13 ms·
Qubes OS: A reasonably secure operating system
- snvzz 9y agoTheir weakest point is the hypervisor, Xen, which while a better choice than Linux/KVM, is still extremely bloated and has a poor security history. Thankfully, better designs such as seL4's VMM do exist, although it might need a little more work [1] until usable for the purpose. [1] https://sel4.systems/Info/Roadmap/ https://sel4.systems/Info/Roadmap/
- dijit 9y agoCould you clarify "Better choice"? I've been using KVM/Xen/VMware for some time and always enjoyed it. And since Amazon and Google especially are going all in on KVM I'm surprised to hear the Xen is a better choice.
- hennsen 9y agoAmazon is going KVM?
- hennsen 9y agoAh - https://www.theregister.co.uk/2017/11/09/aws_deletes_new_hypervisor_kvm/ https://www.theregister.co.uk/2017/11/09/aws_deletes_new_hyp... Sorry for not googling before asking...
- snvzz 9y ago>Could you clarify "Better choice"? KVM is, like VMware, a Type 2 hypervisor. [1] Xen is a proper Type 1 hypervisor. [1] https://microkerneldude.wordpress.com/2010/10/14/much-ado-about-type-2/ https://microkerneldude.wordpress.com/2010/10/14/much-ado-ab...
- aleden 9y agoIt should be noted that KVM supports many different archs, and it lives inside the mainline Linux kernel while VMware's kernel modules are out-of-tree. I think this fact is an important difference (also that qemu-system-* are open-source, while vmware is not).
- theossuary 9y agoWhy is a type 1 hypervisor instantly considered more secure though? I'd assume using Linux, instead of rolling your own code to interface with hardware, would make you more secure?
- snvzz 9y agoIn the Linux vs Xen example, the TCB is much bigger with Linux. The idea is to keep the TCB as small as possible, with an emphasis on restricting the code size that's actually running privileged.
- monocasa 9y agosel4's virtualization support make it a type 2 hypervisor. Akaros too, which IMO has the right model for virtualization with it's 'VM threads' concept. All 'type 2' really means is that the kernel directly supports running threads in ring 3 in addition to ring 0. I guess it's your use of 'proper' that bugged me.
- mmrezaie 9y agoXen's hypervisor's size is very small. Qubes is about security and trustability of the whole system. In operating systems for measuring the trustability of the system, one very important measure is the lines of the code. Xen has a smaller footprint in the hypervisor part. Additionally, Xen has a robust model isolation for the drivers. That's why they went for Xen not KVM. But boy I wish to see more seL4. It was sad to see Gnu Hurd/seL4 didn't make it.
- walterbell 9y agoQubes mailing list thread about hypervisor choices: https://groups.google.com/forum/m/#!topic/qubes-devel/jEe4pQ2zSKo https://groups.google.com/forum/m/#!topic/qubes-devel/jEe4pQ... > It seems one major residing problem with KVM is the Linux kernel (which is large and vulnerable). A port of KVM to a thinner base layer would obviate those issues.
- nickpsecurity 9y agoOne of the trends I told Joanna about (i.e secure L4 kernels) led to folks developing exactly that. It was called KVM-L4. Here you go. http://os.inf.tu-dresden.de/papers_ps/liebergeld-diplom.pdf http://os.inf.tu-dresden.de/papers_ps/liebergeld-diplom.pdf Complexity was still yoo high. Most in high-assurance security were trying stuff like Nova microhypervisor as a result. KVM on separation kernels might be worth further investigation for these platforms that will stay on KVM regardless.
- xyzzyz 9y agoThe problem with Xen is that no major industry player is backing it, especially with Amazon going KVM now. (disclaimer: working at Google on virtualization security)
- pjmlp 9y agoWhat about Cisco?
- 9y ago
- monocasa 9y agoNo, I'd say that the weakest point is the IPC marshalling necessary to connect all of the containers together into a cohesive system. That's what I'd attack first.
- JoachimSchipper 9y agoA good place to look, but do note that that's the code written by the Qubes OS people - presumably, it's written with security in mind. Of course, Xen has had more eyeballs, so...
