avsm changed the topic of #mirage to: mirage 2 released! party on!
pierpa has quit [Ping timeout: 245 seconds]
yegods has quit [Remote host closed the connection]
mort___ has joined #mirage
mort___ has left #mirage [#mirage]
demonimin has quit [Ping timeout: 256 seconds]
pierpa has joined #mirage
dezzy_ is now known as dezzy
lobo__ has joined #mirage
musha68k has joined #mirage
NhanH has quit [Quit: Connection closed for inactivity]
ansiwen has joined #mirage
<ansiwen>
hi there, I have a question:
<ansiwen>
what is the plan for dom0 security? it is my understanding, no matter how secure the unikernel is, as long as the dom0 is still running a standard OS you don't gain much on security because it has full access to the domUs and is therefore the weakest link in the chain. is this correct?
<ansiwen>
if you can answer that or link me to a site explaining that, it would be great
mort___ has joined #mirage
<hannes>
ansiwen: yes, dom0 is an attack vector... goal is to minimize what it needs to do... maybe a hypervisor with scheduler, some memory management, and a network device driver is enough? :)
mort___ has quit [Quit: Leaving.]
<ansiwen>
hannes: I thought all of these things Xen itself could provide. I thought dom0 is just necessary for VM management (create, kill,...)
<ansiwen>
so, would be great if MirageOS also can build a dom0 unikenrel for these tasks...
<ansiwen>
ok, I just looked it up. Xen requires the drivers to be in dom0 (or another VM if disaggregated).,,
<ansiwen>
so, what is considered the safest dom0 at the moment, given you want to implement a high-security service with MirageOS?
brson has joined #mirage
AltGr has joined #mirage
AltGr has left #mirage [#mirage]
mort___ has joined #mirage
mort___1 has joined #mirage
lobo__ has quit [Quit: WeeChat 1.3]
mort___ has quit [Ping timeout: 245 seconds]
yegods has joined #mirage
mort___1 has quit [Quit: Leaving.]
brson has quit [Ping timeout: 250 seconds]
mort___ has joined #mirage
mort___1 has joined #mirage
brson has joined #mirage
mort___ has quit [Ping timeout: 276 seconds]
mort___1 has quit [Quit: Leaving.]
nullcat has quit [Ping timeout: 276 seconds]
nullcat has joined #mirage
brson has quit [Ping timeout: 276 seconds]
brson has joined #mirage
mort___ has joined #mirage
yegods has quit [Remote host closed the connection]