10 ms·
Of course it improves security. On Qubes, someone who can exploit your browser (pdf reader, word processor) doesn't automatically get free rein on your machine.
by spindritf 12y ago
Of course it improves security. On Qubes, someone who can exploit your browser (pdf reader, word processor) doesn't automatically get free rein on your machine. They still need to escape Xen.
- csirac2 12y agoNot just apps, it even routes physical USB devices to specific VMs, which potentially mitigates BadUSB type attacks against the dom0. And I really appreciate that they've tried to solve XDMCP weaknesses.
- mrottenkolber 12y agoNope. If somebody exploits your PDF reader, they still have to circumvent the OS. Sound familiar? Now instead of one layer with hardware contact, you have two (assuming you want performance too). Twice the attack surface.
- amalcon 12y agoThis would be sound logic if existing desktop operating systems had actual good security models. In the real world, if someone exploits your PDF reader, they don't have to circumvent your OS: your OS hands over everything you can access, by design. One could argue that a better security model baked into the OS would make more sense than a virtualization hack, but the latter has the advantage of actually existing.
- Touche 12y agoWhat would be the better security model?
- SamReidHughes 12y agoSomebody exploiting your PDF reader can't upload all your email.
- Touche 12y agoThat's not a model. What's the model that prevents this? User performs a 2-step auth every time code executes?
- SamReidHughes 12y agoJust pick one that gives the feature I described without being a pain to the user.
- Touche 12y agoI know of no such models. Perhaps someone smarter than me has thought of them, that's why I asked the question initially.
- SamReidHughes 12y agoSandboxing. It's present on OS X.
- Touche 12y agoI'm confused. The original person I responded to said that no desktop OSes had good security models. On OSX I can write a script that, when run as a user, has access to everything the user has access to. So what exactly are you talking about?
- deleted 12y ago[deleted]
- SamReidHughes 12y agoI'm talking about OS X sandboxing. The hypothetical PDF reader doesn't have access to the email.
- pjmlp 12y agoSandboxing, where each process is only allowed to use a precise set of system resources. Any attempt to use anything else leads to termination.
- wyager 12y ago> If somebody exploits your PDF reader, they still have to circumvent the OS. That is correct. This is probably why privesc exploits are much more expensive than adobe reader exploits. You are kind of arguing against yourself here.
- walterbell 12y ago> Now instead of one layer with hardware contact, you have two (assuming you want performance too). Could you expand on that statement? By definition, only one layer can own each hardware component.