Forrester's Security & Risk Management Blog
I've sat through a number of presentations and sessions about security and
virtualization in recent times and can't help thinking that people are
falling into the old trap of going after the possible rather than the
probable.
Most discussions I've seen around security and virtualization center around
subtle threats to the hypervisor layer, and whether it's possible to jump
from one virtual machine to another. Then there are the circular discussions
about whether it's provably more secure to perform AV and intrusion
inspection from inside the virtual machine, or have the host perform all the
functions.
All pretty tedious if you ask me. I reckon we've some much bigger problems in
a virtual world.
Isn't it more of a problem that... (more)