4 ms·
Yet Qubes OS demostrates it's possible to run X11 programs isolated from each other. They had the need and will to improve security, and found the way over a de
by ElectroBuffoon 2mo ago
Yet Qubes OS demostrates it's possible to run X11 programs isolated from each other. They had the need and will to improve security, and found the way over a decade ago.
Making server side decorations an important part of it. Oh, the irony.
- throwaway84932 2mo agoQubes OS achieves isolation by separating apps into VMs. Wayland does this at the display protocol level. If Qubes OS is serious about security, they should consider Wayland with containerization. It would result in a similar level of isolation with significantly lower resource overhead.
- zbentley 1mo agoI feel like the sheer volume of OS LPEs and escape CVEs in container runtimes indicates that, at least for now, the security boundary capabilities of containers are inferior to those of VMs. Which is ironic, given that a lot of the tools that underly a container runtime were originally designed to facilitate security, not ease of deployment.
- throwaway84932 1mo agoYou're aware of the VM escape issues over the past decade? There's no perfect, and high overhead from running many guests can also create security risks. Wayland with all of its problems remains a logical step forward from the X model.
- zbentley 1mo agoI was narrowly responding to the point about Qubes using VMs. I have no problems with Wayland’s design; I agree that it’s a step forward.
- throwaway84932 1mo agoAh, got it! Thanks for clarifying. That makes a lot of sense.