ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Qubes Leverages Xen for Application Security on Linux

    News
    xen linux qubes fedora linuxinsider
    3
    8
    1.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • mlnewsM
      mlnews
      last edited by

      LinuxInsider takes a look at the Qubes Linux distro and how it leverages Xen to create VM containers for applications in order to increase security.

      1 Reply Last reply Reply Quote 2
      • stacksofplatesS
        stacksofplates
        last edited by

        It's interesting that they choose this approach vs something like an unprivileged LXC container.

        1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          LXC is not as secure.

          stacksofplatesS 1 Reply Last reply Reply Quote 0
          • stacksofplatesS
            stacksofplates @scottalanmiller
            last edited by

            @scottalanmiller said:

            LXC is not as secure.

            Unprivileged is from the host. I guess maybe not from container to container.

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @stacksofplates
              last edited by

              @johnhooks said:

              @scottalanmiller said:

              LXC is not as secure.

              Unprivileged is from the host. I guess maybe not from container to container.

              The separation in Xen is extreme, though. No kernel sharing even.

              stacksofplatesS 1 Reply Last reply Reply Quote 1
              • stacksofplatesS
                stacksofplates @scottalanmiller
                last edited by

                @scottalanmiller said:

                @johnhooks said:

                @scottalanmiller said:

                LXC is not as secure.

                Unprivileged is from the host. I guess maybe not from container to container.

                The separation in Xen is extreme, though. No kernel sharing even.

                True. With the unprivileged container you would have to find an exploit to allow a normal user to have system access though. Those containers are limited to the users home folder and at worst only what they could access anywhere else.

                How secure is running a DE in the Dom0 though?

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @stacksofplates
                  last edited by

                  @johnhooks said:

                  How secure is running a DE in the Dom0 though?

                  Are they running it there?

                  stacksofplatesS 1 Reply Last reply Reply Quote 0
                  • stacksofplatesS
                    stacksofplates @scottalanmiller
                    last edited by stacksofplates

                    @scottalanmiller said:

                    @johnhooks said:

                    How secure is running a DE in the Dom0 though?

                    Are they running it there?

                    Ya.

                    Dom0 is sort of a system domain separate from the default domains and any other domains you create. The desktop manager runs in this domain. Your login credentials reside there. Much like a super domain, Dom0 is more trusted than any other domain.

                    It provides just two functions: It runs the window manager and the desktop manager.

                    1 Reply Last reply Reply Quote 0
                    • 1 / 1
                    • First post
                      Last post