10 ms·
Qubes Air: Generalizing the Qubes Architecture
- mirimir 9y agoThis is interesting. However, I don't get how stuff in the cloud can be considered secure. Unless you trust them, anyway. And also, I'm reminded how little privacy seems to matter for Qubes devs. Edit: OK, I take it back. Replacing VMs with discrete devices on local networks is very cool. I just wish that they'd emphasized that, and then talked about using cloud resources. Indeed, what boggled my mind is that someone would go through the hassle of learning Qubes, and then put some of it in the cloud.
- ecesena 9y agoUh!? What’s the issue with privacy? Qubes is great to make sure you don’t get a malware while you watch “youtube”, and this malware gets access to your bank account. I feel privacy is kind of out of scope here, not that you don’t need it, but you can plug it in with ease. There’s nothing in qubes design that prevents privacy. Cloud is just a way to distribute computation, and make sure storage is always available to you. Everything should be assumed to be protected — I mean, they protect video memory among processes/apps, you’d bet they protect your data on the cloud.
- jimktrains2 9y agoThat's all assumptions thought. I'm assuming they're protecting stuff. I'm assuming they're not looking at stuff. I'm assuming their underlying systems are patched. It's just assumptions that they're doing the right thing.
- mirimir 9y agoThere is currently no way to keep cloud stuff private. Maybe one day homomorphic encryption will be usable. And without that, the cloud provider can see everything. You can, of course, encrypt stuff locally first. But that's only good for static data.
- xelxebar 9y agoThe cloud stuff seems incidental to the article's main point. At least that's how I read it. Rather, it sounds like they are trying to properly abstract the isolation technology away from any specific implementation. They then realized that this would also allow "Qubes on the Cloud" with relatively little extra effort. From a personal choice standpoint, it seems we will still have the option of avoiding cloud zones completely if we so desire, so no harm there. If we think about the sociology of security however, lowering the barrier to entry seems like an overall win, assuming we believe in the Qubes security model. It's a lot like fingerprint readers on phones. Sure, they're not near as strong as a high entropy password, but they're convenient enough so people who previously never locked their phones now use a fingerprint lock.
- conradev 9y agoI agree. I liked the diagram that showed separate machines on the same local network running qubes. Physical separation is stronger compartmentalization than Xen.
- mirimir 9y agoYes, I agree. And I wonder what a hybrid with Tinfoil Chat might look like. That is, using opto-isolators to make some device-qubes read-only.
- robryk 9y agoYou can put the untrusted VMs in the cloud, to get better isolation between them and more important stuff. This, e.g., is a way of preventing two colluding VMs from communicating.
- masklinn 9y agoThat's a very interesting take, you can run local network for trusted qubes and put more risky/untrusted qubes on "cloud" VMs, that way you strongly mitigate colluding VMs (same-machine & same-network) and VM excursion attacks on your hypervisors & physical machines.
- ecesena 9y agoQubes would make for a great startup and, given the time, prob a very successful ICO. I was positively and at the same time negatively surprised reading about the 30k users. All issues/obstacles reported don’t seem so unachievable if one can imagine to focus on one specific hardware platform and with a good marketing team. I understand this is beyond a research project, but it would make for a great startup.
- tlrobinson 9y agoWhy would Qubes do an ICO?
- ecesena 9y agoFor the cloud, it would be an incentive to run the nodes, and you’d pay for the resource you’re using. I’m not saying they should, Im saying it could be a good startup or, in this case, a good model for a blockchain-based company.
- kakarot 9y agoI think the idea is you just buck up and pay the cloud fees. If you follow Qubes / ITL, you would know that they are hardly a "startup" as a decade-old company, and they have been experimenting with enterprise-level support. If they can find a home in the enterprise market, it will at least give them enough cashflow to continue developing Qubes for the foreseeable future. Besides, I imagine Joanna Rutkowska's opinion on the ICO scene isn't a very positive one, and I don't think she wants to complicate her company by pivoting to a blockchain model that has absolutely no relevance to developing secure operating sytems.
- ecesena 9y agoI don’t know how to write it better. I never said Qubes should change their biz model or do an ICO. Full stop. All I said is that their product would be great in the hands of a startup that focuses on a single hardware platform and does more marketing, and/or does an ico because I see a great incentive to run nodes of the cloud (because qubes utself provides all the building block for trust). > If you follow Qubes I do, since 2010, when I was doing very similar research on trusted cloud computing. > If they can find a home in the enterprise market I wish it to them, but this doesn’t mean someone else can try a more aggressive consumer route, or an alternative for their cloud model. I respect a ton their work, and as I said in my very first comment I think they should focus on the research part, and someone else could provide capital and grow the consumer product.
- xvilka 9y agoWonder about their progress of integration[1] with ReactOS. [1] https://github.com/QubesOS/qubes-issues/issues/2809 https://github.com/QubesOS/qubes-issues/issues/2809
- jeditobe 9y agoMe too
- secfirstmd 9y agoThat would be amazing...especially for helping transition people who feel uncomfortable with Linux type environments.
