The question is by how much and whether it’s not by far outweighed by
the fact that you’ll probably do updates less often because it takes
much more time when you have 5+ templates to update (which may cause
security issues).
Also more complexity usually leads to more user errors…
In total it depends on what you install inside the template. The usual
client software is unlikely to make the attack surface much larger.
This is rather a different argument from your previous “what’s the risk
of having some more? You don’t execute them”. I dont see any reason to
suppose that people will update less often, and my experience suggests
that this is not so. I am an advocate of using a caching proxy, which
reduces the update load (time and bandwidth) of holding multiple
templates.
As the update mechanism is effectively click and run, it’s immaterial
how long it takes. Users can set it running and get on with productive
(or not) activities, checking back in to see the final result. They
arent blocked by the update process.
I’d argue that having multiple templates is actually less complex.
I have no idea what this means: on the obvious reading it is patently
false.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
1:1 and OS diversify. I would love to see more micro-kernels or Tiny-Core support. It is not so much a question of a Template being compromised for me. Qubes could be fantastic if every app had its own minimal kernel and was isolated that way. I don’t trust anything, so the only thing todo is remove as much as possible except for what is needed for each task, then isolate each task.
ps. atm, imo, 2 of the biggest ‘threats’ would be systemd and the monolithic linux kernel.
Do you have an actual study giving actual numbers on how much the risk
exposure increases? No?
Well, until then I’ll consider that number absurdly low as any
reasonable hacker can persist inside a VM with or without one additional
client software installed.
I never heard anyone saying “Oh, I exploited firefox. So now I’ll need
the thunderbird libraries to persist more easily.” That’s absurd.
Until numbers are presented all we’re talking is about belief and
security feeling, not about actual security.
Anyway it fits the current times.
1.25
generally speaking, I have a dedicated template for each appvm. “browser-based” vms just happen to share the same template such that the ratio increases.