Yet Another Reason Containers Don't Contain: Kernel Keyrings
projectatomic.io
projectatomic.io
"x86 virtualization is about basically placing another nearly
full kernel, full of new bugs, on top of a nasty x86
architecture which barely has correct page protection. Then
running your operating system on the other side of this brand
new pile of shit.
You are absolutely deluded, if not stupid, if you think that a
worldwide collection of software engineers who can't write
operating systems or applications without security holes, can
then turn around and suddenly write virtualization layers
without security holes."
See http://web.archive.org/web/20120513060008/http://kerneltrap.... for discussion/context.Totally totally totally. I loved building VMs with BSD jails, and was excited to try out LXC a couple of years back - and it felt similar to very early years of the big jails push - all was working but kinks still existed and the user land was immature.
This is not stuff that great UX with Ansible will fix - the underlying mechanisms will still take a couple of years to shake out. We will run on them but ... Keep your secrets close.
https://blog.sandstorm.io/news/2014-08-13-sandbox-security.h...
You can break out of a jail if there is a local exploit that gives kernel code execution as non root.
I can easily find some for the other BSDs (I am a NetBSD developer), of course there was the famous remote code execution for OpenBSD [2].
Security is hard, all code has bugs. Never be complacent. Use layers of security, reduce risks, audit,...
[1] https://www.freebsd.org/security/advisories/FreeBSD-SA-08:07...
Well, this has always been true of any sandbox or virtual machine.
> But this bug is to do with the fact that Linux just has a lot more complex kernel functionality than the BSDs do.
Also probably true. The linux kernel was not built to be namespaced, unfortunately, so bolting no namespacing will have edge cases that are not covered. I would not recommend anyone use linux containerization for production environments for some years.
Well, this has always been true of any sandbox or virtual machine.
That's not true for Virtual Machines.
I would not recommend anyone use linux containerization for production environments for some years.
Too bad people have been doing it for years - successfully - already. For example, most PAAS products use linux containers for isolation and as a security layer.
OpenVZ (ie, early version of Linux containers) has been used in production hosting environments to give people root shell access for just as long.
That's certainly an opinion: http://www.ubuntu.com/usn/usn-2342-1/
> It was discovered that QEMU incorrectly handled certain PCIe bus hotplug operations. A malicious guest could use this issue to crash the QEMU host, resulting in a denial of service
Most virtualization servers are great big chunks of C and C++ running as root with a bunch of crazy optimizations for benchmarks. They get some help from the ISA, but... stuff happens.
I'm not arguing that people haven't successfully run in production, but doing so and assuming you won't be hit with a zero-day exploit is just naive.