4 ms·
Qubes OS achieves isolation by separating apps into VMs. Wayland does this at the display protocol level. If Qubes OS is serious about security, they should con
by throwaway84932 1mo ago
Qubes OS achieves isolation by separating apps into VMs. Wayland does this at the display protocol level. If Qubes OS is serious about security, they should consider Wayland with containerization. It would result in a similar level of isolation with significantly lower resource overhead.
- zbentley 1mo agoI feel like the sheer volume of OS LPEs and escape CVEs in container runtimes indicates that, at least for now, the security boundary capabilities of containers are inferior to those of VMs. Which is ironic, given that a lot of the tools that underly a container runtime were originally designed to facilitate security, not ease of deployment.
- throwaway84932 1mo agoYou're aware of the VM escape issues over the past decade? There's no perfect, and high overhead from running many guests can also create security risks. Wayland with all of its problems remains a logical step forward from the X model.
- zbentley 1mo agoI was narrowly responding to the point about Qubes using VMs. I have no problems with Wayland’s design; I agree that it’s a step forward.
- throwaway84932 1mo agoAh, got it! Thanks for clarifying. That makes a lot of sense.