logoalt Hacker News

Topfitoday at 12:10 PM3 repliesview on HN

I feel that, in fairness, one should at least read Adam’s response, though ideally all subsequent mails: https://marc.info/?l=openbsd-misc&m=119320496730314&w=2

Theos is a very opinionated and not necessarily wrong position, but I feel also a bit too reductive given we are eternally having to deal with compromises of some form. Also, lest we forget, it has been two decades in the interim and oh so much has changed. In any case, this originated from their code, not virtualization, so it doesn’t really apply either way…


Replies

chmod775today at 1:00 PM

That's an impressive amount of maturity and composure Adam demonstrates there after receiving a response like that.

sdcfgytoday at 1:33 PM

I think it's pretty much spot on myself and applies to more than virtualization based on the last point. It really suggests that further complexity and abstraction is not a good security posture. And I agree with this from extensive experience (embedded, defence).

Regarding the two decades since and the numerous exploitable x86-64 and hypervisor bugs suggests he wasn't wrong and that the tone was appropriate for the severity of the problem.

Betelbuddytoday at 1:45 PM

In all fairness also read this: https://taviso.decsystem.org/virtsec.pdf

show 1 reply