3 ms·
>My computer has disabled and neutralized Intel ME. So why don't you make that the top priority before Qubes? Isn't it essential to make sure every user of Qub
by GhettoComputers 5y ago
>My computer has disabled and neutralized Intel ME.
So why don't you make that the top priority before Qubes? Isn't it essential to make sure every user of Qubes does the same? Locking the screen door without locking the front door isn't at all secure. Do you expect the people worried about an email to flash the BIOS with an clip connected to their Pi or Arduino they programmed first? Its a sales pitch that ignores bigger issues. Most people from that pitch if convinced will have a false sense of security when the real threat is an ever present backdoor that can be hacked.
>Qubes PVH virtualization has no practical effect on performance. Qubes works great for me for everything that a non-sophisticated user would want, except games. RAM is cheap.
People like to play games, not everyone has removable ram or multiple slots, and if it has no practical performance effect, what computer do you have? I bet your computer isn't a generic dual core that most people have. You said it has no GPU acceleration, which a lot of browsers use, so it wiil be much slower for most people.
>Any serious privilege escalation which happen every month on all other systems.
Again, what real world threats? You say serious, but these threats are not serious, if they were, you wouldn't need to convince anyone to use qubes. There are not real issues, BSD servers that don't update or reboot for years wouldn't exist if there were actually any serious threats. Windows has automatic updates, Linux has quick patching, OSX had a bunch of RCEs corrected and no hacks. You fail to name a single concrete threat. Its cool if you want to run a bunch of VMs, but on a laptop that you need 32GB of ram, that depletes battery life more, and for some vague "serious privilege escalation"? Its a hard sell, better to suggest it as a remote desktop that you can control with a thin client.
- fsflover 5y ago> Locking the screen door without locking the front door isn't at all secure. https://news.ycombinator.com/item?id=27897975 https://news.ycombinator.com/item?id=27897975 Yes, it would be ideal to have everything open and controllable. However you need to take into account the bitter reality and go step by step. Are you aware of any possibility of remote access with Intel ME? I'm not. See also: https://forum.qubes-os.org/t/intel-me-real-threat-for-ordinary-persons https://forum.qubes-os.org/t/intel-me-real-threat-for-ordina.... > Do you expect the people worried about an email to flash the BIOS with an clip connected to their Pi or Arduino they programmed first? I did not do it myself and I don't expect that people will do it, too. I bought my Librem 15 as it is, and recommend to everyone. (It's not sold anymore, Librem 14 replaced it.) See also recommended computers: https://forum.qubes-os.org/t/community-recommended-computers https://forum.qubes-os.org/t/community-recommended-computers. > I bet your computer isn't a generic dual core that most people have. It's actually dual-core i7-6500U. > People like to play games Sure. These people unfortunately are not the target audience of Qubes, unless they are ready to do GPU passthrough (which has been shown to work). > not everyone has removable ram So what? Do you suggest to give up? People who are aware of dangers of the Internet could choose their next machine to be compatible with Qubes and allowing more security and control. > You said it has no GPU acceleration, which a lot of browsers use, so it wiil be much slower for most people. Bloated websites are slow, almost independently on what machine you have. User-friendly websites work flawlessly for me. Youtube works fine. > but these threats are not serious, if they were, you wouldn't need to convince anyone to use qubes. Are you implying that every person knows everything about their threats and makes perfectly logical decisions? This is not a game with complete information: https://en.wikipedia.org/wiki/Complete_information https://en.wikipedia.org/wiki/Complete_information. People need security even if they do not realize it yet (until their data is leaked, which happens very often nowadays). > BSD servers that don't update or reboot for years wouldn't exist if there were actually any serious threats I don't see the logic here. There are millions of hacked servers in the world used for spam and DDoS attacks. Where do you think they come from? (hint: not just from IoT devices) > Windows has automatic updates, Linux has quick patching Before it is patched, you are vulnerable. It's called a "zero-day vulnerability". And you are typically not aware of it when it happens. Also, vulnerabilities in browsers are also numerous and frequent. > better to suggest it as a remote desktop that you can control with a thin client I don't get it. You are going to connect to a "secure" server from an insecure machine with full access. Do you expect that your server stays secure after that? You also did not mention that Qubes defends you from simply broken software which you sometimes have to install, which could make your system unstable. > but on a laptop that you need 32GB of ram, that depletes battery life more Are you aware that a lot of people today are using a laptop as their desktop home computer? I do. Also, note that I'm not trying to literally sell anything. I'm just a happy Qubes user and I think that more people deserve better security for their computing.
- GhettoComputers 5y agoI see pitching as sales. Yes, I think qubesOS is perfect for people who worry about privacy, opening emails, still want a PC over a tablet or phone, do not have Intel ME/AMD PSP and will spend much more for lesser hardware to purchase one without or are willing to do so themselves, do not play games, battery life not as important, have an i7 with expandable ram up to 32GB, do not install patches often, and are willing to isolate their programs in VMs. >Are you aware that a lot of people today are using a laptop as their desktop home computer? I do. False, most are using mobile like phones and tablets as their main computer, desktops and laptops have declined for over a decade. >I don't get it. You are going to connect to a "secure" server from an insecure machine with full access. Do you expect that your server stays secure after that? Does my insecure computer compromise hacker news?
- fsflover 5y ago> Does my insecure computer compromise hacker news? Probably yes, if you access HN via ssh with root privileges.
- GhettoComputers 5y agoLots of ifs, like if I installed a hardware keylogger onto your computer. >I don't get it. You are going to connect to a "secure" server from an insecure machine with full access. Do you expect that your server stays secure after that? Yes, XEN and hardware virtualization keeps it all safe. VMs like those on Qubes work the same way. Most laptops don't have good virtualization hardware, expandable ram, or decent processors. Connecting to a server doesn't compromise it in any real world scenarios, the same way if I remote access your laptop through mine, root ssh is not common, and you'll have it isolated in a VM anyway won't you?