10 ms·
Subgraph OS: Adversary resistant computing platform
- verandaguy 10y ago"Adversary-resistant" is an extremely bold claim. While the architecture does look promising, and (at least intuitively) reasonably-designed, I think it's a bit too soon to make a call about adversary resistance.
- Animats 10y agoThey try to avoid saying it, but it's mostly a patched Linux.
- tptacek 10y agoWhat else would you expect it to be?
- Animats 10y agoMaybe a real secure kernel, such as SeL4 or LynxOS.
- tptacek 10y agoThe tipoff that it's not L4 is that it's a desktop OS that runs applications.
- nickpsecurity 10y agoYou can do a desktop on a microkernel that runs Linux in user-mode or with hypervisor support. Critical stuff stays outside directly on microkernel. It's what every vendor of separation kernels does. Two examples from commercial and FOSS that's similarly alpha: Sirrix TrustedDesktop on Turaya: https://www.sirrix.com/content/pages/trusteddesktop_en.htm https://www.sirrix.com/content/pages/trusteddesktop_en.htm Turaya's architecture: http://www.perseus-os.org/content/pages/Overview.htm http://www.perseus-os.org/content/pages/Overview.htm FOSS alternative that they already use to develop itself: https://genode.org/ https://genode.org/
- mad_titan 10y agoHave you use any of those commercial offerings? I've honestly never heard of them before. Can i, as a regular consumer go purchase one of those operating systems and use it on my laptop?
- nickpsecurity 10y agoYou probably have to buy hardware from them if the drivers are on the microkernels because I doubt they're doing many ports. I haven't used the product as I had custom stuff. Here's a video of the academic prototypes that both the commercial stuff and Genode drew from if you're wondering about performance. That's on a Core Duo 2 @ 1.6GHz. The L4Linux VM's were fast. https://www.youtube.com/watch?v=x9IwtY9gqCg https://www.youtube.com/watch?v=x9IwtY9gqCg
- ohpauleez 10y agoYou can go and use Genode right now. There's no installer (to my knowledge) -- you'll have to build the OS by hand. If the area of secure OSes or capability-based OSes are interesting to you, Genode is the best playground for that. The DROPS/Dresden folks have been working in this area for a long time. Genode is largely kernel agnostic, being an "Operating System Framework" -- you can run it on Linux, variants of L4, seL4, Muen, and more.
- xdma 10y agoHi, I'm an SGOS dev. I don't know what you mean by "mostly a patched Linux", but here's what Subgraph OS is so far -- and it's a young project: we have a kernel patched with grsec/PaX/RAP, but we have also developed our own application sandbox framework (namespaces + limited fs + seccomp bpf whitelisting), app firewall, event monitoring subsystem, usb disable on desktop lock (based on grsec), etc. Here's a walkthrough of our sandbox framework: https://github.com/subgraph/oz/wiki/Oz-Technical-Details https://github.com/subgraph/oz/wiki/Oz-Technical-Details
- mtgx 10y agoNo updated iso since June. Any plans for an update soon? Also, shouldn't you just use Wayland for the stable 1.0 release? Why even bother with X11 at this point? Do you plan to support flatpaks as well?
- xdma 10y agoThe new ISO is coming very soon. We've just been busy with consulting we do to support the project and there were some issues with gpg2. Wayland is one huge reason why we aren't even calling this "beta". Wayland is absolutely part of the plan. We are working on integration now. Flatpaks: probably not. Different vision. Flatpak is an 'appstore' type model, not sure we will want that in Subgraph OS, but it's worth a deeper investigation than the thought I've given it so far. There are things in Flatpak that we can benefit from, such as the UI advantages of "Portals". We'll probably be adding support for it to Oz.
- mtgx 10y agoGood to hear you're considering it. It may be worth looking into appimages as well. They don't seem to focus as much on security, but perhaps their isolation is better? Flatpaks seem to share quite a bit with each other, and I worry it may create another X11-situation. Flatpaks may still be better overall, though, if they can also have good isolation. I doubt you should even bother with snaps. They don't seem to be that well supported outside of Ubuntu, and I doubt they will ever be.
- dom0 10y agoimho the qubes approach is more viable and exposes far less attack surface. Qubes is also, contrary to it's reputation, a very usable OS (with KDE in dom0, at least).
- mad_titan 10y agoI honestly find the XFCE desktop more usable.
- dom0 10y agoI greatly prefer a desktop that has searchable menus and decent Hi DPI support (although the older version in F23/Q dom0 isn't quite plugnplay). Personally I think that KDE also looks better. Especially XFCEs window decorations are just so... 90s "design".
