←back to thread

441 points ploggingdev | 1 comments | | HN request time: 0.248s | source
Show context
snvzz ◴[] No.15734641[source]
Their weakest point is the hypervisor, Xen, which while a better choice than Linux/KVM, is still extremely bloated and has a poor security history.

Thankfully, better designs such as seL4's VMM do exist, although it might need a little more work [1] until usable for the purpose.

[1] https://sel4.systems/Info/Roadmap/

replies(6): >>15734676 #>>15734739 #>>15734803 #>>15734841 #>>15734956 #>>15735067 #
1. mtgx ◴[] No.15734841[source]
The Genode team proposed some integration with Qubes a while ago, but not sure if the discussion went anywhere from that:

https://secure-os.org/pipermail/desktops/2015-November/00000...