Why Use Minimal Templates?

This is how I look on this. My idea is better something not to work, but to work with security omissions.

So, “learning basics” and “gradually reaching minimals” might be too late - system already compromised. I studied Qubes at least 3 years and sketched my qubes organization that reflected my threat model, before I installed it, and the very first install that ever happened was with all minimals (templates based on them) as defaults. I even waited for PVH, early 4.1 alphas because of hardware security.

Did everything worked out of the box? Nope. Almost nothing. But once it worked it was based on minimal. So I started from building sys-net’s minimal template and sys-firewall’s and didn’t go online from Qubes machine until I built them, sys-whonix is alreday there, and just created whonix-dvm-template which is not minimal by its nature, so got Tor Browser. Once I had that chain, I got access to online resources about how to bulid all other templates based on minimal.

So, I would actually encourage people first to read a lot about Qubes, then about minimals, then to install Qubes for the first time and build up templates with minimals. That is why we have things like this, for example

This is excellent guide what, and more importantly, how to test.

Any user can ask me which packages to install for a specific minimal template. I have my notes about each and everyone of them. For the needs I don’t have in my threat model, the user can open a topic with a specific subject.

For example:

Firefox-minimal

firefox qubes-core-agent-networking qubes-split-browser-disp mozilla-ublock-origin mozilla-https-everywhere mozilla-noscript pulseaudio pulseaudio-qubes qubes-audio-daemon tinyproxy --allowerasing

Even all of those aren’t needed, but they are pretty self-explanatory, so even novice can decide which to omit.

2 Likes