zlacker

[parent] [thread] 2 comments
1. michae+(OP)[view] [source] 2023-07-26 02:17:21
None of the consumer facing resources need to be accessible via your vm in the cloud because that isn't how users get to Content/Banking/Shopping/School/resources/communication they do so on their desktop OS. There is zero reason 99.9% of use cases couldn't or would bother to block "insecure" environments and not also block VMs running in insecure environments.

> You may need to make KVM fake HyperV, though.

Not even techies are farting around with virtual machines and hoping their fake virtualization tricks don't break this weak when they have important things to do much less 99.999% of planet earth. They might however be willing to press one button that perceptively from the user standpoint switches their screen to a different desktop that happens to be running on a different machine. The interface to this feature would be simple enough they wouldn't have to care to understand it.

Users Mental Model: press button and "special" browser pops up full screen where I can bank/spend money. Press button again and it goes back whatever they were doing.

replies(1): >>jeroen+SW
2. jeroen+SW[view] [source] 2023-07-26 11:36:29
>>michae+(OP)
Virtual Windows machines with thin clients are used all over the world. Microsoft is even trying to make Window 11 an online-first platform according to news like https://www.theverge.com/2023/6/27/23775117/microsoft-window.... Some of these companies may run Windows on bare metal, but I doubt the majority of them doesn't do at least some server/workspace separation through VMs.

I know people want convenience. Anyone interested in convenience will just use Windows or macOS. They won't need to mess with VMs. This whole problem is only an issue for the small percentage of the population that wants to use their own weird operating systems, browsers, or addons.

If the need arises, someone will make a user friendly tool to do all this. Cassowary can do it today after following a step by step guide, they can also add their Web Integrity patches to those steps if they need to.

If you, as a user, want to have a special button that makes banking work without needing to know how or why, stick with proprietary operating systems. Linux isn't user friendly enough to accomplish this and it probably won't be for a while. The same is true if you want to watch your HD/4K streaming content without a huge struggle.

replies(1): >>michae+b48
◧◩
3. michae+b48[view] [source] [discussion] 2023-07-28 05:26:53
>>jeroen+SW
Why wouldn't the host and client be attested to be safe without letting arbitrary virtualization?
[go to top]