A good ballpark rule here is, don't trust anything in the stack you don't control any more than you are forced to. Using OpenVZ forces you to trust the host environment a lot more than the alternatives.Anything beyond "don' trust your host"?
Of course, either way they could MITM you, as network traffic has to pass through the host environment, but that is presently well-mitigated by having a secure trust root (the network having it's own CA, or using an established CA).