Live data from Hacker News

PureOS: Freedom, Privacy, and Security

lwn.net

41–50 of 51 posts

Re: PureOS: Freedom, Privacy, and Security

#41
post #37

Personally I think QubeOS is probably the best option in terms of Privacy and Security at this stage. If your hardware can handle it (16GB RAM would be best). I would seriously consider QubeOS over PureOS if privacy and security are your concerns. It works pretty well and I've been using it for a while now on not so recent hardware without much issues. Their compartmentalization and seamless virtualization is just am…

What is the response of QubeOS to the famous Theo de Radt critique[1] that virtualisation is basically adding another layer (hypervisor) of possible exploits just below the existing one (kernel)? [1]: https://news.ycombinator.com/item?id=8393940

[deleted]

Re: PureOS: Freedom, Privacy, and Security

#42
This is nice and all and I am being 'that guy' nit picking but I hate the use of 'OS' when this is actually a Linux distribution. It is really confusing as in some cases an 'xxxOS' really is a new OS but more so these days it means 'xxx Linux distribution'.

Also given their links to fsf who insist on 'GNU/linux' it is amusing to see the name contain neither GNU nor Linux.

As a huge Linux fanboy (I contribute to the kernel minorly as a hobby) I can also see the positive side - using Linux is such a foregone conclusion that we don't even need to mention it any more :)

Re: PureOS: Freedom, Privacy, and Security

#43
post #37

Personally I think QubeOS is probably the best option in terms of Privacy and Security at this stage. If your hardware can handle it (16GB RAM would be best). I would seriously consider QubeOS over PureOS if privacy and security are your concerns. It works pretty well and I've been using it for a while now on not so recent hardware without much issues. Their compartmentalization and seamless virtualization is just am…

What is the response of QubeOS to the famous Theo de Radt critique[1] that virtualisation is basically adding another layer (hypervisor) of possible exploits just below the existing one (kernel)? [1]: https://news.ycombinator.com/item?id=8393940

Rutkowska wrote various posts about it. She does not answer your question directly and precisely, but provides considerations that make clear why she considers Qubes' approach an improvement over the status quo.

On Formally Verified Microkernels (and on attacking them) - https://blog.invisiblethings.org/2010/05/03/on-formally-veri...

The Linux Security Circus: On GUI isolation - https://blog.invisiblethings.org/2011/04/23/linux-security-c...

I think she had other posts on another blog as well, but unfortunately I don't remember the address. And I don't know if it still exists.

Re: PureOS: Freedom, Privacy, and Security

#44
post #37

Personally I think QubeOS is probably the best option in terms of Privacy and Security at this stage. If your hardware can handle it (16GB RAM would be best). I would seriously consider QubeOS over PureOS if privacy and security are your concerns. It works pretty well and I've been using it for a while now on not so recent hardware without much issues. Their compartmentalization and seamless virtualization is just am…

What is the response of QubeOS to the famous Theo de Radt critique[1] that virtualisation is basically adding another layer (hypervisor) of possible exploits just below the existing one (kernel)? [1]: https://news.ycombinator.com/item?id=8393940

What is Theo de Raadt's model with regards to X11 security on OpenBSD? Does it work out of the box?

Re: PureOS: Freedom, Privacy, and Security

#45
I’m a big fan of Linux, and I’ve been thinking and wanting to go full Linux for a while, but there just doesn’t seem to be a single laptop in existence that only runs free software. Every thread I read just turns into an infinite rabbit hole.

Re: PureOS: Freedom, Privacy, and Security

#46
post #38

Earlier quoted context omitted.

From the above link: What about safe languages and formally verified microkernels? In short: these are non-realistic solutions today. We discuss this in further depth in our Architecture Specification document: https://www.qubes-os.org/attachment/wiki/QubesArchitecture/a... .

Interestingly enough they only mention it being unreasonable for x86, it would be interesting to see SEL4 supported for ARM (of which SEL4 already has a verified kernel for).

The paper discusses more fundamental issues than just x86 architecture:

* Usermode drivers need to be formally verified to prevent malicious DMA. Adding IOMMU/SMMU to the microkernel will complicate the current proofs.

* All user processes that manage resources, like filesystem, network and memory management, must also be formally verified. These are currently unproven.

Re: PureOS: Freedom, Privacy, and Security

#47
post #36
post #33

Earlier quoted context omitted.

Qubes is fantastic but as a PSA the hypervisor's kernel doesn't support newer GPUs such as AMD rx5000 (AFAIK rx580 is the newest supported one). Learned this the hard way. Qubes 4.1 will bring the support, once it's complete https://github.com/QubesOS/qubes-issues/milestone/20

Any notes on the VM integration in general? Been looking forward to a "Windows subsystem for Linux" style thing where I can run Visual studio and games without actually having to deal with Windows as a primary OS =P

Proton - Valve's branch of Wine is probably your best option for running Windows games on Linux right now. That is of course unless you also want all the security that comes with Qubes. If you want to use a VM, VMware had a reasonably well working implementation of 3D acceleration when I last tried it 4 or 5 years ago.

Re: PureOS: Freedom, Privacy, and Security

#48
post #44
post #37

Earlier quoted context omitted.

What is the response of QubeOS to the famous Theo de Radt critique[1] that virtualisation is basically adding another layer (hypervisor) of possible exploits just below the existing one (kernel)? [1]: https://news.ycombinator.com/item?id=8393940

What is Theo de Raadt's model with regards to X11 security on OpenBSD? Does it work out of the box?

OpenBSD doesn't do GUI isolation. xinput grabs all. But file system is limited (unveil) and what apps can do (pledge)

Re: PureOS: Freedom, Privacy, and Security

#49

Earlier quoted context omitted.

I feel like I must be misreading something, because your second paragraph appears to me to be the doublespeak you claim to dislike. The problem with "free software" fundamentalists is they care more about the freedom of the software than the freedom of the user. Part of free choice from a user perspective is the freedom to run proprietary blobs. Also when it comes to freedom to run or not run proprietary software the…

> The problem with "free software" fundamentalists is they care more about the freedom of the software than the freedom of the user. Part of free choice from a user perspective is the freedom to run proprietary blobs. No one is removing the freedom to use blobs. You can use them on PureOS, too (and I did). The difference is you will not run into proprietary software by mistake (which is possible on Debian). > Also wh…

The labelling should be improved to educate the user more. That's it.

What you're discussing is really the level of convenience, and what that does to influence user behavior.

Re: PureOS: Freedom, Privacy, and Security

#50
post #45

I’m a big fan of Linux, and I’ve been thinking and wanting to go full Linux for a while, but there just doesn’t seem to be a single laptop in existence that only runs free software. Every thread I read just turns into an infinite rabbit hole.

It's probably not as bad as it appears. I currently have a Lenovo ThinkPad running Ubuntu with no problems, and it is not the first laptop I've run Linux on. Honestly, if you are not using bleeding edge or obscure hardware, you are probably ok. The only time I've had hardware problems with Linux in the last 10 years was a video card (on desktop) that could not initially output audio over HDMI. After a few months, the driver was updated, and all was fine.
Post reply on HN