I strongly agree that mainline Qubes should do this out of the box like some private channel releases based on Qubes already do.
Disposable qubes are for wimps. I’m going to download it and play it in a HVM of Windows.
Am I the only one getting the feeling that some will get excluded from the forum sooner or later?
It would be more productive to ask yourself if you will do something about that feeling or not.
Yes, of course! For example?
Take some time to think about it, I am confident you can produce a plan better and sooner than I can against my limited resources.
You are right. Too much dust for my brain cells, obviously.
This thread is not at all in line with the standards we hold the Qubes community up to.
Can we just take a step back and calm down?
All of the following are true:
Qubes is used by hackers and developers.
Qubes is used by people with little/no linux experience
Qubes is used by people who do not use CLI tools.
Qubes is used by people who want to customise their systems.
Qubes is used by people who do not want to customise their systems.
Qubes isnt for every one.
How is this so difficult to understand?
I work with many Qubes users - some of them want extensive modifications
to their Qubes systems. Some do not or are restricted in what they can
do. All of them use Qubes productively and benefit from it.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
I would argue - it is actually. But the wrong way it is presented to public (“only for hackers and blah blah”) is what turns back regular users from it. What would they say for film-noir trying to overcome Hayes Code: it’s not what you say, but how you say it.
Once the “Qubes-way” thinking is properly presented and adopted even in a short term, not to say longer, users deploying even default setup are put at rest thinking about security…
Who is it that presents it like this? It’s not Qubes, but commenters and
often forum users. I do not use Reddit but I’m told that it is full of
this nonsense.
But Qubes is not for everyone. Every user has different priorities
and requirements. And while Qubes is versatile, in some cases it does
not provide what the user wants. That’s fine.
I’ve rolled out Qubes in a number of organisations. Sometimes, after the
initial pilot, we agree that it’s not suitable across the board;
sometimes, not at all. This does not depend on their security posture.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
Saying it’s not for everyone is saying not everyone needs security.
No, it means that QubesOS is a security tool. Whether or not it can help you depends on your threat model.
Believing that simply installing any tool will provide safety is nothing more than superstition. You could use a “desktop firewall” with a nice lock or shield icon as well. Comfy feelings.
The official Qubes website and documentation have never stated this.
If you have information to the contrary, please share it with us here so it can be reviewed and updated. In lieu of something valid to point out, your tacit admission that the Qubes website and documentation have never stated this is accepted. Please make a sincere attempt to not post blatant disinformation, it’s very unfair to the development team and other users of the forum when that happens.
Similar experiences motivated myself and broader team to develop ui/ux that “abstracts” away the VMs. Users don’t use VMs/containers, they use apps. To make this happen we had to develop a storage model that would allow users to remain totally obvlivious to the qubes running those apps while preserving the compartmentalization model.
This interface to Qubes is something more that feels more like GrapheneOS (the only good Android distro) with its Storage Scopes that does work for “everyone”, even better so than any conventional GNU+Linux desktop out there.
The other pain point we see prominent on this forum is setting up VPNs/proxies, we solved this with a GUI that users who are not technical can understand and use to choose the desired network pathing.
I would argue what we have is far better than Windows or macOS because our system doesn’t actively fuck people/businesses over such as turning on cloud file sync or turning on AI agents without consent.
I am actively working to overcome some red tape to move to publish what we have done. In my opinion the codebase needs to be rewritten anyway, the main blocker right now is permission so to not be seen as violating some existing agreements.
I agree with the sentiment that some widely available iteration of Qubes should be for everyone. I know we can get there. Hopefully this will be the reality before 2027 hits.
YES.
I’ve been arguing this for years, and promoting exactly this
approach.
For most users, all the talk of templates/qubes//AppVMs is irrelevant.
They have little interest in the plumbing - only in what they can
do. This is why I promote KDE - it’s simple to get away from the
Template/AppVM model and provide “normal” menus that open applications
as needed in distinct qubes, and an interface that enhances the Qubes
model.
Users who have struggled with the template/AppVM model and worked
through it often think it is essential to understand it. It really is
not. With careful planning and setup it’s possible to provide the
benefits of Qubes isolation to users who know nothing of Xen, VMs,
qubes or the like.
Like you, I provide simplified VPN set-ups where needed. Again, the end
user need know nothing about Qubes networking, nftables, or the
like, to be able to use VPNs within Qubes.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
The Kicksecure, Whonix, and Qubes projects are made by hackers for hackers. Apparently you are not one of us.
YOU are the one misrepresenting Qubes as for hackers @de_dust2. I’m sick and tired of this schoolyard nonsense on a forum that’s supposed to be technical in nature. This isn’t the place for childish opinions about who should and shouldn’t be able to use Qubes, nor for ad hominem attacks. It’s a place to get and receive help, to distribute and acquire useful knowledge.
In other places, even in this topic if you sort out the nonsense, you’ve made valuable contributions. I don’t know why you also insist on attacking others and making trouble, as then those contributions are hidden or less likely to be listened to. This forum is a nice thing. I implore you, please keep it that way.
Qubes OS Live Mode:
Fully amnesia, fully isolation,
Hardened appVM (Kicksecure/Whonix VM),
Keystroke/mouse anonymization (Qubes Event Buffering),
Protection against time-attack (sdwdate in Kicksecure/Whonix VM),
Many distros
This guide combines the best practices from this topic Qubes in tmpfs. It offers two live‑mode options in a single convenient menu. The old topic’s founder and one of its main contributors are no longer active on forum. I created this guide so users don’t have to read through the entire topic of almost 100 comments looking for a final solution. I’ve been using this guide for four months. You will get two ways to launch dom0 in RAM for protection against forensics: dom0 in zram0 dom0 in ove…
Tails:
not isolation,
not hardened,
default debian only,
keystroke/mouse deanonymization,
susceptible to time-attacks
The purpose of your post is unclear, but good luck to you.
Keystroke/mouse anonymization (Qubes Event Buffering)
How did you achieve that? Or is part of kicksecure?
Users who have struggled with the template/AppVM model and worked
through it often think it is essential to understand it. It really is
not. With careful planning and setup it’s possible to provide the
benefits of Qubes isolation to users who know nothing of Xen, VMs,
qubes or the like.
Can you explain what it would it look like? How the end user will install an app then for example? Or is it the end user shouldn’t even be able to install apps?
Can you explain what it would it look like? How the end user will install an app then for example? Or is it the end user shouldn’t even be able to install apps?
All depends on the use case. Sometimes the requirement is that users not
be able to do this, but support is provided centrally to install apps or
provide packages that can be installed. Sometimes users are given this
right. Every deployment aims to have Qubes working within the existing
infrastructure and policies: possibly after improving the policies.
That is why it’s important to have clear requirements and a good test
phase before full deployment.
What does it look like? In the simplest cases, users have a menu based
on tasks, not on qubes; for most users, there’s no need for details of
qubes and templates to be available from the Menu. In some cases I have
tried to get the Menu as close as possible to what was used before. Some
training is needed in most cases, but after a good deployment support
calls are the same as with Windows or Mac.
People who have worked through Qubes install and set up often find this
difficult to understand. If you’ve struggled to understand templates,
qubes, and disposable, it’s hard to put that aside. Focussing on
user need and use, changes that perspective. Some people complain that
this is not empowering the users: that is true. But in these cases
the organisation does not want the users to be “empowered”, and they do
not need to be.