Hacker News new | ask | show | jobs
by xelxebar 3064 days ago
The cloud stuff seems incidental to the article's main point. At least that's how I read it.

Rather, it sounds like they are trying to properly abstract the isolation technology away from any specific implementation. They then realized that this would also allow "Qubes on the Cloud" with relatively little extra effort.

From a personal choice standpoint, it seems we will still have the option of avoiding cloud zones completely if we so desire, so no harm there.

If we think about the sociology of security however, lowering the barrier to entry seems like an overall win, assuming we believe in the Qubes security model.

It's a lot like fingerprint readers on phones. Sure, they're not near as strong as a high entropy password, but they're convenient enough so people who previously never locked their phones now use a fingerprint lock.

1 comments

I agree. I liked the diagram that showed separate machines on the same local network running qubes. Physical separation is stronger compartmentalization than Xen.
Yes, I agree. And I wonder what a hybrid with Tinfoil Chat might look like. That is, using opto-isolators to make some device-qubes read-only.