zlacker

[parent] [thread] 1 comments
1. freyrs+(OP)[view] [source] 2011-06-12 08:40:21
I'm not claiming they're going to be satisfied by this or that the technology even addresses any security problems. My point was that gaming in not a necessary feature or a selling point of Qubes and that the demographic who would a) know what this is and b) have a use for it in their business/research, is not going to use it based on it's ability to run Quake.
replies(1): >>rdl+d2
2. rdl+d2[view] [source] 2011-06-12 10:08:21
>>freyrs+(OP)
IMO, the real alternative to Qubes is running some kind of trusted windowing system/kvm switch/x display equivalent that doesn't suck, and then connecting to distinct remote hosts through some kind of security proxy, each running system-high security.

That protects you from hypervisor and hardware attacks. The only thing you need to trust is that none of the guests can induce the windowing system to incorrectly direct output, and that the windowing system can enforce access control (mandatory or discretionary) to the various guests.

The basic/extant version of this is putting a bunch of discrete devices in different security domains on serial ports, and then having a trusted console server to intermediate everything. A console server is vastly simpler than a full graphic windowing system like X Windows, much easier to audit, and more secure.

[go to top]