[Freedombox-discuss] Policy questions

Sandy Harris sandyinchina at gmail.com
Sun May 8 09:35:52 UTC 2011


On Sun, May 8, 2011 at 5:00 PM, Jonas Smedegaard <dr at jones.dk> wrote:

>> > There may also be problems with the VM method.
>> > Random numbers are one. ...
>> >
>> > This is just one problem that seems obvious.
>> > Has anyone done a security audit on one of
>> > the VM methods? Without that, should it be
>> > trusted?
>>
>> Maybe the cloud companies have done some research on that? You have a
>> valid question here. I'm very interested how secure the virtualization
>> i use (LXC) is.
>
> You expect cloud companies to have done research in running
> virtualization on crippled hardware without dedicated RNG or even CPU
> virtualization support?

There is some research, but none I have seen is encouraging.
PDFs of conference papers:

www.isoc.org/isoc/conferences/ndss/10/pdf/15.pdf
www.usenix.org/events/hotos05/prelim_papers/garfinkel/garfinkel.pdf
eprint.iacr.org/2009/474.pdf



More information about the Freedombox-discuss mailing list