I recently spoke at the InfoSec World 2010 Summit on Virtualization and Cloud Security and also attended the main conference sitting in on many Virtualization discussions. Perhaps it was the crowd, which was roughly 30-40% auditors. Perhaps it was the timing as SourceBoston was also going on, as well as CloudExpo in NY. But I was surprised to find that people are still ‘just starting’ to think about Virtualization Security. Since I think about this subject nearly every day, this was disappointing to me at best. I found ideas around virtualization security ranging from:

* Virtualization Security is not part of an architecture/design, what do I bolt on?
* My Physical Security will work
* Virtual Environments NEED More security than physical environments
* There are no new threats, so why have something more
* Security is a hindrance

The End of ESX is Near – Is ESXi Ready for the Enterprise?

Well the worse kept secret in virtualisation is now finally out in the open, have a read of VMware ESX to ESXi Upgrade Center:Planning your Upgrade to the next-generation hypervisor architecture where they state that “In the future, the superior architecture of ESXi will be the exclusive focus of VMware’s development efforts. This means that not only will the ESXi hypervisor superceed the classic ESX hypervisor in a new version of vSphere; what the time scale is, is currently unknown however it is most likely to be vSphere 5 or whatever they decide to call the next major release. What is more interesting in statement is that VMware expects their customers to upgrade their existing installations of vSphere based on the ESX hypervisor to the new ESXi hypervisor.

Just as Milton Friedman (the Nobel prize winning economist) once said “There is no such thing as a free lunch”, there is also no such thing as free software. The minimum cost of a supposedly free piece of software is the opportunity cost of your time spent using it, and the forgone value of that time spent doing something else. Therefore neither Microsoft Hyper-V, nor VMware ESXi are really free.

VMware Study – Benefits of Virtualization for the SMB

VMware has recently released the results of a new study that VMware did of 309 companies that have between 20 and 1000 employees. The two major benefits of virtualization reported by the survey participants were reduced time spent on routine and repetitive tasks, and improved applications availability. 73% of respondents reported reductions in time spent on routine tasks, and 71% reported improvements in applications availability.

Citrix has recently joined the Linux Foundation, and there is a report (which they seem to have endorsed) that they plan to open source XenServer. That’s not Xen, it’s XenServer – not the kernel, the product, the thing you stick on your server instead of ESXi, or sometimes vSphere.

It is entirely possible that Citrix’s lawyers have noticed that XenServer was so infected with GPL code that it was already Open Source anyway.

In trying to re-use some old server hardware I re-vsisted VirtualBox/Ubuntu, a viable and completely free Open Source option for non-virtualization-enabled hardware. It is a neat solution, simple and well-supported, but the open source version of VirtualBox is nobbled to make it extremely awkward to use, in a different way to VMware’s nobbling of the non-Open Source (but also free) ESXi.

Now is the time, for Oracle/Sun to put all the features of VirtualBox into the Open Source version, and let it live on, perhaps not for use on Linux servers, but as free virtualization platform for other operating systems on Windows. If Apple ever loosens up the licencing on MacOS, it could turn 15 million PCs into Macs – overnight.