[email protected]: > So you're saying that you can run an entire Xen exploit without installing > anything to the hard drive at all... Just purely run it in the RAM itself.
Well, most GNU/Linux systems have a /tmp/ partition, which acts like a hard drive but is backed by RAM. So even if you removed the emulated hard drive from a Xen VM, I assume the /tmp/ partition could still be used by a hypothetical Firefox exploit much the same way that the hard drive could. I suppose removing the emulated hard drive might reduce the attack surface a bit, for the specific case of vulnerabilities in Xen's hard drive emulation code. I'm not a Xen expert by any means. Marek or one of the other Qubes devs would presumably be able to give a better answer than I can. > And what do you think about Selfrando..? > > Is this going to fix browser exploits once and for all, or will it just fall > to hackers..? Quoting the blogpost that you quoted: "This makes it much harder for someone to construct a reliable attack" AFAICT No one is claiming that Selfrando will "fix browser exploits once and for all", but they are claiming that, if it works as intended, it should increase the cost of attacks significantly. Defense in depth is a useful approach. Hence why it might make sense to use Xen, AppArmor, and Selfrando together, so that if a subset of them fail, you may still survive. Cheers, -Jeremy -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/979507bf-d1f9-b8db-5b9f-812b37256706%40airmail.cc. For more options, visit https://groups.google.com/d/optout.
signature.asc
Description: OpenPGP digital signature
