All news
cybersecurityregulation

Theo de Raadt's 2007 Warning on Virtualization Security

13 Jul 2026

The Claim

On October 24, 2007, OpenBSD founder Theo de Raadt sent a message to the openbsd-misc mailing list that has since become a touchstone for skeptics of virtualization security. His argument was simple but pointed: virtualization, as he described it, places another nearly full kernel on top of the x86 architecture, with an operating system running on the other side of this new layer.

His conclusion followed directly from that description. De Raadt expressed skepticism that software engineers who cannot write operating systems without security holes could somehow write virtualization layers without security holes. In other words, if kernel-level code is already prone to vulnerabilities, adding another kernel-like layer underneath it doesn't eliminate that risk—it potentially doubles the surface area for it.

What's Missing From the Record

The full context of the thread De Raadt was replying to is not available, so it's unclear what specific claim or product prompted his response. Similarly, there's no information in the record about which virtualization products or vendors were under discussion at the time, nor any data on how the broader security or OpenBSD community reacted to the statement when it was posted. The origin of the "mind altering" phrasing referenced in discussions of this quote is also not explained by the available facts.

Why Founders Should Care

For founders building infrastructure, devtools, or anything that sits on top of virtualization layers, this decades-old critique is worth revisiting—not as settled fact, but as a prompt for scrutiny. The core risk it points to is straightforward: virtualization layers may inherit or introduce security vulnerabilities similar to those found in operating system kernels. If that risk holds even partially true in modern environments, it could mean that startups relying heavily on virtualized infrastructure should weight additional security auditing as a higher priority than they otherwise might.

This is likely more relevant for founders in security-focused infrastructure than for typical SaaS builders one layer removed from the hypervisor. Still, the underlying logic—that complex, kernel-adjacent software is difficult to secure regardless of who writes it—is a reasonable heuristic for evaluating any dependency stack, not just virtualization specifically.

The Opportunity Angle

Skepticism like De Raadt's, even if it originated in a niche mailing list nearly two decades ago, can be read as a signal of enduring demand for more rigorously engineered or independently audited virtualization solutions. Founders building in security-focused infrastructure may find room to differentiate by directly addressing the kinds of gaps this critique implies—treating virtualization layers with the same suspicion traditionally reserved for kernel code, rather than assuming abstraction equals safety.

The Takeaway

De Raadt's 2007 post doesn't come with data, vendor specifics, or documented industry response in the available record—so it should be read as a pointed opinion rather than a proven finding. But the underlying question it raises—can virtualization layers really escape the same security failures as the operating systems they're built to isolate?—remains one that infrastructure-focused founders may want to keep asking, especially as their systems scale and their attack surface grows.

Sources