|
|
|
|
|
by naasking
937 days ago
|
|
> The only reason to prefer a unikernel is because you wrongly believe that hypervisors are a security boundary. That's wrong. They rightly believe that traditional operating systems deployments come with much larger attack surfaces. |
|
To move beyond the mere practical aspects, even theoretically you are wrong. The techniques needed to develop a secure hypervisor are basically exactly the same techniques needed to develop a secure operating system. They are almost trivially transferrable. If you can do one, you can do the other. So, again, no advantage to preferring a hypervisor based solution.