We have a big picture/small picture problem. The problem is one OS, regardless of it's pedigree, has casually established read/write access to the root drive and all mounted drives of another OS, also regardless of it's pedigree. Specifically, the OS's in this discussion reside on the same machine and are running at the same time but that is not a factor in respect to the principles of security.
The risk arises from the fact stated - one system has extreme access to another and it is provided rather silently by a user level application. In this case the mechanism is Parallels. In the case of Solaris the mechanism can be sshfs and it is a real problem today but not Parallels' problem. The same principle applies.
What makes it a security problem is that this is a default configuration that happens as a consequence of creating a virtual machine in Parallels. To date only Windows vm's are set up this way but perhaps as the product develops this method will be applied to other supported guest OS's.
What makes this a social problem is that while the situation described is real, there are those among us who would prefer this not be discussed and/or believe the problem is not a real problem at all. Keeping such important information from the end user is unwarranted. What harm can come from end users knowing the risks associated with this feature?
That is a community I at least have never been a part of, but explain please how so many Windows users know about this problem when it only came to light with RC 3150 or thereabouts? Historically Windows users have never had the ability to tunnel into another OS's hard drive before Parallels introduced it. I'd think people would be curious about what it means.
[Fargo] No, see, no, there are no airplanes, there's just... No. There's no airplanes![/Fargo]