Live data from Hacker News

New user guide: How to organize your qubes

qubes-os.org

1–10 of 16 posts

Re: New user guide: How to organize your qubes

#5
The secure copy and paste feature always seemed to address the wrong threat model or use case for me. Sure, it's great that it keeps things isolated and compartmentalized across VMs, but it doesn't help much if you accidentally paste it into a phishing site. I wish there was just better browser integration for it, so you could have a password manager that could only access secrets on-demand + also automatically verify the domain or site you're trying to enter credentials into.

Anyway, still very cool stuff. I used Qubes for a few years before I made the mistake of purchasing a laptop that wasn't fully supported, but I often think about picking it back up or trying to install it again.

Re: New user guide: How to organize your qubes

#6
post #3

How is the performance if you run like 5 VMs incl. a Windows one?

I have not run a Windows VM in Qubes, and I've been using it full time for only about a week now, but: performance has not been an issue with up to at least 8. This is with an NVMe drive, Ryzen 5600G, and 32GB of RAM.

Usability, however, is a bit wonky, but that's the trade-off for security. I'm sure my relative inexperience with it is at play there, as well.

Re: New user guide: How to organize your qubes

#7

The secure copy and paste feature always seemed to address the wrong threat model or use case for me. Sure, it's great that it keeps things isolated and compartmentalized across VMs, but it doesn't help much if you accidentally paste it into a phishing site. I wish there was just better browser integration for it, so you could have a password manager that could only access secrets on-demand + also automatically verif…

In practice, the Qubes C/P thing isn't unpleasant. There's also no reason browser integration can't be done right now; I use it with Qubes.

I have a primary 'vault' qube that holds all the credentials for all qubes, and then use Firefox's built-in password management on a per-qube basis. There is an initial 'config' step where I'll need to pass credentials from the Vault qube to an App qube, but after that it's smooth+automated.

Alternatively, you could use a vault-per-qube model.

Re: New user guide: How to organize your qubes

#8
This is nice but misses one vital step IMO: Do your basic web surfing in a disposable VM.

The article mentions using a disposable VM to view email attachments but considering how much malware is delivered through the web I like to keep my web activity highly comparmentalized by default. The trick is to configure the browser and set your bookmarks etc first in the disposable app vm template. You can even have some accounts pre logged in, ideally using Firefox's container tab system for extra security.

For a more advanced setup: I have one dispvm template for general web surfing and another for my social activity, with container tabs and live logins for various social platforms, and then a third dispvm template where I'm logged in to some things I care more about like Google Docs. Then all my really sensitive stuff is in a fourth, non disposable vm where I only use it for things like bank, mutual fund, 401k, credit cards, etc (all in container tabs for extra security). No web surfing ever in that vm.

Post reply on HN