My unofficial stance below. In my opinion, it doesn’t do justice to what Qubes does do for privacy, but that’s not the point of a question I think is mainly about priorities.
Security first, no other priority is on a similar level, and privacy is nowhere near - “security and privacy” is a clear no if we’re talking about priorities (outcomes could be a different matter, and more subjective anyway)
Privacy prioritized where convenient or demanded, or a specific threat is relevant/interesting to the team - strong historical record of this
Level of privacy won’t meet the expectations of users wanting every privacy characteristic or defense against every threat that privacy aficionados are currently talking about
“Reasonable” security doesn’t intentionally cover deep state actors, and there’s zero commitment to combating deep-state anti-privacy actors (same with Whonix, I think)
No real ambiguity about relative priorities in the docs/website (opinions may vary regarding the Donate page quote from OP), but I could describe some of the messaging about privacy as “bullish” (unusually for libre software), maybe attracting wishful thinking and over-optimistic expectations
Some elements of Qubes may make it outperform some alternative privacy-specific solutions on some privacy characteristics - i.e. it may achieve or facilitate good privacy outcomes despite these not being a primary focus
Qubes core team isn’t comprised of privacy experts, and this isn’t a problem
What I’d like to add, but am unclear/under-informed on, is whether Qubes keeps pace with industry practices on privacy
Is there anything else you think is needed to decide “security” vs “security and privacy” for you?
I’m going to leave the “which forum users are deep state?” and “should we restrict which arguments we make?” sides of this post to others.
Suppose you’re a detective investigating a crime. You’re trying to find out what happened, so you start interviewing witnesses. You won’t blindly trust what any one witness tells you, since they might be lying or misremembering. You also won’t trust any pair of witnesses, even if their stories match, since they could be in cahoots. But what if you get the same story from ten unrelated witnesses? Or a hundred? At some point, it becomes improbable that they’re all in cahoots or all misremembering in exactly the same way. The simplest explanation is that they’re reporting what they witnessed. A similar principle applies here.
Witnesses are not infrastructure nodes. There is no premise or assumption that the whole society is compromised and distrusted, so the principle is completely different.
Your post was flagged as inappropriate: the community feels it is offensive, abusive, to be hateful conduct or a violation of our community guidelines.
This post was hidden due to flags from the community, so please consider how you might revise your post to reflect their feedback. You can edit your post after 10 minutes, and it will be automatically unhidden.
9 minutes later, your reply to that already hidden post came.
I just thought I should tell you that because your reply quoted that same offensive, abusive, hateful content in full, so you may be unaware it is an unacceptable violation.
I am leaving now, as I am obviously mentally incapable to understand even my own posts. I wish you well. Sorry for the interruption.
I don’t understand what you don’t like in this excellent analogy. Nobody said the whole society was compromised or distrusted, just like not all witnesses are. You can’t trust any single source in both cases, since you can never know them well, but when many independent sources tell you the same thing, it’s the way to reliably verify the claim. How else are you going to verify anything at all? (As an alternative, I only see a meeting in person with the Qubes devs , which is impossible to arrange for everyone.)
What is wrong with the above verification approach? If you don’t like it, you should tell us precisesly, in which particular case it would betray you. I can’t imagine such case.
I can’t count the number of times I have seen users paint themselves in to
a corner with an untenable position, and then withdraw from the
lists/Forum, rather than continue the argument, acknowledging the error.
It’s a shame.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
Analogies do not necessarily have to be measured against criteria of strict commensurability. In this sense, a denial of ontological equivalence can hardly be understood as an argument if the analogy in question originally only served to illustrate a (partial) aspect.
One could recast @adw’s illustration as a Bayesian argument for establishing the basis of trust in a world where all information depends on untrusted sources. However, I much rather enjoyed the illustration, which is both more memorable and more eloquent than any rigorous argument from probabilities could have been.
Are you in the qubes team? I didn’t see your name in the list but maybe you have more than one alias? If you are in the team that makes it 2 team members who have said it’s security only (that’s my interpretation of what you said, explained below).
