yazomie

joined 2 months ago
[–] yazomie@lemmings.world 1 points 2 months ago (1 children)

Oh, good to know... In other words, sandboxing is not the best practice on Linux... So I'm better off with Qubes than with Secureblue

[–] yazomie@lemmings.world 1 points 2 months ago (3 children)

I could use gvisor inside distrobox inside an appVM in Qubes, couldn't I?

Many CVE's for Xen were discovered and patched by the Qubes folks, so that's a good thing...

As for OpenBSD, I thought I mentioned in the blog post that I'm intending to use it as sys-net VM inside Qubes if not as HVM alongside my Linux appVMs, for when I need Linux. The best of both worlds, so to say.

[–] yazomie@lemmings.world 1 points 2 months ago

Well, I'm not sure why they didn't include Secureblue qubes...

I don't do gaming or intensive development, so it's fine for me.

[–] yazomie@lemmings.world 0 points 2 months ago

Server-side API? I was talking about avoiding to get one's entire OS hijacked. The qube with the browser might get compromised, but dom0 would stay safely offline, that's my ideal, not the utopic notion of never possibly getting attacked and hacked.

As long as you don't explain what concepts am I mixing up, I don't see the respect, but as a random person on the Internet, feel free to troll, I'll move on.

[–] yazomie@lemmings.world 1 points 2 months ago

AppVMs are isolated in Qubes even without the help of Wayland

[–] yazomie@lemmings.world 3 points 2 months ago

Thanks, Ironclad and Gloire look interesting for a RISC-V system, gonna try out at some point alongside CheriBSD

[–] yazomie@lemmings.world 1 points 2 months ago (6 children)

I'm all for a better Flatpak, but I'm on the fence with full-on usage of Rust, I'd wait for there to be a second Rust compiler. Otherwise, sandboxing might be enough for some users, but not exactly for me.

[–] yazomie@lemmings.world 4 points 2 months ago (1 children)

I actually forgot to mention it, but I was going to say anyway that sandboxing I deem less ideal than paravirtualization

[–] yazomie@lemmings.world 4 points 2 months ago

GNOME is just the default, there's also KDE and no-GUI options if I'm not mistaken

[–] yazomie@lemmings.world 5 points 2 months ago (1 children)

Chimera is a nice alternative to Alpine, have you thought of sending this feedback to Chimera's dev?

[–] yazomie@lemmings.world 3 points 2 months ago (2 children)

It works decently with just 8 GB RAM, and I'm going to upgrade the RAM.

Secureblue is based on sandboxing rather than paravirtualization, and I'm not sure that's secure enough for me.

62
submitted 2 months ago* (last edited 2 months ago) by yazomie@lemmings.world to c/linux@lemmy.ml
 

TL;DR - About switching from Linux Mint to Qubes OS from among various other options that try to provide security out-of-the-box (also discussed: OpenBSD, SculptOS, Ghaf, GrapheneOS)

view more: next ›