- monocasa 9y agoChrome's IPC was written with security in mind too, but most of the sandbox escape exploits have been around IPC marshalling. Unlike the nitty gritty of how the sandbox works, the IPC changes often with new releases. And quite frankly it isn't as fun, cool, or interesting as VMMs or other sandboxing techniques, so a lot of the time it isn't given the close eye that it should.
- mtgx 9y agoThe Genode team proposed some integration with Qubes a while ago, but not sure if the discussion went anywhere from that: https://secure-os.org/pipermail/desktops/2015-November/000008.html https://secure-os.org/pipermail/desktops/2015-November/00000...
- X86BSD 9y agoYou also have access to BHyve on FreeBSD for a good hypervisor.
- floatboth 9y agoJust like KVM, bhyve includes a whole unix kernel in the TCB. Sure it's a better one :) but still. Tiny hypervisors like NOVA http://hypervisor.org http://hypervisor.org, seL4-based are the ideal solution, but sadly no one seems to be pushing to make them usable and production-ready :(
- jjawssd 9y agoIs it possible to run secure code on any Intel microprocessor which supports the x86 instruction set? I do not think so.
- morganvachon 9y agoPre-2006 systems, maybe. I have a PIII based laptop that I'm reasonably sure doesn't contain any malicious microcode or BIOS shenanigans. It certainly doesn't have IME or equivalent. However, that was the CPU that started Intel's serial number controversy, and while I do have a BIOS setting to turn it off, is it really off? It's a pretty deep rabbit hole if you really want to go down it. You can make a case for not trusting any CPU that you didn't design and fab yourself, and even then you have to watch out for your own mistakes and bugs that can be used against you.
- jlgaddis 9y agoDamn, I was really hoping this was an (early) announcement for 4.0 (or at least an -rc3).
- 0x17A 9y agoSame here. I'm waiting for 4.0.
- superasn 9y agoCan it also protect against key-loggers, i.e. if i'm running an app in a qube, can an app in a different qube read my keystrokes?
- 0x17A 9y agoYes, it will protect against keyloggers. Unless you install the keylogger on both qubes. You can have a separate "qube" that is not connected to the network where you would store your passwords, etc.
- Santosh83 9y agoNope, not unless your keylogger is installed in the dom0 qube, or is a hardware one.
- Jeaye 9y agoWhat I'd really love to see is a marriage between NixOS and Qubes, allowing for full-system declarative configuration, including the various systems which will be running under Qubes. NixOS has containers that show how this could work, but they're only via systemd-nspawn, so not as jailed as Qube's domUs.
- akavel 9y agoMe, I'd like to see such a marriage between NixOS and GenodeOS (which provides capabilities management and has the advantage of using a microkernel as base, so much smaller attack surface, aka TSB, than Xen + Linux) http://www.genode.org/about/index http://www.genode.org/about/index
- Mathnerd314 9y agoAn abandoned attempt: https://github.com/ehmry/genode-nix https://github.com/ehmry/genode-nix
- akavel 9y agoIIUC, it didn't build the whole OS, it was more of a port of Nix, not whole NixOS, to Genode. But I may be wrong. As such, it could be seen as a step towards the goal. But I believe a different approach might be also possible: by starting from NixOS, and adding support for L4Linux (thus seL4 - bottom layer), then Genode On Linux (top layer), then somehow connecting the two.
- ohpauleez 9y agoGenode now has its own package management system with the 17.05 and 17.08 releases, informed/inspired by the work from Genode/Nix (linked in the other comment). This means you can run Genode on NOVA with VirtualBox 5 fully integrated as the VMM, all with the improved Noux/POSIX interop components in place, and have a decent package management solution (that handles API compatibilities, multiple version installs, src vs binary deps, packages, and more). There's also Xen support with the most recent release (for cloud appliance work with Genode) What's more, based on the roadmap and challenges, they should be bringing VirtualBox5 support to the seL4 kernel, and they even have a goal for being the virtualization foundation of QubesOS. https://genode.org/about/challenges https://genode.org/about/challenges With the recent toolchain update and new package management system, its easier than ever to cook up your own Genode-based systems.
