zlacker

[parent] [thread] 5 comments
1. hsbaua+(OP)[view] [source] 2025-12-17 22:59:02
Virtual machines are treated as a security boundary despite the fact that with enough R&D they are not. Hosting minecraft servers in virtual machines is fine, but not a great idea if they’re cohosted on a machine that has billions of dollars in crypto or military secrets.

Docker is pretty much the same but supposedly more flimsy.

Both have non-obvious configuration weaknesses that can lead to escapes.

replies(2): >>hoppp+S4 >>kevinr+eh2
2. hoppp+S4[view] [source] 2025-12-17 23:32:24
>>hsbaua+(OP)
Yeah but why would somebody co-host military secrets or billions of dollars? Its a bit of a stretch
replies(1): >>hsbaua+q5
◧◩
3. hsbaua+q5[view] [source] [discussion] 2025-12-17 23:36:19
>>hoppp+S4
I think you’re missing the point, which was that high value targets adjacent to soft targets make escapes a legitimate target, but in low value scenarios vm escapes aren’t worth the R&D
replies(1): >>z3t4+gI
◧◩◪
4. z3t4+gI[view] [source] [discussion] 2025-12-18 06:30:51
>>hsbaua+q5
but if you can do it at scale it might still be worth it, like owning thousands of machines
5. kevinr+eh2[view] [source] 2025-12-18 17:12:07
>>hsbaua+(OP)
> Virtual machines are treated as a security boundary despite the fact that with enough R&D they are not. Hosting minecraft servers in virtual machines is fine, but not a great idea if they’re cohosted on a machine that has billions of dollars in crypto or military secrets.

While I generally agree with the technical argument, I fail to see the threat model here. Is it that some external threat would have prior knowledge that an important target is in close proximity to a less hardened one? It doesn't seem viable to me for nation states to spend the expensive R&D to compromise hobbyist-adjacent services in a hope that they can discover more valuable data on the host hypervisor.

Once such expensive malware is deployed, there's a huge risk that all the R&D money is spent on potentially just reconnaissance.

replies(1): >>hsbaua+Xu3
◧◩
6. hsbaua+Xu3[view] [source] [discussion] 2025-12-18 23:23:34
>>kevinr+eh2
Yes. Docker too.
[go to top]