Live data from Hacker News

When will we get secure desktop OSes? (2018)

games.greggman.com

41–50 of 102 posts

Re: When will we get secure desktop OSes? (2018)

#41

I don't understand the responses in this thread. Does nobody want an OS with a permissions system where you can reliably control access to resources? Or strong app sandboxing by default to keep chrome from sniffing your files (allegedly, this is virus scanning)? There isn't any loss of freedom with those as long as your super user can modify it all - its a gain of freedom in that you can have some control over what y…

Almost surely that will be coupled with an appstore and end the era of free computing for most people. It would be great if it didn't happen that way, but I don't see Apple or Microsoft doing it any other way.

Re: When will we get secure desktop OSes? (2018)

#42
I feel like Linux has the building blocks, it's the configuration necessary to take full advantage of them that is overwhelming.

When I used to use Windows there was also sandboxie which whilst probably wasn't perfectly secure was a good first point of call if you wanted to take a bit more care without firing up a whole VM - was especially interesting to see where apps would dump files as part of their installation process since they were operating in a clean directory tree

Re: When will we get secure desktop OSes? (2018)

#43
I find it hilarious the article is written by a Chrome developer.

Chrome is not a Windows store app. It could have been (MS edge was for years) but it's not. Store apps are substantially more secure than Win32 apps, at the cost of smaller API surface and less permissions.

Re: When will we get secure desktop OSes? (2018)

#44

This reads like fearmongering paranoia-propaganda for driving people towards the authoritarian centralised walled gardens... The problem is once you give an app perission then you never know when it's turning on the mic or the camera. The microphone and camera are unplugged when not in use. "secure"? No thanks, I'd rather sacrifice some security and keep my freedom. We're already losing the war against general-purpos…

> The microphone and camera are unplugged when not in use. Seems really inconvenient to have to physical unplug things when you're not using them. And in laptops and other integrated devices you can't unplug them.

but you can always put small physical switches anywhere in the device to turn them off by hardware.

Re: When will we get secure desktop OSes? (2018)

#45

Earlier quoted context omitted.

> The microphone and camera are unplugged when not in use. Seems really inconvenient to have to physical unplug things when you're not using them. And in laptops and other integrated devices you can't unplug them.

but you can always put small physical switches anywhere in the device to turn them off by hardware.

[deleted]

Re: When will we get secure desktop OSes? (2018)

#47
Qubes OS is perfectly usable if you are a technical person and describes itself as "reasonably secure" https://www.qubes-os.org/ . They take the security challenges of all the layers of the onion pretty seriously and have built a system that works well for many threat models. You do have to put up with some inconvenience (eg copying and pasting between vms etc) but you get a lot for that.

Re: When will we get secure desktop OSes? (2018)

#48

This reads like fearmongering paranoia-propaganda for driving people towards the authoritarian centralised walled gardens... The problem is once you give an app perission then you never know when it's turning on the mic or the camera. The microphone and camera are unplugged when not in use. "secure"? No thanks, I'd rather sacrifice some security and keep my freedom. We're already losing the war against general-purpos…

> The microphone and camera are unplugged when not in use. I guess you don't use any laptops than. > I'd rather sacrifice some security and keep my freedom. We're already losing the war against general-purpose computing. That's a false dichotomy. As a user you can give all the permissions you want to a sandboxed app you want to use. The only one losing freedom is the potential malware writer. If you are true to this…

I don't have to run everything as root. I just need the option to easily run something as root when I choose to. An option that is denied to me on those walled garden phone OSes.

Re: When will we get secure desktop OSes? (2018)

#49

This reads like fearmongering paranoia-propaganda for driving people towards the authoritarian centralised walled gardens... The problem is once you give an app perission then you never know when it's turning on the mic or the camera. The microphone and camera are unplugged when not in use. "secure"? No thanks, I'd rather sacrifice some security and keep my freedom. We're already losing the war against general-purpos…

> The microphone and camera are unplugged when not in use. Seems really inconvenient to have to physical unplug things when you're not using them. And in laptops and other integrated devices you can't unplug them.

> And in laptops and other integrated devices you can't unplug them.

This is why Purism makes laptops and phones with kill switches: https://puri.sm/security/

Re: When will we get secure desktop OSes? (2018)

#50

This reads like fearmongering paranoia-propaganda for driving people towards the authoritarian centralised walled gardens... The problem is once you give an app perission then you never know when it's turning on the mic or the camera. The microphone and camera are unplugged when not in use. "secure"? No thanks, I'd rather sacrifice some security and keep my freedom. We're already losing the war against general-purpos…

Like many here, I’m sure, I would love to be able to physically disable my camera and microphone somehow but do not have that option.

https://puri.sm/security/
Post reply on HN