Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wonder if openbsd is secure running as a guest ? it it able to isolate it-self sufficiently so that the host cannot mathematically breach it ? (which makes openbsd very suitable for keyholding)




As of 2025 OpenBSD has support for AMD SEV and SEV-ES, with support for SEV-SNP work-in-progress, so with the right hardware yes it's able to isolate itself sufficiently https://www.bsdcan.org/2025/timetable/timetable-Confidential...

The host kernel and probably the host VMM can see guest memory, so I wouldn't use it for that.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: