Comment by dbmikus
1 day ago
I don't know why it's taken as a given that we can't design a hypervisor that is secure.
Cursory research with AI says
> ~3 clearly documented, publicly demonstrated full escapes directly through KVM kernel code over roughly 15+ years of widespread KVM deployment
Surely, there are more, but we could formally verify the correctness of the entire codebase, with the help of AI.
Then we'd have "jails" that work, as long as you don't connect them to the internet.
If you had a super smart AI, you could then totally airgap it if you wanted to.
Networking opens up a can of worms and there won't be zero vulnerabilities, but we can design safer software.
No comments yet
Contribute on Hacker News ↗