- bsdnoob 9y agoopenbsd vs qubes os, which one will you prefer?
- JoachimSchipper 9y agoAs an OpenBSD fan: consider Qubes instead if you want a "desktop" experience. OpenBSD works fine, but the open-source desktop is quite vulnerable (consider how many things need to go wrong for https://scarybeastsecurity.blogspot.nl/2016/12/redux-compromising-linux-using-snes.html https://scarybeastsecurity.blogspot.nl/2016/12/redux-comprom...), and a lot of OpenBSD's hardening is in the (simpler) base system, not in GNOME / KDE / Firefox / Chrome / ... Alternatively, consider not running a full-blown desktop or using Windows, which has grown a lot more secure since the Windows XP pre-SP2 days.
- rebuilder 9y agoWow, your recommendation for desktop security is either not running a full-blown desktop or running Windows? As in, Windows beats the popular Linux distros in desktop security?
- deleted 9y ago[deleted]
- muxator 9y agoAre openbsd and qubes really comparable?
- fasquoika 9y agoTo a certain degree. If you're unfamiliar with OpenBSD, security is basically its #1 priority and it's often recommended when you want better security on your server
- rmdoss 9y agoQubesOS -> Secure Desktop OpenBSD -> Secure & minimal Server OpenBSD doesn't have the isolation and hardening on the desktop apps, as Qubes has.
- mtgx 9y agoVersion 4.0 should be out soon (at RC2 now): https://www.qubes-os.org/news/2017/10/23/qubes-40-rc2/ https://www.qubes-os.org/news/2017/10/23/qubes-40-rc2/ Some exciting changes are coming: https://www.qubes-os.org/news/2017/10/03/core3/ https://www.qubes-os.org/news/2017/10/03/core3/ https://www.qubes-os.org/doc/releases/4.0/release-notes/ https://www.qubes-os.org/doc/releases/4.0/release-notes/ EDIT: Downvotes for providing relevant sources, really?
- ZenoArrow 9y ago> "EDIT: Downvotes for providing relevant sources, really?" Sometimes the downvotes on HN make no sense. Looking through your comment history there are a number of recent comments that were unfairly downvoted. Just a guess, but I wouldn't be surprised if it was the same people doing it.
- jlgaddis 9y ago> EDIT: Downvotes for providing relevant sources, really? I only just now downvoted you. From [0]: > Please don't comment about the voting on comments. It never does any good, and it makes boring reading. [0]: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- partycoder 9y agoQubesOS won't protect you from Intel ME though.
- bluepirate 9y agoPurism laptops do.
- morganvachon 9y agoI wouldn't trust that company at all, they lied and misrepresented themselves for nearly three years before finally claiming to make good on what they sold their customers. Beyond that, they didn't fix it themselves as they say, they relied on the work of other projects then claimed they did it alone. Considering the researchers who actually disabled IME require physical access to the machine[1], Purism's claim that they can do it to previously sold devices with only a software update[2] stinks of BS to me. [1] https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Disabling_the_Intel_Management_Engine https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Di... [2] https://puri.sm/posts/purism-librem-laptops-completely-disable-intel-management-engine/ https://puri.sm/posts/purism-librem-laptops-completely-disab...
- floatboth 9y agoIIRC they didn't really lie, everything was always worded like "will be free in the future". Also the post you linked to directly gives credit to me_cleaner and Positive Technologies. The reason the researchers required physical access: > Although some systems do allow the full contents of the BIOS flash chip to be reprogrammed using software tools only (so called 'internal flashing'), on most PCs this facility is either completely unavailable, or can only write to the unprotected areas of the flash filesystem (excluding the ME area), or will only write vendor-signed images. Accordingly, we will describe the approach of using 'external' flashing in this guide, as that is the most reliable. Purism being, uhhhh, the vendor, allowed full write access.
