4 ms·
I think one qubes feature that could be profitably extracted are the disposable VMs, particularly for web browsing but also as a sort of default jail for potent
by eduction 2y ago
I think one qubes feature that could be profitably extracted are the disposable VMs, particularly for web browsing but also as a sort of default jail for potentially dodgy software. Like a right click “run this in a disposable vm” option in mainstream OSes. And run the built in web browser like that by default.
Apple could probably come up with some spiffy branding. “Run this on an islandTM” or something like that. Call the feature “Archipelago.”
- fishgoesblub 2y agoIntroducing: Apple Iceberg™ Isolate your apps for enhanced security through Secure Containers™ on all MacOS™ systems
- wishfish 2y agoWouldn't Windows Sandbox come close? Easy to fire up and it all vanishes on exit.
- LeFantome 2y agoYou mean, like a Docker container?
- ElectricalUnion 2y agoNamespaces and jails share the host OS kernel. Assuming malicious applications, you don't want to expose your kernel, so those aren't safe enough.
- transpute 2y ago> one qubes feature that could be profitably extracted are the disposable VMs, particularly for web browsing but also as a sort of default jail for potentially dodgy software A similar feature ships on HP business PCs as HP SureClick based on uXen, derived from Bromium micro VMs, derived from Xen, which is used by Qubes. Also cloned by Microsoft in Windows as Application Defender Guard. Bromium isolated each tab of a web browser in a separate Windows VM with copy-on-write memory, and even individual network connections could be isolated in a micro-VM. A similar architecture has evolved on mobile phones as Android Virtualization Framework (AVF) with pKVM nested virt. Apple has taken baby steps in this direction, adding hardware nested virt on M2+ silicon, M3+ macOS and M4+ iPad Pro "Secure eXclave" micro-VM for camera LED indicator. While the underlying infrastructure is slowly being built to enable disposable VMs and other security improvements based on micro-VMs, one challenge is high-performance graphics composition of display output from the VM with the main desktop. Google has blazed an OSS trail with virtio and CrosVM on ChromeOS, which will hopefully be ported to Android with external display output. Since Apple controls both hardware and OS, they could add GPU hardware support for virtualization, removing any perceptible UX slowdown from micro VMs. Intel already added SR-IOV virtualization to Xe iGPUs.
- eduction 2y agoThanks, this is great overview of the space, I had no idea about all this. Maybe I should play with other OSes more beyond Mac and Qubes and Linux but configuring Qubes tends to take up all my extra OS time :-)