this post was submitted on 04 Jun 2024
19 points (95.2% liked)

Linux

47988 readers
1220 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS
 

publication croisée depuis : https://lemmy.world/post/16156662

To be completely open, this is not a question about XCP-ng vs Proxmox. I'm open to doing everything in the cli, comparing two platforms is not my intention here.

I'm very interested in the security benefits one has over the other though. AFAIK Xen has a dedicated for security? I'd like to think that both are reasonably secure by default, but I do not get many hits for "KVM hardening", for example, only OS-level hardening advice.

Do both protect equally against attacks that try to escape the VM? Is there anything in terms of security that one has and the other doesn't?

I know this is not the usual kind of question that is asked on this sub, any help is greatly appreciated!

all 10 comments
sorted by: hot top controversial new old
[–] [email protected] 7 points 5 months ago (2 children)

From the FAQ of Qubes OS (i.e. most secure desktop OS for general use):

"Why does Qubes use Xen instead of KVM or some other hypervisor?"

"In short: we believe the Xen architecture allows for the creation of more secure systems (i.e. with a much smaller TCB, which translates to a smaller attack surface). We discuss this in much greater depth in our Architecture Specification document."

[–] [email protected] 2 points 5 months ago* (last edited 5 months ago)

Searching for "XenTCB" already brings a lot of useful results

[–] [email protected] 2 points 5 months ago
[–] [email protected] 4 points 5 months ago (1 children)

As KVM is part if the Linux kernel, I assume you'll have to look into kernel hardening instead, next to OS hardening. Hardware is also important to consider when talking about VM escaping. A CPU that supports better VM isolation features and encrypted memory

[–] [email protected] 1 points 5 months ago

Thanks, that's a great idea and I'll keep CPU support in mind