VM Security Debate

Comments debate the security isolation provided by virtual machines, questioning their effectiveness against host OS compromises, VM escapes, hypervisor vulnerabilities, and side-channel attacks.

➡️ Stable 0.6x Security
3,460
Comments
20
Years Active
5
Top Authors
#9168
Topic ID

Activity Over Time

2007
1
2008
16
2009
13
2010
31
2011
57
2012
71
2013
167
2014
192
2015
244
2016
235
2017
230
2018
322
2019
257
2020
224
2021
270
2022
254
2023
293
2024
258
2025
270
2026
57

Keywords

IT HVM AWS SAN IMO forum.qemu bloat.pdf crowdstrike.com example.com ASLR vm hypervisor host vms security attack virtualbox virtualization os exploitable

Sample Comments

c_c_c Jun 7, 2016 View on HN

Host OS being compromised is one thing. Hardware compromised? VM won't help you

rini17 Aug 7, 2020 View on HN

Does this solve a real problem? Such as, hardware owner leaking stuff from VMs was an issue?

TazeTSchnitzel Mar 6, 2016 View on HN

Beware that VMs are not necessarily secure. They can be escaped!

landemva Mar 12, 2022 View on HN

That works on bare metal you control. If you rent something with VM / hypervisor the mitigations are important to protect from other VMs on the machine.

oblio Dec 29, 2017 View on HN

I'm not sure I get this - are you saying that you are more at risk due to the VM host layer?

throwawayboise Dec 22, 2021 View on HN

VMs still provide better isolation and security, or is that no longer true?

abecedarius Sep 14, 2013 View on HN

The VM is easily vulnerable to the host OS, so running in a VM only protects the activities you do in the VM in the sense that the software pwning the host might not be looking for it. So not really.

bigodanktime Dec 22, 2021 View on HN

Counts what you are afraid against. There's always some side channel attack that could possibly used to gain information, even on VM's this is true. Off the top of my head there could be some timing attack to gain information on which libraries others are using by reading in libraries and seeing if they are warm in the buffer cache, counts if you care about sharing the same kernel. I generally find them secure enough considering how fast they can be brought up and down.

ec109685 Jul 29, 2023 View on HN

How does a VM not break privacy barriers?

eru Mar 4, 2013 View on HN

Wouldn't a vm help with security?