LWN.net Logo

Is virtualisation a viable alternative to MAC ?

Is virtualisation a viable alternative to MAC ?

Posted Aug 6, 2010 10:43 UTC (Fri) by job (guest, #670)
In reply to: Is virtualisation a viable alternative to MAC ? by copsewood
Parent article: AppArmor set to be merged for 2.6.36

I would expect it to be _much_ easier to construct a secure chroot than to make a secure VM. All that hardware to control guest kernel access to must be a nightmare to get right. Plus it is considerably easier to verify the security.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds