Chapter 13. Security considerations

Table of Contents

Potentially insecure operations
Authentication
Encryption

Potentially insecure operations

The following features of VirtualBox can present security problems:

  • Enabling 3D graphics via the Guest Additions exposes the host to additional security risks; see the section called “Hardware 3D acceleration (OpenGL and Direct3D 8/9)”.

  • When teleporting a machine, the data stream through which the machine's memory contents are transferred from one host to another is not encrypted. A third party with access to the network through which the data is transferred could therefore intercept that data.

  • When using the VirtualBox web service to control a VirtualBox host remotely, connections to the web service (through which the API calls are transferred via SOAP XML) are not encrypted, but use plain HTTP. For details about the web service, please see Chapter 11, VirtualBox programming interfaces.

Authentication

The following components of VirtualBox can use passwords for authentication:

Encryption

The following components of VirtualBox use encryption to protect sensitive data: