Re: IPCop in VirtualBox ?
David Taylor <daveytay-wUU9E3n5/[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
On 26/08/2015 12:51 a.m., Arnt Karlsen wrote: > On Tue, 25 Aug 2015 09:01:12 +0200, Danjel - Jungersen Grafisk ApS > wrote in message <55DC12B8.18496.4CFDE73A-F3ckeFbCHhSEKx6MMK3iymSdvHPH+/[email protected]>: > >> On 22 Aug 2015 at 8:00, Joe Acquisto-j4 wrote: >> >>>>>> On 8/21/2015 at 5:22 AM, Renaud (Ron) OLGIATI >>>>>> <renaud-9qJ39Kf4vhh95CE/QLhGvQK61p16E/[email protected]> >>> wrote: >>>> In recent weeks I have started using VirtualBox on my Linux >>>> desktop machine, which has allowed me to get rid for good of dual >>>> booting: I run Debian, but need from time to time a MS Windows >>>> box to be able to access some modern gadgets (Camera, cellphone, >>>> GPS, Casio CD Printer) for which there is no Linux possibility. >>>> >>>> This set me thinking: for a single Linux or Windows user, no LAN, >>>> would it be reasonable (and feasible) to run IPCop in VirtualBox, >>>> to improve the security of his computer, but without the hassle >>>> of having to run a second box for IPCop ? >>>> >>> . . . >>> >>> Feasible as in "possible"? Maybe. But I think the real answer >>> is: No. >>> >>> If I understand, IPCop would be running in a "virtual" space, >>> sharing the hardware, etc, with other "virtual" devices, under the >>> control of a "master". >>> >>> So, who has control when IPCop is "asleep". Not IPCop. I think >>> that is your answer. >> Maybe you could do something acceptable, if you you make static >> configuration on the "non ip-cop box", so that it will not have any >> outside connection when ip-cop is closed. >> >> But it will never be as secure, as when the firewall is seperate >> >> In my opinion, you can virtualize anything, except the firewall and >> router. > ...which means ipcop must be the host OS. > Can Ipcop host guest OSes safely enough? > > ..in that case ipcop becomes the ultimate laptop OS, > running only the router, the firewall, maybe Tor, > and the virtual machine host server, forcing everything > else into virtual machines. > > ..this again means anyone needing a new pc or laptop, can simply > install ipcop on their new iron, and then simply copy all their > old laptop etc disks into virtual machine disk files and run all > their old junk on their "old" virtual machines, and move their code, > music etc around _as_ they damned well please. > > ..we probably wanna deny them putting it on the ipcop host OS, and > make them put their goodies in e.g. Debian guest file server OSes, > and play games in e.g. Steam guest OSes etc, etc. > > ..crash prone beta test programs are best run in virtual machines, > so they can crash only their virtual machines and not their crash > debug output. Etc. > > ..the host OS does not ned to be VirtualBox based, > there are probably better ways to skin these cats. > > ..building on the current 32bit x86/intel platform, means we cannot > host 64bit OSes, nor run ipcop on cheap armhf irons like the 4 core > 32bit Raspberry Pi 2s. > > ..ipcop should be based on Debian for these and 4 more reasons, > Debian has _several_ viable virtualisation solutions, Debian has > a much larger development community who has done and will carry > on doing the hard work for us, Debian has a by far superior package > management in apt, aptitude, synaptic etc, than ipcop, and because > this allows dumping EFI booting, Tor, graphics, virtual machine etc > hard work onto Debian.org, who did most of it years ago. > > ..do we have a viable plan for ipcop-3.0? ;o) > This is why the very smart people at invisiblethingslab invented Qubes-OS https://www.qubes-os.org/doc/QubesDevelopers/ https://www.qubes-os.org/ It now even runs off a USB stick, <very beta> but their whole tenant has been trust NOTHING you don't control. The layers are fascinating reading. I haven't tried it out, but it ticks many boxes you raise regarding onion shells of the trust relationship. IPCop will probably not go down this road in the near future because it is not made for that type of scenario. That is why there are other solutions to meet the security need of a one box to solve them all on one piece of hardware. If you want to do a the solution your thread refers to with one laptop travelling around and having a firewall, and your hosted trusted stuff, seperate from the bad real world, then you need to look into this as a solution. They made it just for you. ------------------------------------------------------------------------------ _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user