- brl 10y ago> imho the qubes approach is more viable and exposes far less attack surface. I don't know what you base that opinion on since it's not an easy comparison to reason about. One metric you could use would be actual vulnerabilities. In the last year there have been several hypervisor escape vulnerabilites that compromised Qubes OS VM isolation completely, most (all?) of which have been present in Xen for the entire lifetime of the Qubes project. By contrast during the same period only one Linux kernel vulnerability (DirtyCow) affected Subgraph sandboxed applications, and it would only have been exploitable using techniques which have not been disclosed in any public exploit so far.
- delinka 10y agoAfter reading the article, and reading replies to you, I still have to guess whether this is a Linux kernel or something else. And I still don't understand why they don't mention this on their site. The talk of "kernel with certain patches" has me guessing it is indeed Linux.
- tptacek 10y agoThey are practically screaming grsec/PaX from the rooftop. It's even in the diagram! What else could they possibly be?
- tonyplee 10y agoCare to put out a vm image, invite folks to hack it? That is a lot more interesting.
- xdma 10y agoYou can install/run the downloadable image in a VM. Lots of people do. We test with VMWare Fusion/kvm/Virtual Box.
- protomikron 10y agoThis is a step in the right direction (in the sense that we should sandbox applications harder), but in my opinion we have to change fundamental aspects of our stack (e.g. Proprietary Firmware <=> Linux <=> GNU-System-Libs <=> X <=> GTK <=> Evince), to gain more security. In particular I think it is harmful that all applications share the same view on the FS and have in principal the possibility to use e.g. full unixoish capabilities. My bet is that the solution is via better type systems, e.g. an application that is a desktop game could have something like exec :: GameConfig -> WindowControl () where GameConfig is e.g. some CFG specific to the game and WindowControl is similar to IO () however limited to interacting with a drawing library (e.g. OpenGL) and input systems (keyboard and mouse local to the window). At the moment every application just implements `main()` and is good to go and we separate between kernel- and user-space (and a VM on top e.g. Android and Apple), and maybe this is too coarse. I think pledge (http://man.openbsd.org/pledge http://man.openbsd.org/pledge) is also a step in the right direction however I would prefer it to be the other way around: an application goes through a setup process where it gains the capabilities it needs (in pledge it's the other way around, you ask to drop them).
- ShaneWilton 10y agoYou might be interested in coeffects. Just like monads can be used in a language like Haskell to model effectful operations, you can use the dual of monads, comonads, to model the dual of effects, coeffects! Coeffects can be used to represent the "context" of a program, which includes things like permissions or capabilities that the program may have access to. They provide a fascinating way of modeling all kinds of information that is traditionally not handled by even powerful type systems like OCaml's or Haskell's. You can read a lot more about the topic on Tomas Petricek's website: http://tomasp.net/coeffects/ http://tomasp.net/coeffects/ I especially recommend this short article from 2014: http://tomasp.net/blog/2014/why-coeffects-matter/ http://tomasp.net/blog/2014/why-coeffects-matter/
- protomikron 10y agoThank you, that sounds very interesting.
- 10y ago
- formula1 10y agoIll give it a shot. Ive been feeling quite vulnerable on 16.04 due to the absurd amount of unfixed bugs. I have a couple of questions - its mentioned that it does not have access to documents and downloads within the user folder. When it wants/needs read access, how am I told? - if it doesnt have access to these folders, does it only write to its own subset? - is it possible to make my home downloads folder an aggregate of the application downloads? - when uninstalling/purging, since its sandboxed it deletes all of the content or keeps it? Can I force removal as well? - how does subgraph deal with shared services/folders/info? Can I share a service with another user? Can I share the network setting modifications with other users? - how can I prevent an application from using the network without my knowledge? - are the tools like nethogs/top for subgraph that can take advantage of the compartments to show a more realistic view of whats going on? I think this has a lot of potential!
- xdma 10y agoThese are great questions. We have a Gnome shell plug-in to move files into sandboxes while an application is running. Certain applications also have shared directories (e.g. "Downloads/TorBrowser", "Documents/LibreOffice"). This is a UX work in progress though, neither of these are adequate, though together they're workable. re: Applications and network access: we have an application firewall, unique to Linux-based OSs. It's basically Little Snitch for Linux. There is a screenshot here: Keep in mind that the project is very young. We are just getting started, tbh. With questions like these you should idle in our IRC channel where we talk about all of this stuff: OFTC/#subgraph.
- formula1 10y agoWill do! Im very excited for this. Containerization and safety is a very important problem to me. Im not particularly interested in running a docker instance or a vm just to use an application. And if I do, id prefer it being automated.
