https://news.ycombinator.com/item?id=27897975
Yes, it would be ideal to have everything open and controllable. However you need to take into account the bitter reality and go step by step. Are you aware of any possibility of remote access with Intel ME? I'm not. See also: https://forum.qubes-os.org/t/intel-me-real-threat-for-ordina....
> Do you expect the people worried about an email to flash the BIOS with an clip connected to their Pi or Arduino they programmed first?
I did not do it myself and I don't expect that people will do it, too. I bought my Librem 15 as it is, and recommend to everyone. (It's not sold anymore, Librem 14 replaced it.) See also recommended computers: https://forum.qubes-os.org/t/community-recommended-computers.
> I bet your computer isn't a generic dual core that most people have.
It's actually dual-core i7-6500U.
> People like to play games
Sure. These people unfortunately are not the target audience of Qubes, unless they are ready to do GPU passthrough (which has been shown to work).
> not everyone has removable ram
So what? Do you suggest to give up? People who are aware of dangers of the Internet could choose their next machine to be compatible with Qubes and allowing more security and control.
> You said it has no GPU acceleration, which a lot of browsers use, so it wiil be much slower for most people.
Bloated websites are slow, almost independently on what machine you have. User-friendly websites work flawlessly for me. Youtube works fine.
> but these threats are not serious, if they were, you wouldn't need to convince anyone to use qubes.
Are you implying that every person knows everything about their threats and makes perfectly logical decisions? This is not a game with complete information: https://en.wikipedia.org/wiki/Complete_information. People need security even if they do not realize it yet (until their data is leaked, which happens very often nowadays).
> BSD servers that don't update or reboot for years wouldn't exist if there were actually any serious threats
I don't see the logic here. There are millions of hacked servers in the world used for spam and DDoS attacks. Where do you think they come from? (hint: not just from IoT devices)
> Windows has automatic updates, Linux has quick patching
Before it is patched, you are vulnerable. It's called a "zero-day vulnerability". And you are typically not aware of it when it happens. Also, vulnerabilities in browsers are also numerous and frequent.
> better to suggest it as a remote desktop that you can control with a thin client
I don't get it. You are going to connect to a "secure" server from an insecure machine with full access. Do you expect that your server stays secure after that?
You also did not mention that Qubes defends you from simply broken software which you sometimes have to install, which could make your system unstable.
> but on a laptop that you need 32GB of ram, that depletes battery life more
Are you aware that a lot of people today are using a laptop as their desktop home computer? I do.
Also, note that I'm not trying to literally sell anything. I'm just a happy Qubes user and I think that more people deserve better security for their computing.