7 ms·
Qubes OS 3.1 has been released
- jmnicolas 11y agoI really like the concept of Qubes. But they really need (imho) to work on their hardware compatibility list. I didn't investigate laptops much but last time I checked (2 or 3 months ago) they didn't have a fully supported (desktop) motherboard that can be bought new. I tried to install it on my computer, it didn't work. I'd buy a new desktop just for Qubes if I had the guaranty that it would be fully supported. I'm not spending money just to discover that it won't run with my shiny new hardware.
- blinkingled 11y agoI used it on my Thinkpad x220 and NUC 5th gen (BOXD54250WYKH) and it worked great. https://www.qubes-os.org/hcl/ https://www.qubes-os.org/hcl/ - The HCL is pretty decent actually. But since they have to work on older Linux Kernel and Xen releases for stability/security and the hardware needs to have VT-d, TPM, HVM/VMX etc enabled - they will always be lagging in terms of the newer hardware they can support. Might want to try out the BOXD54250WYKH1 NUC - Amazon is still selling it.
- jmnicolas 11y agoYou forgot to update the HCL with your NUC ;-)
- conradev 11y agoOn this topic, does anyone have suggested hardware to use Qubes with besides the Purism laptop?
- pfg 11y agoHaven't run into any issues on a ThinkPad T420. There's a number of more recent ThinkPads on their Hardware Compatibility List[1] as well. [1]: https://www.qubes-os.org/hcl/ https://www.qubes-os.org/hcl/
- revanx_ 11y agoWorked out of the box for me on my Z77 board.
- walterbell 11y agoDell T20 Haswell Xeon ($500) has the hardware features (TPM, TXT, VT-d, VT-x) used by Qubes, and supports ECC memory.
- jmnicolas 11y agoInteresting but when I go on Dell's website (Europe) I can't order it with more than 8GB of RAM. I would feel more comfortable with 16.
- walterbell 11y agoIt has 4 memory slots and supports 32GB RAM. Try calling Dell, they can likely sell you "upgrade kits" for memory and disk. Or use aftermarket memory.
- eveningcoffee 11y agoI think that Qubes OS is a very welcomed development in the OS landscape. I have few usability related questions to see if such things would be possible in Qubes OS. Would it be possible for Qubes OS to implement similar window maximization as one can see in Ubuntu? That is, when a window is maximized then its title bar integrates with the toolbar. Edit: Also would it be possible for applications to enter into full screen mode?
- kyboren 11y agoYes, but there's a good security reason to have those labeled/colored dom0-drawn window decorations. However, if you want, you can still manually put any window in proper full screen mode. It's just a right click away, at least on XFCE.
- 0942v8653 11y ago> Edit: Also would it be possible for applications to enter into full screen mode? No. If they could, then when they were told to full screen (or do so "automatically"), they could draw as convincingly as possible a Qubes-looking desktop and trick users into thinking it's their own desktop, allowing them to phish credentials and whatnot. The viability of this attack is low, but it can be avoided by not allowing full screen. (Edit: Apparently I was wrong. It is possible to enable fullscreen manually, according to a sibling comment.)
- krylon 11y agoI remember reading a discussion a couple of years back where somebody wondered why Microsoft did not go a similar route for Windows. The original context was backwards compatibility with applications written for older releases of Windows. But given the general security situation on Windows, it would be really nice to have, for example, the browser strongly isolated from the rest of the system. The idea of using virtualization to enforce stronger isolation between different parts of the system seem like a good one, and it does not appear to be that non-obvious (of course, in hindsight so many things do).
- kristopolous 11y agoPardon me, but I see a double negative in your last sentence. For clarification are you saying that "it does appear to be non-obvious" or as you wrote, "it does not appear to be non-obvious" (as in, it appears to be obvious)?
- ams6110 11y ago"not non-obvious" isn't quite the same as "obvious." English prose can't be parsed by pure logic alone. I think in the context of the entire sentence it's clear that the choice of words is correct as written.
- krylon 11y agoYes, that is what I meant. Sorry for my convoluted phrasing. ;-) In German, my native language, double negatives cancel each other out. I mean that in retrospect the idea is obvious, as in, "why did I not think of that". Of course, in computers and technology there are many, many ideas that appear obvious in retrospect but were still hard to arrive at.
- geofft 11y agoBromium (https://www.bromium.com/ https://www.bromium.com/) is a commercial product that does basically this on Windows, and is also based on Xen. https://www.bromium.com/advanced-endpoint-security/our-technology.html https://www.bromium.com/advanced-endpoint-security/our-techn...
- revanx_ 11y agoI just really hope that the next generation of GPUs will have better support for virtualization, yeah, looking at you NVIDIA.
- naveen99 11y agoI thought you don't need any specific support from the gpu, since we already have pci pass through: https://wiki.archlinux.org/index.php/PCI_passthrough_via_OVMF https://wiki.archlinux.org/index.php/PCI_passthrough_via_OVM...
- deleted 11y ago[deleted]
- SXX 11y agoProblem is that Nvidia refuse to support it for consumer GPUs. So you have to buy Quadro hardware if you need official support. They also introduced two "bugs" that make Windows drivers to fail on startup if KVM or Hyper-V enlightenments detected. Currently there is way to bypass both "bugs", but they can introduce something new in newer version of drivers.
