Comment 4 for bug 1305135

Revision history for this message
Martin Pitt (pitti) wrote :

@Dave: I don't know what would expose the VMs to a public LAN; they don't use a veth or anything which would connect them to a real interface. You can configure qemu to do that, but adt-run doesn't as it is not necessary.

As for the VM itself, there is no security at all there. There is a root shell listening on the VM's tty1 which is used as the adt-run control channel from outside. Any more refined method to access the VM is just a matter of convenience (sensible terminal capabilities, pre-installed programs), not security. So yeah, don't run that on VMs which have anything secret in it :-)