Re: IPCop in VirtualBox ?

Arnt Karlsen <[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Organization ..ing.Arnt.Karlsen
Message-ID <[email protected]>
On Tue, 25 Aug 2015 09:01:12 +0200, Danjel - Jungersen Grafisk ApS
wrote in message <55DC12B8.18496.4CFDE73A-F3ckeFbCHhSEKx6MMK3iymSdvHPH+/[email protected]>:

> On 22 Aug 2015 at 8:00, Joe Acquisto-j4 wrote:
> 
> > >>> On 8/21/2015 at 5:22 AM, Renaud (Ron) OLGIATI
> > >>> <renaud-9qJ39Kf4vhh95CE/QLhGvQK61p16E/[email protected]>
> > wrote:
> > > In recent weeks I have started using VirtualBox on my Linux
> > > desktop machine, which has allowed me to get rid for good of dual
> > > booting: I run Debian, but need from time to time a MS Windows
> > > box to be able to access some modern gadgets (Camera, cellphone,
> > > GPS, Casio CD Printer) for which there is no Linux possibility.
> > > 
> > > This set me thinking: for a single Linux or Windows user, no LAN,
> > > would it be reasonable (and feasible) to run IPCop in VirtualBox,
> > > to improve the security of his computer, but without the hassle
> > > of having to run a second box for IPCop ?
> > > 
> > . . . 
> > 
> > Feasible as in "possible"?   Maybe.  But I think the real answer
> > is: No.
> > 
> > If I understand, IPCop would be running in a "virtual" space,
> > sharing the hardware, etc, with other "virtual" devices, under the
> > control of a "master".
> > 
> > So, who has control when IPCop is "asleep".   Not IPCop.   I think
> > that is your answer.
> Maybe you could do something acceptable, if you you make static
> configuration on the "non ip-cop box", so that it will not have any
> outside connection when ip-cop is closed.
> 
> But it will never be as secure, as when the firewall is seperate
> 
> In my opinion, you can virtualize anything, except the firewall and
> router.

...which means ipcop must be the host OS.  
Can Ipcop host guest OSes safely enough?  

..in that case ipcop becomes the ultimate laptop OS, 
running only the router, the firewall, maybe Tor, 
and the virtual machine host server, forcing everything 
else into virtual machines.

..this again means anyone needing a new pc or laptop, can simply
install ipcop on their new iron, and then simply copy all their 
old laptop etc disks into virtual machine disk files and run all 
their old junk on their "old" virtual machines, and move their code,
music etc around _as_ they damned well please.

..we probably wanna deny them putting it on the ipcop host OS, and 
make them put their goodies in e.g. Debian guest file server OSes,
and play games in e.g. Steam guest OSes etc, etc.

..crash prone beta test programs are best run in virtual machines,
so they can crash only their virtual machines and not their crash 
debug output.  Etc.

..the host OS does not ned to be VirtualBox based, 
there are probably better ways to skin these cats.  

..building on the current 32bit x86/intel platform, means we cannot
host 64bit OSes, nor run ipcop on cheap armhf irons like the 4 core 
32bit Raspberry Pi 2s.

..ipcop should be based on Debian for these and 4 more reasons, 
Debian has _several_ viable virtualisation solutions, Debian has 
a much larger development community who has done and will carry 
on doing the hard work for us, Debian has a by far superior package
management in apt, aptitude, synaptic etc, than ipcop, and because 
this allows dumping EFI booting, Tor, graphics, virtual machine etc 
hard work onto Debian.org, who did most of it years ago.

..do we have a viable plan for ipcop-3.0? ;o)

-- 
..med vennlig hilsen = with Kind Regards from Arnt Karlsen
...with a number of polar bear hunters in his ancestry...
  Scenarios always come in sets of three: 
  best case, worst case, and just in case.

------------------------------------------------------------------------------
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.