Suggestions for Qubes Architecture Diagram

So sys-usb to AppVM link should be red?

We didnā€™t discuss that in particular (but we did discuss the sys-net <-> sys-firewall. For that one even though the argument ā€œVM-interconnects are trustedā€, I think there is an associated risk of exposing that VM to a Bab USB, so Iā€™d argue it should be red.

Another thing, I just noticed that bellow ā€œAppVM 1ā€ there should be label ā€œpersonalā€ (all other AppVMs have a label). But I donā€™t think itā€™s to important to justify another change (at least from my part).

I agree - AppVM1 just stands for any AppVM, it could also be ā€œworkā€ or even ā€œuntrustedā€ - but then we would again get into the colour discussion. For me, itā€™s just fine as it is!

1 Like