Hacker News new | ask | show | jobs
by mtgx 3499 days ago
You may find this talk between the Qubes, Subgraph and TAILS representatives helpful:

https://www.youtube.com/watch?v=Nol8kKoB-co

I believe Joanna from Qubes also set-up this forum for discussions on secure operating systems:

https://secure-os.org/

Joanna also talked a bit about the trade-offs between the two here:

https://secure-os.org/pipermail/desktops/2015-October/000002...

I believe initially there were some discussions to integrate Subgraph into Qubes as a TemplateVM (just like the Debian VM, Ubuntu VM, etc), but the Subgrapth guys thought Grsecurity wouldn't work well with Qubes OS. I think that situation has improved, and there is some progress in making Grsecurity work with TemplateVMs and AppVMs.

https://twitter.com/Phoul/status/801114260881424384

However, even if it does work, I'm not sure how excited the Subgraph guys are about making their OS "just" a Qubes OS TemplateVM. They may think that's the wrong business strategy for them as a company. I'm just saying this as someone watching from the outside. They may actually not believe that at all.

However, I did also notice the relationship between the two projects got a little colder, at least for a while, and in public, after Edward Snowden called Qubes his preferred secure OS.

3 comments

It was me, at Subgraph, that setup the Secure Desktops mailing list and website. We hope to collaborate more with other projects in the future. There is already interest from other projects in things we've built for Subgraph.

As for Subgraph in Qubes, being a template OS, etc, maybe later? We haven't even had a real release yet and are still building. I wouldn't recommend it anyways unless all of the Qubes VMs have hardened kernels by default.

Having a subgraph TemplateVM will get easier with Qubes 4.0, as Qubes switches over to HVM (I think just HVM with PV drivers, PVH in Xen is not ready yet). grsecurity and PaX do not work with paravirtualization, which is pretty limiting in terms of memory management and such (It also opens up some vulnerabilities, which is why Qubes is switching).
Thanks for the interesting stuff.

Even if Snowden called out Qubes, you have to decide on your own security level which system is best for your needs.