- adultSwim 9y agoI think the Qubes team desperately needs more funding. Give them some of your money. Tell them your priorities. Qubes + Whonix has been an enormously tremendous success. I'm so happy to have Qubes as my daily driver at home. However, because of so little money coming in, development seems much more limited than it could otherwise be. It's a wonder what they've been able to do so far with no budget and few external developers contributing.
- weinzierl 9y agoI‘m a heavy user of Qubes OS. The “Convert to Tusted PDF” feature is something I use almost daily. My use case is examining, cleaning and possibly distributing application letters and CVs. If you have to read job application letters, the advice to just open files from people you trust, just doesn’t work. The amount of untargeted malware we receive through this channel is considerable. We had targeted attacks too. I’ve known about Qubes OS for a long time but interestingly the advice to use it for all processing of application letters didn’t come from my tech circles but from a recruiter. Given the strict laws about data retention in my jurisdiction (Germany) a cloud solution (short of homomorphic encryption) probably isn’t going to work for me. The idea of using discrete devices sounds interesting though.
- viraptor 9y agoHave you considered a jailed pdf reader application instead? I'm curious what the decision factors were important for you.
- blattimwind 9y agoSo everyone downstream of weinzierl has to be aware that (1) the PDFs he hands them may be full of malware (2) have to use VMs (3) must open said malware-packed PDFs in a disposable VM (4) must strictly adhere to D-VM usage protocol.
- dhimes 9y agoOr weinzierl could print them and possibly rescan for further distribution.
- JulianMorrison 9y agoConvert to DjVu.
- blattimwind 9y agoWhich is basically what Qubes "Convert to trusted PDF" does.
- slaymaker1907 9y agoI think the cloud aspect is also quite interesting in the potential for a much cheaper remote desktop. Most applications don't require a beefy CPU, so just run them on something cheap and then just run anything demanding on a more powerful node.
- kakarot 9y agoThis was an awesome read. These guys are doing some of the most groundbreaking work in computing right now. The idea of having an "operating system" made up of components dispersed across the globe seems like a fantasy that is too good to be true. If Qubes can finally provide a method for passing through NVIDIA GPUs with this kind of architecture, Xen or not, that would be incredible. It's the only reason I had to leave Qubes.
- hawski 9y agoIt did not help Plan 9 to conquer the world. I found a good introduction to Plan 9 architecture in this comment: https://news.ycombinator.com/item?id=15989697#15990077 https://news.ycombinator.com/item?id=15989697#15990077
- eptcyka 9y agoPassing through GPUs is problematic, as it's a massive attack surface.
- effie 9y agoCould you elaborate on the 'massive'? Let's say you let the VM see the GPU. What kind of attack would that enable? Let's suppose that a virus inside VM manipulates GPU outside of what applications are allowed to do. What worst thing could happen?
- pjc50 9y agoThe GPU is a PCIe/AGP "bus master", so it can usually initiate DMA transfers from host memory and read anything it likes. IOMMU blocks some of this, but is not a perfect defence. https://security.stackexchange.com/questions/150386/does-iommu-prevent-dma-attacks https://security.stackexchange.com/questions/150386/does-iom...
- effie 9y agoThanks, according to [1], it seems DMA is quite a 'backdoor', bypassing any memory management the kernel would do. But it is not clear to me whether this allows the attacker inside VM also to write into the forbidden regions of memory and thus either modify behaviour of the hypervisor or send information out via Internet. [1] https://en.wikipedia.org/wiki/DMA_attack https://en.wikipedia.org/wiki/DMA_attack
- qplex 9y agoQubes runs mostly on computers with Intel CPUs. It's good of them to admit that the layers-upon-layers approach just doesn't bring in any additional security if you have buggy/unsecure hardware.
- jstewartmobile 9y agoAmen. Huge silver lining to Meltdown has been raised awareness over what a mess our hardware is. As long as we're in Intel x86 land, the Plan 9 service-per-box approach is probably about the best we can do, and I'm not saying that with any joy, or as an endorsement. Or, perhaps we can claw our way back to the 1960s and reclaim working memory protection? As obvious as that sounds, I wouldn't take it for granted. People already accept all sorts of half-broken proprietary bullshit for GPU performance, bootloading, AMT, etc. From the mailing lists, looks like Intel is trying to normalize that for CPUs as well.
- transpute 9y agoWith the Qubes Air architecture, the unpopular Intel ME/AMT could be repurposed as a VNC server for web browsing on a dedicated device, e.g. old laptop. The AMT VNC client could be run in a thin Qubes VM. This would isolate the web browser (main x86 CPU), VNC server (Intel ME cpu) and VNC client (Qubes device CPU) on three physical processors. Usability would depend on performance of the AMT VNC server.