Real threat of installing software in dom0?

@balko When you say that it’s OK to install something in dom0, you should indeed mention that it’s not really OK for everyone, but only if the user knows what they are doing.

The whole deal with (not) installing additional software in dom0 is about trusted computing base. Qubes provides security through compartmentalization, i.e, your TCB must be as small as reasonably possible. The Qubes team is trying to remove most things from dom0: audio, handling of USB devices, GUI and so on. This is the Qubes way. For advanced users, it’s even recommended to use minimal templates, which have less code – despite the fact that you still can install something in them quickly. For this reason you should avoid installing anything in dom0, unless you know what you are doing.

It would be interesting to see a comment from @unman about possible security implications of installing KDE. This is more or less the reason why I’m not using KDE and stick to xfce, which has less code.

See also:

5 Likes