6 ms·
Virtual machines can be considered a security boundary. Containers are absolutely not.
by openasocket 3y ago
Virtual machines can be considered a security boundary. Containers are absolutely not.
- dvt 3y agoThe distinction is getting more and more fuzzy, so this is almost a meaningless point (as is GGP). It's very vendor-specific, let alone that I'm pretty sure Spectre attacks can work across VMs.
- openasocket 3y agoI wouldn’t consider the distinction “fuzzy”. Assuming we’re talking Linux (I don’t know about the Mac and Windows world) containers are implemented using namespaces and cgroups, and always have been. Whether you are talking docker, containerd, some more minimalistic thing built on runc, it’s all Linux namespaces and cgroups. And those things were explicitly not designed to act as security boundaries when running untrusted code.
- deleted 3y ago[deleted]
- zokier 3y agoKata containers would like a word
- yjftsjthsd-h 3y agoNow in fairness, that is very specifically using a VM to add an even stronger boundry; it's not really the same thing.
- Kluggy 3y agoDoes anyone actually use Kata containers? I've tried recently to run them on a current Ubuntu platform and couldn't get it working at all after a few days of work.
- dharmab 3y agoYes, I worked for a very large tech company that used Kata.
- k1r1ka 3y agoIf it's Ubuntu, possible you had docker inside snap unintentionally and issues because of that? I had a bit trouble getting it integrated with certain versions of Podman, but that aside setting up kata was pretty straightforward. I have so far only used it for hosting some gameservers which I don't trust, i.e some simple containers, but I really want to try it in a new k3s cluster once I get it setup and move some services there. I like the idea of putting internet facing ones into it as an additional layer of separation and could imagine it being useful in production.
- pjmlp 3y agoAzure does, https://thenewstack.io/microsoft-adopts-openinfra-kata-containers-security-on-azure/ https://thenewstack.io/microsoft-adopts-openinfra-kata-conta... https://learn.microsoft.com/en-us/azure/confidential-computing/confidential-containers https://learn.microsoft.com/en-us/azure/confidential-computi...
- tptacek 3y agoThe distinction is in fact pretty clear. Conventional container runtimes are shared-kernel isolation. Virtual machines aren't: every tenant has their own running kernel.
- yjftsjthsd-h 3y agoWhy? Both are supposed to keep whatever is inside trapped unless you poke holes in that protection (say, using virtio or even just 9P to hand it real storage)
- lmm 3y agoBecause virtual machines were designed from the start to run untrusted code, and containers were not? > supposed to keep whatever is inside trapped unless you poke holes in that protection As far as I know that was never a design decision for containers on Linux; certainly not in the early days.
- zekrioca 3y agoThis doesn’t answer the question. How were VMs designed with security in mind and not with host emulation? Untrusted code? I’m confused, people are talking about vulnerabilities.
- icedchai 3y agoVMs don’t share the kernel with the host. Any host escape would need to happen through a device driver exposed to the guest (virtio, etc.) Containers use the same kernel, obviously a much larger set of code. More code means a greater chance of vulnerabilities.
- zekrioca 3y agoHow do you think the VM itself is spawned? Something in the host instantiate it. But even if we ignore that, I would argue that concentrating in one location only (e.g., some exposed driver) to escape is also easier, since an attacker would need to spend time trying to find only one vulnerability rather than several. I think the hardware can help bridging the gap between containers and VMs by enabling userspace processes behave as VMs, which is more or less what QEMU+KVM try to do, except that it still comes with some overheads and less flexibility.
- redserk 3y agoMisconfiguring or granting something unnecessary privileges is enough to eliminate anything as a security boundary. VMs easily give a false sense of security especially with any kind of network-based trust.
- openasocket 3y agoSure, anything that is misconfigured could eliminate a security boundary. That doesn’t mean that containers are even in the same ballpark as VMs in terms of providing a security boundary.
- zekrioca 3y agoWhy not?
- tptacek 3y agoEverything has the "network-based trust" problem, including isolated hardware.
- vaylian 3y agoWhat disqualifies containers as a security boundary?