yazomie

joined 1 month ago
[–] yazomie@lemmings.world 1 points 1 month ago (1 children)

Oh, good to know... In other words, sandboxing is not the best practice on Linux... So I'm better off with Qubes than with Secureblue

[–] yazomie@lemmings.world 1 points 1 month ago (3 children)

I could use gvisor inside distrobox inside an appVM in Qubes, couldn't I?

Many CVE's for Xen were discovered and patched by the Qubes folks, so that's a good thing...

As for OpenBSD, I thought I mentioned in the blog post that I'm intending to use it as sys-net VM inside Qubes if not as HVM alongside my Linux appVMs, for when I need Linux. The best of both worlds, so to say.

[–] yazomie@lemmings.world 1 points 1 month ago

Well, I'm not sure why they didn't include Secureblue qubes...

I don't do gaming or intensive development, so it's fine for me.

[–] yazomie@lemmings.world 0 points 1 month ago

Server-side API? I was talking about avoiding to get one's entire OS hijacked. The qube with the browser might get compromised, but dom0 would stay safely offline, that's my ideal, not the utopic notion of never possibly getting attacked and hacked.

As long as you don't explain what concepts am I mixing up, I don't see the respect, but as a random person on the Internet, feel free to troll, I'll move on.

[–] yazomie@lemmings.world 1 points 1 month ago

AppVMs are isolated in Qubes even without the help of Wayland

[–] yazomie@lemmings.world 3 points 1 month ago

Thanks, Ironclad and Gloire look interesting for a RISC-V system, gonna try out at some point alongside CheriBSD

[–] yazomie@lemmings.world 1 points 1 month ago (6 children)

I'm all for a better Flatpak, but I'm on the fence with full-on usage of Rust, I'd wait for there to be a second Rust compiler. Otherwise, sandboxing might be enough for some users, but not exactly for me.

[–] yazomie@lemmings.world 4 points 1 month ago (1 children)

I actually forgot to mention it, but I was going to say anyway that sandboxing I deem less ideal than paravirtualization

[–] yazomie@lemmings.world 4 points 1 month ago

GNOME is just the default, there's also KDE and no-GUI options if I'm not mistaken

[–] yazomie@lemmings.world 5 points 1 month ago (1 children)

Chimera is a nice alternative to Alpine, have you thought of sending this feedback to Chimera's dev?

[–] yazomie@lemmings.world 3 points 1 month ago (2 children)

It works decently with just 8 GB RAM, and I'm going to upgrade the RAM.

Secureblue is based on sandboxing rather than paravirtualization, and I'm not sure that's secure enough for me.

62
submitted 1 month ago* (last edited 1 month ago) by yazomie@lemmings.world to c/linux@lemmy.ml
 

TL;DR - About switching from Linux Mint to Qubes OS from among various other options that try to provide security out-of-the-box (also discussed: OpenBSD, SculptOS, Ghaf, GrapheneOS)

view more: next ›