Ask HN: 在 Hacker News 上,大家对 Qubes OS 有什么偏见吗?

1作者: vntok4 个月前
我觉得 Qubes OS(“一个相当安全的操作系统”)非常有趣。这不仅因为它是一个关于信息技术如果从一开始就以不同方式设计会是什么样子的概念验证,而且——尤其是在当今第三方风险的背景下:如果你是开发者,软件包依赖项被入侵;如果你在本地接收并打开文件,文件中存在恶意软件;如果你是任何人,都可能遭遇钓鱼攻击;浏览时出现窃取隐私的广告,等等。 在我们的世界里,大多数电脑用户通常会从一台机器上执行数十个完全独立的任务(游戏、电子邮件、银行业务、流媒体、无脑刷屏、在线购物、网页浏览,甚至可能工作),当前的攻击面非常大,因此,将这台机器变成围绕一个精简的安全内核的数十个上下文相关但独立的虚拟机,其好处一直吸引着我。 然而,在 Hacker News 的帖子和评论中搜索时,我找不到太多(如果有的话)关于 Qubes OS 或其愿景的讨论,即使在最近的许多帖子中,人们在这里抱怨持续的数据泄露、窃取 API 密钥的被入侵的 NPM 软件包、诱骗你安装 RAT 作为流程一部分的虚假招聘机构、AI 生成的视频钓鱼等等。 很好奇为什么会这样;当然,在 13 年的时间里,Hacker News 上的许多人都听说过 Qubes。那么,为什么虚拟机隔离,特别是 Qubes OS 的使用,在网络安全及相关领域(事件响应、攻击、恶意软件分析、行动主义)之外没有得到更多的讨论和更广泛的应用呢? 是否存在对团队或项目的特定偏见?它是否难以使用,以至于即使是 HN 技术爱好者也不愿意尝试?
查看原文
I find Qubes OS (&quot;A reasonably Secure Operating System&quot;) very interesting. Not only as a general proof of concept of what Information Tech <i>could</i> have looked like if designed otherwise from the start, but also -especially- in the context of today&#x27;s third party risk: compromised package dependencies if you&#x27;re a developer; malware in documents if you receive and open files locally; phishing if you&#x27;re, well, anyone, privacy-stealing ads when browsing, and so on.<p>In our world where most PC owners typically perform dozens and dozens of completely independant tasks (gaming, emailing, banking, streaming, doom scrolling, online buying, web browsing, maybe working even) from a single machine, the current attack surface is enormous and, consequently, the benefits of turning that single machine into dozens of contextual yet independant VMs around a stripped down secure kernel have always appealed to me.<p>However, searching through HN posts and comments I can&#x27;t find much (if any) discussion about Qubes OS or its vision, <i>even</i> in the numerous recent threads where people here lament constant data leaks, compromised NPM packages stealing API keys, fake hiring agencies that manipulate you into installing a RAT as part of the process, IA-generated video phishing, etc.<p>Curious to know more about why that is; surely in 13 years many on Hacker News have heard of Qubes. So why isn&#x27;t usage of VM isolation in general and of Qubes OS in particular more discussed and more prevalent outside of cybersec and related fields (incident response, offense, malware analysis, activism).<p>Is there a particular bias against the team or the project? Is it so difficult to use not even HN technophiles even try?