#virtualization #security is not good enough to contain current #AI agents like GPT 5.6-Cyber, except that #Firecracker sort of withstood the attack. “I had the AI agent run against Firecracker. It was able to hardlock the machine due to more Linux kernel flaws (all patched in upstream), but could not successfully escape. It may have, given even more time, but Firecracker is obviously a substantially harder target.”
on 02026-09-10#AWS’s "Firecracker" “VMM” is open-source; I think this is what they use for containing Lambda Functions. “an open source #virtualization technology purpose-built for creating and managing secure, multi-tenant container and function-based services. It enables you to deploy workloads in lightweight virtual machines (microVMs) that provide enhanced security and workload isolation over traditional VMs, while enabling the speed and resource efficiency of containers.”
on 02026-09-10My comments on the #Antithesis distributed-system #testing system using #hypervisor #virtualization
on 02025-10-21#video on "Antithesis", a whole-system #fuzzer using #virtualization to make distributed-system failures reproducible. “But the crazy thing is once I have a time machine, once I have a hypervisor, I can run until I make event A happen. And then if I notice that event A has happened, I can say this is interesting. I want to now just focus on worlds where event A has happened. I don’t need to refind event A every single time. I can just lock it in, right? It’s like if you play computer games, it’s like save scumming, right? It’s like I can I can just save my state when I got the boss down to half health and now always reload from that point.”
on 02025-10-19#Treacherous-Computing for “confidential VMs” #privacy despite #Linux #virtualization #toread
on 02025-08-24Firecracker lets you start up VMs in under 125 ms using #KVM, but #Linux then takes 2–3 seconds to run systemd. DigitalOcean does support nested #virtualization. #emulation
on 02021-01-24A #paper about exploiting #virtualization to do “off-host” memory-scanning of guest VM memory for #malware. #censorship
on 02015-08-12Nested uid/gid namespaces since #Linux 3.8 to enable #security #virtualization of users and groups! The uid namespace can map users arbitrarily to outside-namespace uids. Not sure if you can invent new uids. Unfortunately, since #Red-Hat doesn’t trust new features, they’re going to make this useless in RHEL for a while, but Fedora is enabling it.
on 02015-08-11“#Docker is a tool to make manual linking easier. More specifically, it’s a tool to let you do manual linking and then save your work.” #virtualization #containers #linkers
on 02015-08-07