QubesOS 3.2 - A reasonably secure operating system [Paranoid? Read this!]

in #qubesos8 years ago (edited)

View this post on Hive: QubesOS 3.2 - A reasonably secure operating system [Paranoid? Read this!]


Neither Steem, Steemit or Steemit INC can be trusted. Research the #SteemHostileTakeover , and come join everyone else on #Hive .

Sort:  

I have seen it but I been using Linux for mad years so am a stick with centOS Ubuntu and Debian

Fair enough but i mostly use centos and debian for my base templates anyway.. Centos for stability , debian for experimentation

Looks interesting, but I'll probably stick with Ubuntu for now. I realise there are potential issues, but I'm fairly careful. I'll see if I can find time to look at it though. Perhaps someone can package it in an easier to use form.

I do worry about web security. It only takes one browser vulnerability to expose you. I guess I could run the browser in a VM to be more secure.

Found this piece on VMs https://theintercept.com/2015/09/16/getting-hacked-doesnt-bad/

I may at least set up a VM for some of my browsing. It's all useful experience.

Great article :)

Ubuntu does alright, and its infinitely better then windows 10 in terms of security & privacy out of the box :)
Not a big fan of canonical though, and I have some fears about the future directions they could take it, but for now I still recommend it because it usually just works..

Web security is the main way most people get infected, but even just running the browser inside virtualbox would be a massive upgrade over the average setup :)

On that topic, I also use ublock origin in my firefox installs to stop random javascript on every site, and I manually approve each one for my "trusted" browser.

I also have some untrusted disposable browsers, running everything like flash and java applets and pushing traffic via Burp proxy so I can intercept traffic whenever I want - tis nice having the option always available :)

I need to have a look at ublock origin. I use Adblock, but I know that's not perfect. I do allow ads on some sites I want to support, but I hear about malicious code in some ads. I used to run NoScript, but that could be a pain at times. It's amazing how much code some sites run.

I swapped from adblock to ublock because it seems to have some extra features and less memory usage :)

I noticed even my banks website loads dozens of external js files and facebook/twitter etc..

This is frickin brilliant, pardon my french. I am going to spin this up on my fitlet. I always run with encrypted drives and i like the idea of isolating my apps a lot more strongly, in particular, since steem is also my wallet, it should not be mingled with potential drive-by hijacks and the like.

I'm not happy with the current state of anti-surveillance network systems like tor and bitmessage. I intend to work on some new systems that will enable these services to be more monetisable, while retaining security, because I think that, and you can even find a post from me over 7 years ago on the tor email list, about how tor's lack of agorist payment systems is keeping the network small and vulnerable.

I want to check out this OS because I also have visions of a complete security network system, including the OS software distribution platform within the network, something like Tor and Maidsafe but that is designed so you can stay within the safety of the network and not so much be using it to get out at all. Integrating blockchain type systems for various types of communication, indeed, an entire internet that is inside the secure network, with secure distributed data-loss resistant filesystems, etc. It's a big project, and what I am doing now is all about getting the startup capital together so that I can finally start working on it (It's been in my mind almost 4 years now). So, this looks like a good design for the software base for my system design.

Nice im glad you saw this :) It really is worth the effort and im sure you'll love it once you get to explore how they've seperated everything.. I cant imagine changing os again :)

Best of luck with the fundraising

Sadly, it did not want to boot on my fitlet (amd a10 SoC). So I reinstated my old ubuntu install with encrypted swap and home. But I'm looking forward to getting this and its' 3.2 iso is living on my home filesystem for now. I might put it on my laptop when I get a stack of DVDs to burn a copy.

Damn, its a bit fussy about cpu unfortunately hopefully itll run on the lappy

Yes, after I've shifted my data around I'm going to try that. Should work fine on a core 2 duo.

Snowden Edward Snowden tweeted @ 29 Sep 2016 - 13:59 UTC

If you're serious about security, @QubesOS is the best OS available today. It's what I use, and free. Nobody does V… twitter.com/i/web/status/7…

Disclaimer: I am just a bot trying to be helpful.