[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-talk] Securing a Relay - chroot



--- On Wed, 5/25/11, CACook@xxxxxxxxxxxxxxx <CACook@xxxxxxxxxxxxxxx> wrote:
> I am seeing evidence that a chroot jail is not secure, even
> in Linux, due to breakouts such as  someone running
> os.fork() from python and spawning processes to do bad
> stuff.
> 
> For torrents I run Debian in a VirtualBox virtual machine
> which is bridged directly to The Internets, with the VM user
> and user inside being very non-prived.  My best
> information is that this is quite secure.

I run mine in a linux vserver, it should run in lxc also,
those are both much more lightweight than a virtual
machine.  I would suggest that.

> Has anyone done any research on best practices for securing
> a daemon?

Not sure.

-Martin

_______________________________________________
tor-talk mailing list
tor-talk@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-talk