- redtuesday 11y agoMaybe on the Titan, but I don't see it happen below that. I don't understand why AMD doesn't leverage this advantage. It's a niche market for consumers, but from my experience the people who are interested in this are often people who have more income than the average - which are customers that should be interesting to a company I would think.
- sofaofthedamned 11y agoThey don't want to, unless you pay dollars, which is why they block passthrough on KVM without workarounds. Thank god for AMD, basically.
- anonbanker 11y agoI hate AMD cards. I've hated their linux support since I had the misfortune of owning an All-In-Wonder Radeon. I even refused to buy them around 2003, when I had too much abuse from ATI to keep using their hardware. I just (today) made a purchase of a VM server off newegg, using all AMD hardware for hardware passthrough[0], because of how truly poor NVIDIA is in this regard. 0. https://teksyndicate.com/videos/gta-v-linux-skylake-build-hardware-vm-passthrough https://teksyndicate.com/videos/gta-v-linux-skylake-build-ha...
- redtuesday 11y agoDoes anyone know if PCI passthrough works so we can play games inside a windows vm? Some user already asked this on the mailing list but got no answer. [1] [1] https://groups.google.com/forum/#!topic/qubes-devel/MfHy2jmXhXM https://groups.google.com/forum/#!topic/qubes-devel/MfHy2jmX...
- wtallis 11y agoQubes uses Xen and thus PCI passthrough for gaming can be made to work through the same procedures necessary for any other Xen+Linux OS. But PCI passthrough for gaming isn't a great fit for the Qubes security model: it requires trusting that the Windows guest cannot compromise the GPU you loan it, which makes it a much bigger risk than an ordinary AppVM.
- redtuesday 11y agoThanks for the answer, that's promising. Maybe I give it a try after investigating if my other hardware is supported (vt-d etc. is no problem, but it's not on the supported hardware list). Yes, a dedicated machine for gaming would certainly be better. But I play only irregularly and games like Divinity: Original Sin, Pillars of Eternity etc. which I kind of trust to don't hijack the GPU.
- heavenlyhash 11y agoIt's not exactly about trusting the game. You'd be extending trust to... everything inside the VM you expose the graphics card to. And graphics cards are messy. Many of them are frankly a lot like accessing main memory without an MMU. It's extremely easy to get scrapes of other application's video RAM that hasn't been zeroed. I'm not trying to tell you you shouldn't do it of course. Just... be aware. "hijack the GPU" doesn't even require a whole lot of malice. I've had video memory of my firefox tabs from last shutdown draped across my screen while the lightdm login windows do their first paint, for example. This is just the world we live in :(
- 11y ago
- binarycrusader 11y agoThe amusing thing to me is that Solaris provided similar security over a decade ago in the Trusted Desktop: http://www.oracle.com/technetwork/articles/servers-storage-admin/sol-trusted-extensions-1957756.html http://www.oracle.com/technetwork/articles/servers-storage-a... https://en.wikipedia.org/wiki/Solaris_Trusted_Extensions https://en.wikipedia.org/wiki/Solaris_Trusted_Extensions The whole idea of encapsulated data paths with labeled domains, etc. were all pioneered first in Solaris. The unique spin here with Qubes OS seems to be do something similar, but using virtualization.
- nickpsecurity 11y ago"The whole idea of encapsulated data paths with labeled domains, etc. were all pioneered first in Solaris." They actually came from the high assurance field that created the Orange and Red Books for endpoints and networking respectively. Earliest, fielded systems like that were in the mid-80's. Later, since nobody wanted real security, they dropped the assurance but kept & expanded features in so-called Compartmented Mode Workstations described here: http://web.ornl.gov/~jar/doecmw.pdf http://web.ornl.gov/~jar/doecmw.pdf Trusted Solaris, which started as Sun MLS, conformed to low-to-mid grade of Orange Book: http://www.cse.psu.edu/~trj1/cse544-s10/slides/cse544-lec12-solaris.pdf http://www.cse.psu.edu/~trj1/cse544-s10/slides/cse544-lec12-... Others included Trusted IRIX, SEVMS version of OpenVMS, Trusted Xenix around same time as Sun MLS, and so on. Many of those weak OS's with security retrofits. Today, there's Argus Pitbull, Trustifier, maybe others I don't know about. Over time, due to security failures, DOD once again wanted high assurance desktops built on secure isolation. Turned to separation kernels (MILS) built to high assurance requirements. INTEGRITY-178B, LynxSecure, and VxWorks MILS built on that model with labeled, color-defined, virtualized desktops showing up starting around 2005. Nizza security architecture and TUDOS demo did stuff similar to high-assurance work for OSS in 2005-2006. QubesOS showed up later building on insecure Xen stack w/ VM-level separation and CMW-like features. GenodeOS built on Nizza/TUDOS work around 2007 while continuing to integrate high-assurance stuff like seL4 where possible. So, no, Sun didn't invent these concepts or even design a high assurance system that I'm aware of. It was SCOMP, GEMSOS, XTS-300, and likely Trusted Xenix that proved most of the concepts out. Sun copied and improved on a watered down version of that. Separation kernels like INTEGRITY-178B and architectures like Nizza showed how it was supposed to be done. Then, Qubes later copied CMW's w/ a weak virtualization scheme and components but better usability (administration & hardware support) than separation kernels. There's the lineage and history lesson for you.
- Sir_Cmpwn 11y agoI keep waiting for the Qubes release notes that say they've upgraded to KVM.