I think it’s important and useful to a more compact short statement, something that can fit inside a title and possibly with a sub-title. I’m not trying to put words in your mouth, this is just my attempt at doing that with what you’ve said:
Title: Qubes os is a security focused OS.
Sub-title: Privacy is a low priority.
That’s better than “security only” but I think it’s almost same thing.
So far this is the unofficial opinion but if more qubes team members share their opinion and finally the big boss lead project dev as well then we can have an official statement. Even if it is very sad for very many people to read “privacy is a low priority” on the homepage, I think it’s still best to be clear and upfront about it.
I wasn’t suggesting restrictions. I just help everyone how you can interpret posts based on if they are supporting arguments or arguing against. USA’s deep state should be seen as an enemy of qubes os because they don’t want the people to have security and privacy. They want backdoors and mass surveillance. So it’s very useful to be able to identify deep state users so we can avoid being manipulated by them. For example, the deep state is anti-privacy. So if a user is arguing against privacy then it’s more likely they are working for the deep state. But it’s of course important to take into account how often the user is arguing against privacy and the ratio between arguing against and supporting arguments.
Maybe qubist left out something in the email he received but from what he quoted it doesn’t seem clear what he said that was so “bad”. When I read his post before it was censored I didn’t see anything that I thought might get censored. My intention isn’t to defend qubist but how are we supposed to learn from our mistakes when we aren’t told explicitly which combination of words are against the rules. Because if we write several paragraphs then it can be hard to guess what part of it was the bad part.
Nothing here identifies me as one of the qubes team. I’m supportive of them having multiple and anonymous accounts.
My current opinion is that we’ve always had one and that it’s been clear. The main points of my posting at all here are to help people who don’t find it clear and to identify any recurring themes of people not finding it clear.
I don’t think there’s any need to get senior devs involved.
The main reason I didn’t say this is because I believe it’s not at all accurate. You’re quite welcome to rephrase me, but in practice, changing the meaning to this extent tends to undermine these discussions quickly.
Let’s imagine that I’m a new Qubes user. I want to get the genuine Qubes Master Signing Key (QMSK) so that I can authenticate my Qubes ISO (and the qubes-secpack, QSBs, canaries, documentation, and so on). What are my options?
I can download it from the official website, but the website might be compromised.
I can download it from various public keyservers, but they might all be compromised, and bad actors could have uploaded fake keys with the name “Qubes Master Signing Key.”
I can download it from GitHub, but GitHub might also be compromised.
I can get the fingerprint from old tweets, but X/Twitter might also be compromised.
Likewise, I can get the fingerprint from Mastodon, Reddit, LinkedIn, and Facebook, but those might all be compromised too, or they might be from fake accounts.
I could try to use the PGP Web of Trust, but I might not have any other keys I trust that link to the QMSK.
I could try to go to a conference or event where Qubes people are present and get the fingerprints from them, but maybe travel is prohibitive for me.
I could get the fingerprint from old mailing list and web forum posts, but the mailing list and web forum servers might be compromised.
I could ask people on mailing lists, web fora, social media, and chat rooms to post the fingerprint, but I might get replies only from bad actors and, again, the the servers could be compromised.
I could get the fingerprint from videos and slides from past Qubes talks and from photos of T-shirts, but those could all be faked.
I could get the fingerprints from the blogs and personal websites of people who have posted it.
I could do all of this via different Internet connections (home clearnet, work clearnet, home VPN, work VPN, home Tor, work Tor, public library, internet cafe, etc.).
I could do all of the above on different devices (home computer, work computer, smartphone, old laptop in the closet, public library computer, internet cafe computer, etc.) in case some of my devices are compromised.
I could ask friends and family to try all of these methods, then compare the fingerprints we each get (in case all of my devices are compromised).
But if I do all of these things (or even just a lot of them), and I get the same key/fingerprint enough times, then that’s strong evidence that the key is genuine. What are the odds that the Qubes website, all public keyservers, GitHub, Google, Communiteq, X/Twitter, Mastodon, Reddit, LinkedIn, Facebook, Qubes chat rooms, blogs/websites of users, other random technical web fora/mailing lists/chat rooms, and all the users who reply to me in all those places are all compromised (1) at the same time, (2) by a single entity, (3) whose goal is to feed me a fake QMSK? It’s questionable whether any single entity wields such capabilities, but even if such an entity exists, there are far more valuable targets on which to exercise its capabilities.