- morganvachon 9y ago
- deleted 9y ago[deleted]
- tonetheman 9y agoI wish there was a way I could try it. The hardware requirements ... https://www.qubes-os.org/doc/certified-hardware/ https://www.qubes-os.org/doc/certified-hardware/ Is anyone running this on a laptop? I get the feeling after reading that page that this is really strictly desktop only. Maybe the page has not been updated in a bit?
- hyperfekt 9y agoI'm running Qubes 3.2 on my laptop right now (Dell Latitude E5470) and it also fulfills all the requirements to run 4.0. The certification requirements are higher, but that's basically if people want to stick the Qubes-certified label on their devices, signaling to customers that it measures up to the highest standards of security. They're not necessary to run Qubes, they're just ideal.
- trizinix 9y agoI run Qubes OS on my Thinkpad T430s for 1.5 years now. Everything worked out of the box.
- forapurpose 9y agoA least around a year ago, Purism shipped computers with Qubes and claimed to be the "only approved hardware vendor". EDIT: See https://news.ycombinator.com/item?id=15735911 https://news.ycombinator.com/item?id=15735911
- qrbLPHiKpiux 9y agoFun fact. The developer does not believe in using a password on her private keys.
- trizinix 9y agoIf you have your keys on an air gapped computer with an encrypted hard-disk, I don't see the need to use an additional password on the private keys.
- kakarot 9y agoOne possible benefit is giving you enough time to discover the breach and rotate keys before the keys are compromised
- hateduser2 9y agoIf they somehow break the encryption on your hard disk it’s just more security.. isn’t that what security’s all about? Getting the most safety you can get? What need is there to have an encrypted hard drive if your computer is air gapped? It’s just a better safer idea, no?
- hyperfekt 9y agoThe assumption is that the encryption can only be broken via an evil-maid attack. If you are victim of such an attack, the encryption of the file is broken as well.
- avar 9y agoSecurity is not about getting the most safety you can get. Otherwise why stop there? You could store the password protected private key itself as an encrypted file on the encrypted disk, and add one more layer, or double-encrypt it and add yet another layer etc.
- parenthephobia 9y agoIf you mean air-gapped literally, that seems unuseful. Wouldn't you want the keys on the computer that's going to use them? And then, wouldn't you want to make it hard to copy the unencrypted private keys? (I'm assuming we're talking about SSH keys.) OTOH, it could be neat to run an ssh agent in a key-holding qube and forward that to whatever qubes need to use your SSH keys, using `ssh-add -c` so that key use must be confirmed in the key-holding qube.
- AaronFriel 9y agoI'm very excited that Microsoft is moving in the same direction. The feature Windows Defender Application Guard (WDAG) runs Windows applications, right now only the Edge browser, in a virtualization isolated container[1]. Under the hood it's using what Microsoft calls "Hyper-V Containers", which are lightweight virtual machines that share some host resources such as a read-only filesystem. The closest open source analogues to that are Intel(R) Clear Containers[2] and Qubes. The closest you can get to Qubes on Windows would be to follow Microsoft's Privileged Access Workstation (PAW) guide, but it requires a lot of additional infrastructure[3]. That infrastructure allows you to do remote attestation of the virtual machines, but makes it costly to deploy in a SMB or homelab environment. I don't expect it'll be very long before PAW and WDAG are usable at the same time, with colored window borders indicating the origin virtual machine. I hope this is on Microsoft's roadmap. Video on privileged access workstation use, starting at a demo: https://youtu.be/3v8yQz2GWZw?t=41m48s https://youtu.be/3v8yQz2GWZw?t=41m48s Video on privileged access workstation setup: https://www.youtube.com/watch?v=aPhfRTLXk_k https://www.youtube.com/watch?v=aPhfRTLXk_k [1] https://docs.microsoft.com/en-us/windows/threat-protection/windows-defender-application-guard/wd-app-guard-overview https://docs.microsoft.com/en-us/windows/threat-protection/w... [2] https://clearlinux.org/features/intel®-clear-containers https://clearlinux.org/features/intel®-clear-containers [3] https://docs.microsoft.com/en-us/windows-server/identity/securing-privileged-access/privileged-access-workstations https://docs.microsoft.com/en-us/windows-server/identity/sec...
