问HN:在HN上,Qubes OS是否存在某种污名?
我发现Qubes OS(“一个相对安全的操作系统”)非常有趣。这不仅是作为一个信息技术的概念验证,展示如果从一开始设计得不同,信息技术可能会是什么样子,更是特别在当今第三方风险的背景下:如果你是开发者,可能会面临被攻击的包依赖;如果你接收并本地打开文件,可能会遇到文档中的恶意软件;如果你是任何人,可能会遭遇网络钓鱼;在浏览时可能会看到窃取隐私的广告,等等。
在我们的世界中,大多数个人电脑用户通常在一台机器上执行数十个完全独立的任务(游戏、发邮件、网上银行、视频流、无目的刷屏、在线购物、网页浏览,甚至可能工作),因此当前的攻击面非常庞大。因此,将这台单一机器转变为多个上下文独立的虚拟机,围绕一个精简的安全内核构建,一直以来都让我感到很有吸引力。
然而,在浏览Hacker News的帖子和评论时,我发现几乎没有关于Qubes OS或其愿景的讨论,即使在最近许多讨论数据泄露、被攻击的NPM包窃取API密钥、假招聘机构操控你安装远程访问木马(RAT)等问题的线程中,也很少提到。
我很好奇为什么会这样;在过去的13年里,Hacker News上的许多人肯定听说过Qubes。那么,为什么在网络安全及相关领域(事件响应、攻击、恶意软件分析、活动主义)之外,虚拟机隔离的使用,尤其是Qubes OS的使用,讨论得不够多,普及度也不高呢?
是否对团队或项目存在某种偏见?它的使用是否如此困难,以至于连Hacker News的技术爱好者都不愿尝试?
查看原文
I find Qubes OS ("A reasonably Secure Operating System") very interesting. Not only as a general proof of concept of what Information Tech <i>could</i> have looked like if designed otherwise from the start, but also -especially- in the context of today's third party risk: compromised package dependencies if you're a developer; malware in documents if you receive and open files locally; phishing if you're, well, anyone, privacy-stealing ads when browsing, and so on.<p>In our world where most PC owners typically perform dozens and dozens of completely independant tasks (gaming, emailing, banking, streaming, doom scrolling, online buying, web browsing, maybe working even) from a single machine, the current attack surface is enormous and, consequently, the benefits of turning that single machine into dozens of contextual yet independant VMs around a stripped down secure kernel have always appealed to me.<p>However, searching through HN posts and comments I can't find much (if any) discussion about Qubes OS or its vision, <i>even</i> in the numerous recent threads where people here lament constant data leaks, compromised NPM packages stealing API keys, fake hiring agencies that manipulate you into installing a RAT as part of the process, IA-generated video phishing, etc.<p>Curious to know more about why that is; surely in 13 years many on Hacker News have heard of Qubes. So why isn't usage of VM isolation in general and of Qubes OS in particular more discussed and more prevalent outside of cybersec and related fields (incident response, offense, malware analysis, activism).<p>Is there a particular bias against the team or the project? Is it so difficult to use not even HN technophiles even try?