Hacker News new | past | comments | ask | show | jobs | submit login

If the apps work together, they typically belong to the same security domain / trust level. Do you have examples when you still have to isolate them from each other?





Even if things are on the same trust level that doesn't mean that if one gets compromised I don't care that it affects the 2nd.

So just run them in different VMs?

Apart from that, any hardening in Fedora can be utilized inside a Fedora VM on Qubes. Qubes doesn't force you to use VMs with no isolation inside.


But then the files can't be shared.

Qubes has such functionality.

And you just deduced why sandboxing as it is implemented today is really pointless for the desktop .

I'm using Qubes as my daily driver on my desktop, so no.

What do you get from it? Specially considering that from above "programs that work together go in the same context"..




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: