4 ms·
I always wonder that maybe someone can convince these health companies, clinics, etc... to start using Qubes OS for their network connected office computers. Ma
by spoonfeeder006 2y ago
I always wonder that maybe someone can convince these health companies, clinics, etc... to start using Qubes OS for their network connected office computers. Maybe that could prevent a sizeable number of these ransomware attacks?
TLDR Qubes OS is a security focused operating system that is geared towards end users. It relies on isolation via the Xen hypervisor (has much less privileged code than Linux, Windows, or Mac kernels), and uses hardware based virtualization features of the CPU as well. E.g. it prevents a compromised network card from accessing the memory of a trusted virtual machine through DMA attacks as an example
And ultimately it incorporates this isolation into a seamless user interface as well
I'm guessing the primary feature that would protect against ransomware is that it allows on to open suspicious links in disposable VMs
- sofixa 2y agoWith the move of most enterprise software to web interfaces, this could be realistic for some organisation. Others, especially in healthcare, will have odd legacy thick clients developed in obscure languages decades ago that nobody wants to port.
- hsbauauvhabzb 2y agoHas there been any organisation to successfully roll this out, ever? It’s great for security, but useless from a productivity standpoint.
- rty32 2y agoNot sure using a different OS helps the issue, if not making it worse -- * These days hackers have a lot of resources and are often nation state actors. They utilize 0 day vulnerabilities. I don't see how an obscure OS will do any better than mainstream OS in terms of detecting and responding to exploits * Many hacks actually start with social engineering, and human becomes the weakest point (well, in some sense, it always has been) * Users, most of which are not computer experts, could make more mistakes when they are faced with software/interfaces they are not familiar with. (I'm just making this up, happy to see data that says otherwise.) "Open suspicious links in disposable VMs"? Sure, if they have received enough training and can do it perfectly, every single time, and never confuse the VM and the host environment. I'd say "never open suspicious links, forward the email to IT to help with you if needed", or even, just filtering untrusted domains in the email, is a much simpler and effective approach.
- blitzar 2y agoI expect you could mitigate 9 out of 10 breeches by staff not giving out their teams shared admin password (which is password123) over the phone to someone who says they are Jim from the CEOs office who needs to check some numbers for the big presentation tomorrow.
- spoonfeeder006 2y agoLess privileged code would mean less zero day exploits. Qubes relies on an order of magnitude less privileged code than Linux, and I believe Xen has had far fewer escalation of privilege exploits than Linux kernel "Open suspicious links in disposable VMs" change that to "Open all links using the appropriate process" But yeah, the social engineering though...
- sgarland 2y agoThink how many companies have been found to have world-accessible S3 buckets. And you think they’re capable of administering Linux, let alone a niche OS like Qubes?
- spoonfeeder006 2y agoTrue. I guess the root issue is often much more basic