Suggestions for Qubes Architecture Diagram

So sys-usb to AppVM link should be red?

We didn’t discuss that in particular (but we did discuss the sys-net <-> sys-firewall. For that one even though the argument ā€œVM-interconnects are trustedā€, I think there is an associated risk of exposing that VM to a Bab USB, so I’d argue it should be red.

Another thing, I just noticed that bellow ā€œAppVM 1ā€ there should be label ā€œpersonalā€ (all other AppVMs have a label). But I don’t think it’s to important to justify another change (at least from my part).

I agree - AppVM1 just stands for any AppVM, it could also be ā€œworkā€ or even ā€œuntrustedā€ - but then we would again get into the colour discussion. For me, it’s just fine as it is!

1 Like