Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


openvz vs kvm in security - Page 2
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

openvz vs kvm in security

2»

Comments

  • eoleol Member
    edited January 2019

    @dahartigan said:
    KVM lets you encrypt your file system. OpenVZ does not. Your files are all in /var/lib/vz/yourvps basically.

    Any idiot scam host could very easily snoop on your files on OpenVZ. It would take a skilled and determined host to break into your encrypted KVM, those are the hosts that you want to avoid. Trouble is they would be the most competent system admins.

    The point is, go with a host you trust, and if you trust them make sure you trust any 3 letter organization that is also interested in your data. Suddenly you reach a level of paranoia that makes you question everything, including yourself.

    I think they are watching me type this..

    I think it's even worse.
    They used mind-control to make you type this.

    EDIT2:

    Thanked by 1dahartigan
  • @dahartigan said:
    It would take a skilled and determined host to break into your encrypted KVM, those are the hosts that you want to avoid. Trouble is they would be the most competent system admins.

    If your VPS is running, it doesn't matter how encrypted you think it is. All you need to do is alter the kvm- module and dump whatever you want. The truth is, everything is based upon some level of trust. If you can't trust your host, you need to do it all yourself, and then you still have the issue of colocation/et al.

    OpenVZ is not the complete hardware virtualization that KVM is, and due to how it shares resources, it's likely quite a bit less secure, but anyone with root access can pretty much do the same with a KVM that they can with your OpenVZ ploop. They just probably don't care what you're doing with your <$10 shitbox, unless it's illegal.

  • on OpenVZ - "Wouldn't touch it with @Letzien's penis." -@AuroraZ

    Thanked by 1eol
  • jsgjsg Member, Resident Benchmarker

    A good door lock keeps most people out of your house. But of course LEA or
    determined and capable criminals will get in anyway. Does that mean that we shouldn't use door locks? I don't think so.

    The way I see it KVM is like a normal door with a 50$ lock while OVZ is more like a toilet stall with a 5$ "free/occupied" switch. To "break into" an OVZ stall all that's needed i basically just a lack of good manners; to break into a KVM VPS one needs at least some determination and capabilities.

    That said, almost all VPSs run on and use quite questionable material (-> X86 AMT, KVM itself, etc, not at all secure OSs, etc.).

    Plus - and that's interesting and important - many users do not even use what's available in terms of security and seem to not care much.

    But still, KVM, as opposed to OVZ, is a real VM and offers at least a reasonable basis for reasonable security. Against LEA, the NSA, or similar none of the virtualization systems can protect but that's true for almost all OSs, too.

    Plus:

    @Letzien said:
    They just probably don't care what you're doing with your <$10 shitbox, unless it's illegal.

    Yes. Indeed an important factor but I would change that to "sufficiently illegal".

  • @ehab said:
    on OpenVZ - "Wouldn't touch it with @Letzien's penis." -@AuroraZ

    Uh, what? When did he say that?

    Thanked by 1ehab
  • @Letzien said:

    @ehab said:
    on OpenVZ - "Wouldn't touch it with @Letzien's penis." -@AuroraZ

    Uh, what? When did he say that?

    Way back and you told not talk with my mouth full.

    Thanked by 1ehab
  • @AuroraZ said:

    @Letzien said:

    @ehab said:
    on OpenVZ - "Wouldn't touch it with @Letzien's penis." -@AuroraZ

    Uh, what? When did he say that?

    Way back and you told not talk with my mouth full.

    Shit who has time to remember that shit?

  • @Letzien said:

    @AuroraZ said:

    @Letzien said:

    @ehab said:
    on OpenVZ - "Wouldn't touch it with @Letzien's penis." -@AuroraZ

    Uh, what? When did he say that?

    Way back and you told not talk with my mouth full.

    Shit who has time to remember that shit?

    Some of us have memories that are longer then your penis.

    Thanked by 2eol ehab
  • @AuroraZ said:

    @Letzien said:

    @AuroraZ said:

    @Letzien said:

    @ehab said:
    on OpenVZ - "Wouldn't touch it with @Letzien's penis." -@AuroraZ

    Uh, what? When did he say that?

    Way back and you told not talk with my mouth full.

    Shit who has time to remember that shit?

    Some of us have memories that are longer then your penis.

    Some of us have penises longer than your memory.

    Thanked by 2eol ehab
  • @Letzien said:

    @AuroraZ said:

    @Letzien said:

    @AuroraZ said:

    @Letzien said:

    @ehab said:
    on OpenVZ - "Wouldn't touch it with @Letzien's penis." -@AuroraZ

    Uh, what? When did he say that?

    Way back and you told not talk with my mouth full.

    Shit who has time to remember that shit?

    Some of us have memories that are longer then your penis.

    Some of us have penises longer than your memory.

    Picts or it did not happen.

    Thanked by 1ehab
  • ehabehab Member
    edited January 2019

    @AuroraZ said:
    Picts or it did not happen.

    in pm only. and maybe get a 38" screen.

    Thanked by 1eol
  • @ehab said:

    @AuroraZ said:
    Picts or it did not happen.

    in pm only. and maybe get a 38" screen.

    No.

    Thanked by 1ehab
  • ^ must've been what is stored in that shed. :-/

    Thanked by 1ehab
  • jsgjsg Member, Resident Benchmarker

    A nuclear eggsplosion?

    Thanked by 1eol
  • openvz no longer provides updates

  • @Gam3over said:
    openvz no longer provides updates

    Are you this slow, or did you need training?

    Thanked by 1Tr33n
  • @Letzien said:

    @Gam3over said:
    openvz no longer provides updates

    Are you this slow, or did you need training?

    Wtf ... =? What's happening ?

  • @Gam3over said:
    openvz no longer provides updates

    Nonsense.

  • JanevskiJanevski Member
    edited January 2019

    @FlamesRunner said:
    @ehab

    Nah, OpenVZ is like the adult son you let live in your basement, even when you think he's a little noisy at times.

    Hugo?
    Attic/basement whatever...

    Thanked by 1eol
  • @Janevski

    Just wait until you get a condo, it'll get better once you get yourself the KVM.

  • @Tr33n said:

    @Gam3over said:
    openvz no longer provides updates

    Nonsense.

    Improve me if I'm wrong, but in my opinion LXC is the better variant.

  • eoleol Member

    @Gam3over said:

    @Tr33n said:

    @Gam3over said:
    openvz no longer provides updates

    Nonsense.

    Improve me if I'm wrong, but in my opinion LXC KVM is the better variant.

  • @eol said:

    @Gam3over said:

    @Tr33n said:

    @Gam3over said:
    openvz no longer provides updates

    Nonsense.

    Improve me if I'm wrong, but in my opinion LXC KVM is the better variant.

    LXC and KVM** sorry

    Thanked by 1eol
Sign In or Register to comment.