I still don’t understand where is QubesOS not privacy friendly.
Are we discussing the OS? Or are we discussing the forum and other Qubes owned websites?
That’s not my experience reading this forum posts. I think the community finds it unclear if qubes os is security only or security and privacy.
That’s why I think we need the qubes team to officially make it clear. Otherwise it will just be us unofficial users continuing the endless arguments about if qubes os is security only or security and privacy.
I really did think it sounded like you said privacy is a low priority. But if that’s not what you meant, then is privacy a high priority? It has to be either high or low. Can’t be none because then why do we have so good privacy features? Even this question defeats all the users who say qubes is only about security. If it was only about security then we wouldn’t have any privacy but we do have that.
I think, just like many others here do, that qubes os is security and privacy. It has very good privacy already thanks to qubes os being about both security and privacy. And we should keep improving both security and privacy.
Why do you repeatedly set up these binary oppositions. There are
many alternatives to “not low priority”, as is obvious.
From the start of this thread you have promoted a false opposition, and
repeatedly suggested things without any evidence. I simply don’t believe
that there are people who believe that Qubes is “security only”, as you
repeatedly claim, and that there are people who hold the opinion that
“qubes os should not be about security and privacy” - this is a fantasy
of your making.
You give some examples - e.g. that “anti-privacy people argue that tor
is not e2ee if you use whonix”. Where is this from? Who said it? In
what context?
You warn against arguing against the statement that .onion is both more
secure and better privacy than clearnet with tls. Who has argued
against this? Where?
Who is the team member who said Qubes is security only? Where did they
say this? In what context?
Insinuations and false attributions are hallmarks of deep state activity,
and are often used to undermine trust in a project, and spread confusion.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
While I’ve seen similar concerns to yours before on the forum, they don’t attract much supportive engagement. I estimate the fraction of users who find the matter unclear is tiny.
I can’t see anyone getting anywhere with this without a commitment to higher precision. Several people have tried engaging with your questions about whether Qubes “is” security/privacy either by adding clarifications or asking you to add them, and I think that’s the only viable approach for this topic, particularly when we’ve got deep state concerns flying around. I can’t promise you’ll get enough precision back from the Qubes team, but people will at least be able to see you’ve tried.
But I am not the one accusing any specific user, that’s what you are doing, not me. I have not accused anyone of being a deep state user and asking you all to trust me. I am teaching you all how to detect deep state users by yourself. I don’t understand why the concept of objectively categorizing a post as “arguing against” and “supporting argument” is so hard to understand. I’m beginning to think maybe I have a special talent when it comes to these kind of things. It’s like I’m giving you the open source tools to verify by yourself. I’m not pointing my finger at anyone. Unman, you are the one pointing your finger at me and also at yourself. Any stress you have is caused by yourself. Like the post you made earlier in this topic where you put words in my mouth and claimed I’m about to point my finger at you. I wasn’t going to do that.
Then say what the alternatives are if they are so obvious. Someone told me it’s important to be precise, oh it was you. Binary is about being precise. Are you just going to make me sit here and write lots of paragraphs trying to guess what those non-binary alternatives are?
You should be more clear and say it is your opinion it is false. Suggested what things? I think you are conveniently misunderstanding everything even thought I’ve tried several times to explain that one of my goals here is to teach you how to categorize a post as “arguing against” and “supporting argument”. I’m not here to point fingers at anyone. You seem obsessed about wanting me to point my finger at you, why? To derail the topic? Should we start a new topic and start analyzing all your posts? Is that what you want? We can call the topic “Analyzing Unman’s posts to determine if he is a deep state user”. It’s not what I want to do but it seems like you want that.
That’s not exactly what I said. And as usual you are conveniently leaving out the context and misunderstanding the point. I’m trying to teach how to categorize a post as “arguing against” vs “supporting argument”. I don’t know how many times I have to say that until its understood.
