4 ms·
What I wonder is about Qubes [0]. For a long time zero implicit trust is my default way of configuring small systems of 3 or 4 hosts and a handful of services.
by nonrandomstring 3y ago
What I wonder is about Qubes [0].
For a long time zero implicit trust is my default way of configuring
small systems of 3 or 4 hosts and a handful of services. But I get
tired of the administration overhead.
Does anyone who knows Qubes well, and has a sound understanding of
what's implied by this NIST advice, think it's a good fit for meeting
some of the advice? It seems less work.
WRT third parties? Why would anyone outsource trust in a domestic, or
small office system?
[0] https://en.wikipedia.org/wiki/Qubes_OS https://en.wikipedia.org/wiki/Qubes_OS
- aborsy 3y agoI sometimes use Qubes and I find it very useful for securing individual workstations. You can run applications such as a browser in disposable VMs. A vulnerability in the application doesn’t compromise most of the system. Different components such as networking or USB run in isolated environments. That’s segmentation part of the NIST advice (at OS level, not network). It’s especially useful against targeted attacks, that often rely on the zero day exploits. As far as I know, it’s very difficult to chain two vulnerabilities, one in the browser and one in the Xen hypervisor to escape the hypervisor security boundary. There are also a host of other security features, such as air gapping some of data, built in support for Whonix (probably the most secure way to access the Tor network), Gpg Qube, etc. Qubes-OS is usable, although it has to be made more user friendly. You can organize your digital content in isolated “computers” which simplifies your setup. Like, one VM for each project or client. Highly recommended! Another thing: the OS is not backed by a company. You have to trust independent developers (but they are known publicly), in addition to Debian or Fedora developers.
- nonrandomstring 3y agoThanks. Does it make running identity based compartmentalisation across multiple bits of hardware any easier? Anything to replicate/migrate VMs across a network securely or owt like that? Or is it more "single workstation" model as you say?
- aborsy 3y agoIt’s definitely meant to be a single user operating system. It does have a VM back up system, and you can back up your home data with the usual third party tools.
- nonrandomstring 3y agoCheers aborsy. Still on my todo list to harden individual nodes.