<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fear for the Sake Of Fear? Hyper-Jacking Myths?</title>
	<atom:link href="http://toutvirtual.com/blogs/index.php/2008/09/10/fear-for-the-sake-of-fear-hyper-jacking-myths/feed/" rel="self" type="application/rss+xml" />
	<link>http://toutvirtual.com/blogs/2008/09/10/fear-for-the-sake-of-fear-hyper-jacking-myths/</link>
	<description>Best Practices Guide to Virtualization - From Getting Started with Virtualization to Advanced Strategic Virtualization Concepts</description>
	<lastBuildDate>Tue, 14 Feb 2012 19:37:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: SafeTinspector</title>
		<link>http://toutvirtual.com/blogs/2008/09/10/fear-for-the-sake-of-fear-hyper-jacking-myths/comment-page-1/#comment-48900</link>
		<dc:creator>SafeTinspector</dc:creator>
		<pubDate>Mon, 27 Jun 2011 20:39:40 +0000</pubDate>
		<guid isPermaLink="false">http://toutvirtual.com/blogs/2008/09/10/fear-for-the-sake-of-fear-hyper-jacking-myths/#comment-48900</guid>
		<description>&quot;Hypervisors should be designed to never allow themselves to be executed by themselves in abstracted context.&quot;
I know the article is a few years old now, but this one is out of the bag as VMWare partners are already offering this as a cloud deliverable... intentionally.</description>
		<content:encoded><![CDATA[<p>&#8220;Hypervisors should be designed to never allow themselves to be executed by themselves in abstracted context.&#8221;<br />
I know the article is a few years old now, but this one is out of the bag as VMWare partners are already offering this as a cloud deliverable&#8230; intentionally.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Schorschi</title>
		<link>http://toutvirtual.com/blogs/2008/09/10/fear-for-the-sake-of-fear-hyper-jacking-myths/comment-page-1/#comment-12419</link>
		<dc:creator>Schorschi</dc:creator>
		<pubDate>Tue, 28 Oct 2008 07:43:25 +0000</pubDate>
		<guid isPermaLink="false">http://toutvirtual.com/blogs/2008/09/10/fear-for-the-sake-of-fear-hyper-jacking-myths/#comment-12419</guid>
		<description>Actually, you just made the point for me.  You do not hype Hyper-Jacking?  Of  course you don&#039;t, because it is not, as yet, reality at all.  I suggest that instead of you decrying what you don&#039;t like in my blog versus what you think is better in your blog, you consider what is really going on, do some home work.  I have never tried to compare my blog to anyone&#039;s blog, I consider that bad form.  Regardless of why or what you may think about my blog, the point is, many authors have been misleading about Hyper-Jacking, especially authors in so called major publications.  They should be more careful, and more actuate, as you have stated you are, in presenting real issues and real threats to the less technical oriented in the world?  For the record, C2 and C3 ratings are not lame or weak evaluations.  Trying developing a product and passing C2 review, it is not trival nor light weight.  EAL is one thing, whereas C2 is another.  Again, respectfully suggest some home work on your part.</description>
		<content:encoded><![CDATA[<p>Actually, you just made the point for me.  You do not hype Hyper-Jacking?  Of  course you don&#8217;t, because it is not, as yet, reality at all.  I suggest that instead of you decrying what you don&#8217;t like in my blog versus what you think is better in your blog, you consider what is really going on, do some home work.  I have never tried to compare my blog to anyone&#8217;s blog, I consider that bad form.  Regardless of why or what you may think about my blog, the point is, many authors have been misleading about Hyper-Jacking, especially authors in so called major publications.  They should be more careful, and more actuate, as you have stated you are, in presenting real issues and real threats to the less technical oriented in the world?  For the record, C2 and C3 ratings are not lame or weak evaluations.  Trying developing a product and passing C2 review, it is not trival nor light weight.  EAL is one thing, whereas C2 is another.  Again, respectfully suggest some home work on your part.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christofer Hoff</title>
		<link>http://toutvirtual.com/blogs/2008/09/10/fear-for-the-sake-of-fear-hyper-jacking-myths/comment-page-1/#comment-12382</link>
		<dc:creator>Christofer Hoff</dc:creator>
		<pubDate>Mon, 27 Oct 2008 20:10:12 +0000</pubDate>
		<guid isPermaLink="false">http://toutvirtual.com/blogs/2008/09/10/fear-for-the-sake-of-fear-hyper-jacking-myths/#comment-12382</guid>
		<description>I don&#039;t know which one of the blog entries in the group you were talking about when you referenced the &quot;article&quot; in question, so I can&#039;t respond to your point directly.

However, this set of statements is hysterical:

&quot;Unfortunately, this article is misleading. The key virtualization platforms that dominate the industry have been certified and vetted, against known methods and techniques, something this article, among others,never explains and thus never provides a balanced view of the issue. Of course, no one is secure against new techniques and methods, but this article does not explain that point well either, it raises questions, nothing more.&quot;

Certified and vetted?  Against known methods and techniques?  Buahahaha.  So, you&#039;re referencing which certifications, exactly?  Common Criteria?  Up to EAL 4, perhaps?  That&#039;s not exactly difficult to achieve and doesn&#039;t require semiformal or formal design verification, and they do NOT certify or vet that hypervisors cannot be subverted or that guests cannot escape.

And as far as vetting them against &quot;known&quot; methods, that&#039;s hardly the issue when referencing on-going research that has shown recently that abuse of device drivers and DMA can lead to all sorts exploits.

Further, if you read my blog or attended my presentations, you&#039;d discover that I don&#039;t hype hyperjacking or virtualization malware at all -- just the opposite.

I presented both sides of the argument in the cited collection of blog pieces above.  How you get fog/fud out of any of them is beyond me.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t know which one of the blog entries in the group you were talking about when you referenced the &#8220;article&#8221; in question, so I can&#8217;t respond to your point directly.</p>
<p>However, this set of statements is hysterical:</p>
<p>&#8220;Unfortunately, this article is misleading. The key virtualization platforms that dominate the industry have been certified and vetted, against known methods and techniques, something this article, among others,never explains and thus never provides a balanced view of the issue. Of course, no one is secure against new techniques and methods, but this article does not explain that point well either, it raises questions, nothing more.&#8221;</p>
<p>Certified and vetted?  Against known methods and techniques?  Buahahaha.  So, you&#8217;re referencing which certifications, exactly?  Common Criteria?  Up to EAL 4, perhaps?  That&#8217;s not exactly difficult to achieve and doesn&#8217;t require semiformal or formal design verification, and they do NOT certify or vet that hypervisors cannot be subverted or that guests cannot escape.</p>
<p>And as far as vetting them against &#8220;known&#8221; methods, that&#8217;s hardly the issue when referencing on-going research that has shown recently that abuse of device drivers and DMA can lead to all sorts exploits.</p>
<p>Further, if you read my blog or attended my presentations, you&#8217;d discover that I don&#8217;t hype hyperjacking or virtualization malware at all &#8212; just the opposite.</p>
<p>I presented both sides of the argument in the cited collection of blog pieces above.  How you get fog/fud out of any of them is beyond me.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.454 seconds -->

