around solving problems created by themselves or solved decades ago might need to take a hike. Modern "containers" were invented to make things more reproducible ( check ) and sim…

I've always hated the docker model of the image namespace. It's like those cloud-based routers you can buy. Docker actively prevents you from having a private repo. They don't want you to point away from their cloud. Redhat understood this and podman allows you to have a private docker infrastructure, disconnected from docker hub. For my personal stuff, I would like to use "FROM scratch" and build my personal contain…

> Docker actively prevents you from having a private repo.

In what ways? I use private repos daily with no issues.

Re: Unfashionably secure: why we use isolated VMs

#108
post #97
post #96

Earlier quoted context omitted.

Are you claiming it has no security vulnerabilities? If yes, care to present a proof. If no, then please estimate how big of a bug bounty would result in a reported critical vulnerability. If I put up a 1 G$ bug bounty, do you think somebody would be able to claim it within a year? How about 10 M$? Please justify this in light of Google only offering 250 k$ [1] for a vulnerability that would totally compromise the se…

I have no idea who you're talking to, but nobody on this thread has claimed anything has "no security vulnerabilities". If you think there isn't an implicit 7-figure bounty on KVM escapes, we are operating from premises too far apart for further discussion to be productive. My bigger problem though: I gave you a bunch of substantive, axiomatic arguments, and you responded to none of them. Of the three of them, which…

You presented arguments, but did not present any substantive, quantitative effects attributed to those changes. You have presented no quantitative means of evaluating security.

Furthermore, you have presented no empirical evidence that those changes actually result in meaningful security. No, I do not mean “better”, I mean meaningful, as in can protect against commercially-motivated hackers.

None of the systems actually certified to protect against state-actors used such a nonsensical process as imagining improvements and then just assuming things are better. Show a proof of correctness and a NSA pentest that fails to find any vulnerabilities, then we can start talking. Barring that, the explicit, above-board bug bounty provides a okay lower bound on security. You really need a more stable process, but it is at least a starting point.

And besides that, a 7-figure number is paltry. Google Cloud brings in, what, 11 figures? The operations of a billion dollar company should not be secured to a level of only a few million dollars.

So again, proofs of correctness and demonstrated protection against teams with tens to hundreds of millions in budget (i.e team of 5 competent offensive security specialists for 2 years, NSO group for a year, etc.). Anything less is insufficient to bet trillions of dollars of commerce and countless lives on.

Re: Unfashionably secure: why we use isolated VMs

#109
post #108
post #97

Earlier quoted context omitted.

I have no idea who you're talking to, but nobody on this thread has claimed anything has "no security vulnerabilities". If you think there isn't an implicit 7-figure bounty on KVM escapes, we are operating from premises too far apart for further discussion to be productive. My bigger problem though: I gave you a bunch of substantive, axiomatic arguments, and you responded to none of them. Of the three of them, which…

You presented arguments, but did not present any substantive, quantitative effects attributed to those changes. You have presented no quantitative means of evaluating security. Furthermore, you have presented no empirical evidence that those changes actually result in meaningful security. No, I do not mean “better”, I mean meaningful, as in can protect against commercially-motivated hackers. None of the systems actua…

So that's a no, then.

Actual LOL at "an NSA pentest".

Slightly later

A friend points out I'm being too harsh here, and that lots of products do in fact get NSA pentests. They just never get the pentest report. We regret the error.

Re: Unfashionably secure: why we use isolated VMs

#110

It's nice to see the Principle Of Least Access (POLA) in practical use. Some day, we'll have operating systems that respect it as well. As more people wake up to the realization that we shouldn't trust code, I expect that the number of civilization wide outages will decrease. Working in the cloud, they're not going to be able to use my other favorite security tool, the data diode. Which can positively guarantee ingre…

If you're coming by after the fact and scratching your head at what a data diode is, Wikipedia's page on the subject is a decent crib document. https://en.wikipedia.org/wiki/Unidirectional_network>
Post reply on HN