Against my better judgement I will allow you to lure me into quoting that post but I just want to be clear and say that I don’t think rustybird is an anti-privacy user just because of this post. I think it should take more than just one post before labeling them as anti-privacy. But it is interesting to think about why they would make such a post in a topic where we are suggesting upgrading the forum to use .onion for better security and privacy. It’s almost like they just had to think of some valid argument against it and didn’t want to show any support. But it’s still just one post so I won’t judge.
The whole topic is actually a great example: https://forum.qubes-os.org/t/tor-onion-service-security/33003/
Because it’s pretty much just 1 user (Alkenoi) who made a supporting argument. And Alzer was kind of neutral/supporting about it depending how you look at it. Pretty much everyone else didn’t show any real support to upgrade to .onion. It’s just “arguing against” all the time and showing no support. Hopefully everyone are now able to objectively categorize a post as “arguing against” and “supporting argument”. There’s not much point in me linking to lots of posts and topics if you don’t know the difference between arguing against and supporting argument. I’ve been trying to teach that in this topic.
Unman, I also find it tiring to answer your questions because in my experience you have a tendency to just look for that one little tiny mistake and then completely over react and say I’m a dishonest person who can’t be trusted and ignore everything else I say, no regard for the context or bigger points I’m making. I think the below post you made really tells a lot about you:
I made a mistake of mixing up the Snowden quotes that are on qubes os and whonix websites. I thought Snowden said “privacy and security” but I mixed the quotes up. Unman completely over reacts on that little mistake and attacks my character relentlessly.
And then the hypocrisy when he lies and says I’ve been talking about Elon musk but I’ve never even said his name before:
I’ve never talked about Musk and never said anything even close to that. He is blaming me of being dishonest over the small mixup I made where I mixed up the Snowden quotes that are on Whonix and Qubes OS websites. Then he follows that up with lies about me in the same post.
Yeah, as you can see, unman is so precise and truthful /s
Why is Unman attacking/arguing against me so much anyway? I never see any supportive arguments. Could it be that it’s because I’m a big advocate for privacy and freedom? That I want the forum to be upgraded to .onion? That I am exposing USA’s deep state mass surveillance? If you are someone who wants digital freedom and privacy and security and no backdoors, then you would probably like most of the posts I make and think positively about me and show support. But if you are against this, then I can understand you don’t like me and want to argue against me as much as possible.
And then another problem is it seems some posting histories are being cleaned up. Posts I’ve seen before are gone. I guess from now on I have to start taking screenshots of all posts and start making a huge database. It would be simpler if everyone could just learn how to categorize a post as “arguing against” vs “supporting argument”. Remember that I’m just one person with a small amount of time. And I don’t actually want to go pointing fingers at anyone, that’s why I also don’t save a database of quotes.
It’s not hard to understand the basic idea, though I’m finding it hard to find any merit in it, as I’ve already said. I think it’s safe to assume it’s being ignored, because people can decide for themselves whether it looks like a good idea, and you’ve offered no support for it other than appeals to common sense. This is one instance where “repeatedly suggested things without any evidence” does apply.
That happens sometimes, I think it’s fine for you to call it out, and sometimes requests for precision and clarity are indeed a bit of a double standard (not necessarily bad, since we have busy contributors trying to talk to newcomers analyzing forum histories here). Big leap from there to “hypocrisy” though. Bigger still to “deep state actor”.
I’ve seen unman engage with a number of posts in a similar way to yours, and from that I guess the precision/clarity/evidence angle is more of a theme than anything to do with anti-privacy, though there’s going to be some correlation there that’s nothing to do with unman.
Making such aggressive claims as “deep state” when you can hardly back it up can be hard to come back from, though - you might not see “attacks” but you may notice less positive engagement.
I’m sure there are more lightweight ways to do this, and yes, I usually expect that sort of evidence before beginning to consider anything like this. Mods do move things around in the interests of curation, and some other instances are expected - see this thread for example.
Suspecting them of being a deep state actor, fighting back against poor treatment, and believing they’re obstructing other/more/better contributions, as have all been suggested by @capsizebacklog at some point, would all be good reasons tbf. I think right now the problem’s only in attacking without robust support for what you’re claiming - the forum’s not exactly drowning in conspiracy theories yet.