- walterbell 9y agoHP has virt isolation for Chromium & IE, via Xen derivative from Bromium: http://www8.hp.com/us/en/hp-news/press-release.html?id=2405444 http://www8.hp.com/us/en/hp-news/press-release.html?id=24054...
- kijiki 9y agohttps://cappsule.github.io/ https://cappsule.github.io/ It's unmaintained now, but it is basically the same idea as WDAG. Essentially similar to firejail but the container gets its own lightweight kernel and runs in a stripped down VM, so the attack surface is KVM, not all parts of the kernel that aren't firewalled off by SECCOMP.
- 9y ago
- magnat 9y agoJoanna's (Qubes OS Founder) blog [1] is a gold mine when it comes to hardware-software boundary security. Especially "State considered harmful" [2] and "x86 considered harmful" [3] papers are eye-openers. [1] https://blog.invisiblethings.org/ https://blog.invisiblethings.org/ [2] https://blog.invisiblethings.org/papers/2015/state_harmful.pdf https://blog.invisiblethings.org/papers/2015/state_harmful.p... [3] https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf https://blog.invisiblethings.org/papers/2015/x86_harmful.pdf
- jstewartmobile 9y agoThat's why I don't get Qubes. She knows what a steaming pile PC hardware is, and decides to write a spinoff OS for it??? Seems like she'd have more effect designing hardware.
- dillon 9y agoI believe I remember reading she aims at solving the issue of hardware and software vulnerabilities. I can't find the source, but she mentions that there's too much code out there that it would be impossible to secure everything. Qubes' design means hardware and software are all separated so a vulnerability in one doesn't mean exposing another. I like that in their docs they mention an approach they take and when it isn't secure[0] That being said the main point of security contention is the admin (dom0). [0]: https://www.qubes-os.org/doc/copy-paste/ https://www.qubes-os.org/doc/copy-paste/
- jstewartmobile 9y agoBut those two things are not independent. If your hardware is fundamentally broken, hypervisors can only paper over so much. Between the twilight of Moore's law, and the success of open-source software, I just don't see that much long-term value left in x86+PC.
- fghtr 9y agoI think you mean this paper: https://blog.invisiblethings.org/papers/2015/state_harmful.pdf https://blog.invisiblethings.org/papers/2015/state_harmful.p...
- notfed 9y agoNote that while Qubes OS uses full-disk encryption, it runs on Xen, which does not support hibernate. This means that, if you use this OS on a laptop, you'll be vulnerable to cold-boot attacks, even after you close your lid, unless you configure it to shutdown on lid close. (I.e., if a highly skilled adversary steals your laptop then, even if your laptop lid is closed, they will be able to read your RAM and therefore decrypt your entire hard drive.) Despite the major security implications, it doesn't sound like a fix will be implemented any time soon. [1] [1] https://github.com/QubesOS/qubes-issues/issues/2414 https://github.com/QubesOS/qubes-issues/issues/2414
- bearbearbear 9y agoIf a highly skilled thief wants to break into my house they could jimmy the latch on the window and let themselves in. I don't have any bars on my windows to prevent that. You need to draw the line somewhere.
- carlmr 9y agoYeah, I'd say it depend on if you're a normal user or Edward Snowden. Do you have really sensitive data that could cost you your life? Then you have to worry about these edge cases. Are you a normal guy who wants to browse for porn safely, then this is already pretty good privacy.
- notfed 9y agoDo you consider your credit card number sensitive? Your username and passwords to all of your, bank accounts, social media accounts, and email accounts? Your personal photos? Your personal notes with personal information about your family? Your track record of your interests and hobbies? I do. And, if I have a choice, I'd rather not have to wonder if this data is in the hands of a stranger after my laptop is stolen.
- carlmr 9y agoIt has to be stolen a) while it's on, and b) by someone who immediately knows what to do. I'm quite sure if you look at your average thief and multiply these to chances together that's less than one in a million chance to happen. Assuming you're not some high profile person where the right person is out to get you and knows which OS you use, and knows how to steal from you.
