zlacker

[return to "Qubes OS: A reasonably secure operating system"]
1. kkfx+Nl[view] [source] 2022-03-23 11:45:26
>>RafelM+(OP)
Honestly It's not a "reasonably secure OS" but an "absurd OS", absurd because for safety we have since few decades a very lightweight and very effective solutions: Plan 9 namespaces.

Actual older than Plan 9 but still alive OSes have done limited and limiting choices but many have something "somewhat equivalent", for instance GNU/Linux cgroups (see FireJail, BubbleWrap etc) or FreeBSD Capsicum. Choosing anything heavyweight is a nonsense.

◧◩
2. AnIdio+Vw[view] [source] 2022-03-23 13:18:26
>>kkfx+Nl
Plan 9 was so far ahead of its time we still haven't caught up.
◧◩◪
3. gnufx+zM[view] [source] 2022-03-23 14:57:31
>>AnIdio+Vw
If you're talking about security, and regarding namespaces as a coarse-grained capability system, it was late to the game.
◧◩◪◨
4. edgyqu+9Q[view] [source] 2022-03-23 15:17:27
>>gnufx+zM
I think they mean the networking (everything is a file on the network.) This wasn’t adopted but Fuse etc have brought that functionality to Linux. If you really want to model plan9 on Linux there’s an app for that that runs atop Linux.
◧◩◪◨⬒
5. gnufx+bK1[view] [source] 2022-03-23 20:18:34
>>edgyqu+9Q
Heaven knows what someone conflating cgroups and namespaces means in connexion with Qubes. Anyway, if you want to know what I mean, read the paper "Security in Plan 9". "Linux" is irrelevant, and the various Plan 9 stuff-on-Unix efforts surely aren't going to improve the security of the OS.
◧◩◪◨⬒⬓
6. edgyqu+pS3[view] [source] 2022-03-24 15:12:27
>>gnufx+bK1
You are the one who mentioned security, not the other user. My point was I don’t think they were referring to security as Plan9s most famous features very much have made their way into every major OS out there.
[go to top]