问HN:在HN上,Qubes OS是否存在某种污名?

1作者: vntok大约 2 小时前原帖
我发现Qubes OS(“一个相对安全的操作系统”)非常有趣。这不仅是作为一个信息技术的概念验证,展示如果从一开始设计得不同,信息技术可能会是什么样子,更是特别在当今第三方风险的背景下:如果你是开发者,可能会面临被攻击的包依赖;如果你接收并本地打开文件,可能会遇到文档中的恶意软件;如果你是任何人,可能会遭遇网络钓鱼;在浏览时可能会看到窃取隐私的广告,等等。 在我们的世界中,大多数个人电脑用户通常在一台机器上执行数十个完全独立的任务(游戏、发邮件、网上银行、视频流、无目的刷屏、在线购物、网页浏览,甚至可能工作),因此当前的攻击面非常庞大。因此,将这台单一机器转变为多个上下文独立的虚拟机,围绕一个精简的安全内核构建,一直以来都让我感到很有吸引力。 然而,在浏览Hacker News的帖子和评论时,我发现几乎没有关于Qubes OS或其愿景的讨论,即使在最近许多讨论数据泄露、被攻击的NPM包窃取API密钥、假招聘机构操控你安装远程访问木马(RAT)等问题的线程中,也很少提到。 我很好奇为什么会这样;在过去的13年里,Hacker News上的许多人肯定听说过Qubes。那么,为什么在网络安全及相关领域(事件响应、攻击、恶意软件分析、活动主义)之外,虚拟机隔离的使用,尤其是Qubes OS的使用,讨论得不够多,普及度也不高呢? 是否对团队或项目存在某种偏见?它的使用是否如此困难,以至于连Hacker News的技术爱好者都不愿尝试?
查看原文
I find Qubes OS (&quot;A reasonably Secure Operating System&quot;) very interesting. Not only as a general proof of concept of what Information Tech <i>could</i> have looked like if designed otherwise from the start, but also -especially- in the context of today&#x27;s third party risk: compromised package dependencies if you&#x27;re a developer; malware in documents if you receive and open files locally; phishing if you&#x27;re, well, anyone, privacy-stealing ads when browsing, and so on.<p>In our world where most PC owners typically perform dozens and dozens of completely independant tasks (gaming, emailing, banking, streaming, doom scrolling, online buying, web browsing, maybe working even) from a single machine, the current attack surface is enormous and, consequently, the benefits of turning that single machine into dozens of contextual yet independant VMs around a stripped down secure kernel have always appealed to me.<p>However, searching through HN posts and comments I can&#x27;t find much (if any) discussion about Qubes OS or its vision, <i>even</i> in the numerous recent threads where people here lament constant data leaks, compromised NPM packages stealing API keys, fake hiring agencies that manipulate you into installing a RAT as part of the process, IA-generated video phishing, etc.<p>Curious to know more about why that is; surely in 13 years many on Hacker News have heard of Qubes. So why isn&#x27;t usage of VM isolation in general and of Qubes OS in particular more discussed and more prevalent outside of cybersec and related fields (incident response, offense, malware analysis, activism).<p>Is there a particular bias against the team or the project? Is it so difficult to use not even HN technophiles even try?