- tscs37 10y agoFor a second I thought this was about a new linux-distro for servers that featured outage resilient services and such. Oh well, this is good enough I 'spose.
- runeks 10y agoLooks interesting. I'm looking for a more secure minimal OS, for use with backend services. Would it make sense to use it as a server OS, or is it primarily for desktop use? Also, is there a docker image that is ready to go? That would be immensely useful.
- xdma 10y agoIt's a desktop OS, and the hardened kernel is an important part of the project (i.e. no docker image).
- dlevi 10y agoDoes Subgraph isolate USB and network? The isolated serviceVMs for USB and network are in my opinion a very strong value proposition of Qubes. Furthermore, is Subgraph supposed to be an OS for everyday use, like Qubes, or just for anonymous usage like Tails or Whonix? If its the former I don't understand why all traffic should be routed via Tor by default - it wouldn't make sense to route non-anonymous traffic (banking, personal mail, etc.) via Tor. It wouldn't be anonymous anyway and also because of the unnecessary risk of exposure to malicious exit nodes. In this sense I believe the Qubes approach with its optional WhonixVM is superior. If Subgraph is supposed to be for anonymous usage I'd like to read more about what kind of threat model it is trying to address. I don't think there are any amnesic features like in Tails nor strong isolation between gateway and workstation to prevent IP leaks like in Whonix.
- eddyl 10y ago> Does Subgraph isolate USB and network? The isolated serviceVMs for USB and network are in my opinion a very strong value proposition of Qubes. According to Joanna Rutkowska, developer of Qubes: "Unlike Qubes OS, Subgraph doesn't (cannot) isolate networking and USB stacks, or other devices and drivers."[1] [1] https://secure-os.org/pipermail/desktops/2015-October/000002.html https://secure-os.org/pipermail/desktops/2015-October/000002...
- dlevi 10y agoThanks for that - it pretty much answers my question. In this case it seems that Qubes exposes less attack surface.
- brl 10y agoI'm from Subgraph and I disagree. On Qubes OS the networking VM runs a standard Linux kernel with no special security hardening at all apart from the simple fact that it runs in a separate Xen VM. If an attacker is able to compromise NetVM, they may not have direct access to user data, but they have dangerous access to perform further attacks: - Attacks against hypervisor to break isolation - Side channel attacks against other Qubes VMs to steal cryptographic keys - Interception and tampering with networking traffic - Attacks against any internal network this Qubes OS computer connects to. So if you assume that remote attacks against the Linux kernel networking stack are an important threat, the consequences of a successful attack even against Qubes are pretty bad. Subgraph OS hardens the Linux kernel with grsecurity, which includes many defenses against exploitation which have historically prevented local exploitation of most security vulnerabilities against the kernel. Exploiting kernel vulnerabilities locally is so much easier, probably never less than an order of magnitude easier. It's so rare to reliably exploit kernel vulnerabilities remotely even against an unhardened kernel that teams present papers at top security conferences about a single exploit: https://www.blackhat.com/presentations/bh-usa-07/Ortega/Whitepaper/bh-usa-07-ortega-WP.pdf https://www.blackhat.com/presentations/bh-usa-07/Ortega/Whit... I know it's contentious to say so, but I don't believe that anybody will ever remotely exploit a kernel vulnerability against a grsecurity hardened Linux kernel, especially since RAP was introduced: https://grsecurity.net/rap_announce.php https://grsecurity.net/rap_announce.php The threat of remotely attacking the Linux kernel through the networking or USB stack was always low in my opinion, but as the threat approaches zero it raises some questions about how justifiable the system VMs are in Qubes OS considering the system complexity and usability impairment they introduce.
- stcredzero 10y agoI rather like the graphic with this post. Is that based on pixel art, programmatically combined to resemble orthographic projection, or is it generated by WebGL? (Using one of the available blocks libraries in Javascript.)
- xdma 10y agoIt was drawn by hand using a vector illustrations tool, based on a sketch that I had made. We think it is very cool and will produce more conceptual illustration in this style. The artist goes by Sephy Ka: http://www.sephyka.com/box-stories/ http://www.sephyka.com/box-stories/
- rrggrr 10y agoI need to know who/how they made the graphic image. I love it.
- akerro 10y agohttps://news.ycombinator.com/item?id=13026642 https://news.ycombinator.com/item?id=13026642
- ritonlajoie 10y agoI come late to the party but I installed the ISO on virtualbox. It seems after boot, I can't apt update or anything network related. I tried disabling the firewall too, to no avail. I see that /etc/resolv.conf is only having nameserver 127.0.0.1 I guess that's ok (resolv made through Tor maybe ?) but I wonder how to activate the network :/ Is there a way to discuss things related to Subgraph ? thanks