zlacker

[parent] [thread] 0 comments
1. hga+(OP)[view] [source] 2010-04-08 14:35:22
This sounds quite interesting. Joanna Rutkowska has some some serious low level security work, including work on Xen.

Xen was chosen for a minimal TCB, with the plan of moving stuff out of Dom0 like networking now and filesystem(s?) next?/later.

Of particular interest is the graphics system, where the code running in Dom0 was kept as small as possible (2,500 LOC, with no plans for fancy 3D).

ADDED: From a message on the mailing list, an explicit decision was made that each VM would have its own X server: applications sharing one are not isolated, trying to fix that would be "non-trivial" (quite an understatement!) and "the X protocol and X server alone present a huge attack surface". Indeed....

If I had a spare machine that could run it I'd be kicking the tires right now.

[go to top]