5 ms·
Qubes: an open source OS with strong security for desktop computing
- evangineer 15y agoRelated HN post: http://news.ycombinator.com/item?id=2320207 http://news.ycombinator.com/item?id=2320207
- moondowner 15y agoKDE, a good choice. I see they've utilized KWin decorators to display green or red windows, nice idea.
- m0nastic 15y agoWhen I saw the diagram showing the way Joanna partitions her computing on her blog in March, I thought I was looking at something a schizophrenic would have drawn. I think this line of research is interesting though, even if I don't foresee ever using it.
- nvictor 15y agoaren't the specs a little too much for an os focusing on security? Minimum: 4GB of RAM 64-bit Intel or AMD processor (x86_64 aka x64 aka AMD64) Intel GPU strongly preferred (if you have Nvidia GPU, prepare for some troubleshooting; we haven't tested ATI hardware) 10GB of disk (Note that it is possible to install Qubes on an external USB disk, so that you can try it without sacrificing your current system. Mind, however, that USB disks are usually SLOW!)
- eropple 15y agoI agree - it sounds like a performance nightmare across the board, even with those aggressive specs. Wonder how it handles OpenGL applications and games.
- X-Istence 15y agoIt is definitely not meant to be used for gaming. The whole idea is to put everything in a Xen virtualised environment so that you can run untrusted applications or applications with untrusted input in different security levels.
- eropple 15y agoYes, I realize that. The practical concern is that people like to play video games, and if your high-security desktop OS doesn't let them, it will be discarded.
- mishmash 15y agoKinda hoping it's late where you are, like it is here, because otherwise your comment is pretty silly. Absolutely no one that finds this interesting is going to give a crap about playing games on it - just like nobody cares about gaming on the BSDs, or Solaris, or even Linux.
- freyrs3 15y agoQubes is not a desktop OS for the masses, it's a niche operating system for professionals who need a high security environment. I would doubt it would be discarded based on lack of game compatibility since anyone who has that level of security knowledge is certainly going to be able to dual boot into whatever more game-friendly OS they need.
- eropple 15y agoThat's the thing, though: I am skeptical that your "professional who needs a high security environment" is going to be satisfied by this. It's turtles all the way down--while I know Joanna herself was one of the folks behind the Bluepill attack, why trust Qubes to not be vulnerable to its own version of the attack? (This is obviously an oversimplification and executing such a task is nontrivial--but breaking out of a VM was thought to be a lot harder than Bluepill made it, too.) The closest thing to an answer to that, as far as I can tell, is multiple computers. Assuming Qubes works as advertised, however, it seems as if it doesn't really scratch the bigger itch--the technology seems cool (I haven't dug deeply into it), but does it address the social/usability problem of security, even for these professionals who need that high security environment? From reading about this, it seems as if you could have stopped at "it's a niche operating system," because to my mind it seems like professionals who need a high security environment will just have multiple computers. If a segmented system like Qubes is not going to run the stuff that your hypothetical professional will want to run (games just being an example, and one that seems to have been misleading), then why would it be preferable to just rolling multiple computers? (Cost, which is the only advantage I can think of, doesn't strike me as a significant factor to folks who are actually doing things that necessitate this sort of security.)
- X-Istence 15y agoNo, what it does is put everything in different Xen virtualised machines. That is why it needs those specs. It isn't meant to be used as a general purpose OS, it is meant to be used by the paranoid to be able to partition their daily dealings while still using the same physical machine.
- JoachimSchipper 15y agoThis assumes that you can't break out of the VM, and that you can't gather information across the VM boundary. From http://news.ycombinator.com/item?id=2573618 http://news.ycombinator.com/item?id=2573618: > ... [C]onsider e.g. http://cseweb.ucsd.edu/~hovav/dist/cloudsec.pdf http://cseweb.ucsd.edu/~hovav/dist/cloudsec.pdf - cross-VM attacks are real, and extremely scary.