- drawnwren 9y agoI ran Qubes on a laptop for a while. 1) It's a huge battery hog. 2) It's a real pain to run a non rolling release distro (i.e. Arch). Some dependency is going to try and upgrade itself that can't and it will brick your whole distro. Even being locked to a specific release proved a bit of a pain. It just adds a lot of complexity to your day to day operations (i.e. opening a program is a tiny bit more complicated) that turned out to be a huge drain for me.
- kakarot 9y agoRunning an HVM with a separate kernel should alleviate those problems. Qubes is phasing out PV support anyway. I encounter an equal amount of complexity in my KVM workstation as I did in my Qubes workstation, and more problems. For example, lack of a secure copy/paste mechanism, meaning I must type passwords by hand to avoid every VM being exposed to the clipboard.
- spiraldancing 9y agoWhatever happened to the Qubes-Purism marriage? They were on track to start Qubes-certifying Librems, and selling Librems with Qubes pre-installed ... then they cancelled the plans, and I never heard why?
- xkarga00 9y agoFWIW, it seems that when you buy a Purism laptop there is an option to include a Qubes live usb in the deal. I just came across it while skimming through their website[1], not sure about anything else. [1] https://puri.sm/shop/librem-13/ https://puri.sm/shop/librem-13/ - see the Operating System choice
- spiraldancing 9y agoThanks. I know about that. They used to sell Librems that had Qubes pre-installed, and they were on-track to get Librems to be the first officially certified hardware for Qubes. Then they canceled the whole thing, and now, as some kind of consolation/compromise, they offer Qubes-on-a-stick purchase option.
- jnwatson 9y ago10 years ago, I helped design a similar system. It was a capabilities based OS on a formally modeled microkernel. I'm still not sure than there's a market for this stuff. It must be free, and it's hard to build a business model around that.
- nickpsecurity 9y agoWhen Joanna said nothing like Qubes existed, I told her INTEGRITY PC was doing it around 2005 using separatiom kernel approach with stronger security. You must have worked on that one given 10 years remark. Im curious about your experiences with that. Email me if you want details confidential. Rarely meet folks doing the kinds of architectures I research and push for further adoption.
- txgvnn 9y agoHow about Subgraph OS? It has grsecurity patch, tor network, container isolate, firewall. It's another good choice also https://subgraph.com https://subgraph.com
- xtanx 9y agoI've been running Qubes 3.2 for about 10 months on a intel skull canyon nuc. I love it. I have separate vms for media and browsing, for music (spotify), development (python, rust), skype, personal email, work email and password manager. It needs 16gb of ram to be able to run all of these at once and about 150gb of disk if you actually create separate template vms. My only real pain was coping and pasting between all of these vms (you need to ctrl+c then ctrl+shift+c for copy and the ctrl+shift+v, ctrl+v for paste [1]) I solved that with a custom solution that automatically distributes the clipboard contents (for text only) to multiple vms (depending on the source of the clipboard change). I know it defeats the purpose of isolation for the clipboard but it's ok for my use case. [1] https://www.qubes-os.org/doc/copy-paste/ https://www.qubes-os.org/doc/copy-paste/
- known 9y agoI use https://en.wikipedia.org/wiki/Lightweight_Portable_Security https://en.wikipedia.org/wiki/Lightweight_Portable_Security
- EEN_SoftEcoSDK 9y agoIt is likely impossible to devise a secure and reliable operating system. Why not change the problem statement to something with a solution? How can a system survive a successful hack or virus infection with minimal damage? A system can be built with functionality distributed across many computers. Message communication between computers can be routed through a central hub with a white list to ensure only the passage of a legal message. A message can travel two paths (through two central hubs) for reliability. An infrastructure called SoftEcoSDK contains mechanisms to help programs achieve a secure and reliable system. There is a client to server mechanism that helps to recover a client work session or a server work session after a failure. Visit SoftEcoSDK.com for more details.