[tor-talk] Securing a Relay - chroot
Martin Fick
mogulguy at yahoo.com
Wed May 25 20:53:03 UTC 2011
--- On Wed, 5/25/11, CACook at quantum-sci.com <CACook at quantum-sci.com> wrote:
> I am seeing evidence that a chroot jail is not secure, even
> in Linux, due to breakouts such as someone running
> os.fork() from python and spawning processes to do bad
> stuff.
>
> For torrents I run Debian in a VirtualBox virtual machine
> which is bridged directly to The Internets, with the VM user
> and user inside being very non-prived. My best
> information is that this is quite secure.
I run mine in a linux vserver, it should run in lxc also,
those are both much more lightweight than a virtual
machine. I would suggest that.
> Has anyone done any research on best practices for securing
> a daemon?
Not sure.
-Martin
More information about the tor-talk
mailing list