TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: What you think about QubesOS and linux security?

4 pointsby c8gover 8 years ago
https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=13190597<p>you might have noticed this. i thought i should not use gui (desktop). then someone mentioned it.<p>are you think it is more secured and reliable?

3 comments

SXXover 8 years ago
Modern Linux desktop is extremely insecure and lack of any kind of isolation so any process that have access to X can do anything no matter what security measures you applied. With Wayland it&#x27;s possible to isolate desktop applications, but there still unsolved problems like audio.<p>And with concepts like Qubes main flaw remain the user just like with network privacy in TOR &#x2F; I2P. There is very few people around who can actually follow draconian rules systems like that enforce. And once you start to use one app insecurely you lose all advantages really.<p>It&#x27;s just hard to let&#x27;s say use different browsers for different things and from time to time you&#x27;ll use wrong one. Then problem is that most of applications around isn&#x27;t really designed to be used in separate VMs and things like file management get messy. So at some point you&#x27;ll just give up trying to keep it secure.<p>So I think actually secure OS is very far in future.
jstewartmobileover 8 years ago
Here&#x27;s what Theo de Raadt had to say about virtualization for security:<p>&quot;<i>x86 virtualization is about basically placing another nearly full kernel, full of new bugs, on top of a nasty x86 architecture which barely has correct page protection. Then running your operating system on the other side of this brand new pile of shit.</i>&quot;<p>&quot;<i>You are absolutely deluded, if not stupid, if you think that a worldwide collection of software engineers who can&#x27;t write operating systems or applications without security holes, can then turn around and suddenly write virtualization layers without security holes.</i>&quot;
rahrahrahover 8 years ago
I&#x27;d also be interest in hearing from experts about this. The concept seems very elegant, but plenty of elegant things are flawed...