[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Publicity] Another interesting article



On 23/06/2014 11:58, George Dunlap wrote:
On 06/23/2014 11:47 AM, Lars Kurth wrote:
On 20/06/2014 22:22, Dor Laor wrote:
On Fri, Jun 20, 2014 at 11:46 AM, lars.kurth@xxxxxxx <lars.kurth.xen@xxxxxxxxx> wrote:

Interesting blog and timing. Actually OSv isn't based at all on Linux, it's a write from scratch plus
ZFS (I wasn't interviewed to this article).

Check out our recent blog posts:

Dor, thanks for pointing these out. I already noticed the first two parts and started promoting them on our social media channels.

@George: I was wondering whether maybe a short blog post xenproject.org pointing out that there is a debate and linking to various stories in the last week may make sense. Also related is https://news.ycombinator.com/item?id=7909622 and http://www.theregister.co.uk/2014/06/19/docker_security/

I am not sure it makes sense to pick a fight with the Docker community (also given that there is a chance that at some point the packaging part of Docker may support other environments that LXC).

I don't think we'd be picking a fight with the Docker community -- one of the main RedHat guys working on Docker is also a security guy, and has basically said "Docker is for distribution, not for security":

http://www.youtube.com/watch?v=VLK7F3B0pFg

And a guy who actually works for Docker originally wrote this (in August 2013)

http://blog.docker.com/2013/08/containers-docker-how-secure-are-they/

"Virtual Machines might be more secure today, but containers are definitely catching up; and containers are already easier to manage, and therefore itâs easier to make sure that they are up-to-update from a security standpoint.

But in a presentation in January 2014, basically said that the road to "bulletproof containers" was to run one container per VM:

http://www.slideshare.net/jpetazzo/linux-containers-lxc-docker-and-security

It might make sense to just comment on the whole security thing -- particularly w/ Docker 1.0 out recently. Let me see what I can come up with.

Â-George
Cool. It doesn't have to be long.
Lars
_______________________________________________
Publicity mailing list
Publicity@xxxxxxxxxxxxxxxxxxxx
http://lists.xenproject.org/cgi-bin/mailman/listinfo/publicity

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.