I think this OS deserves more attention. By the way, new version 4.1 is out: https://www.qubes-os.org/news/2022/02/04/qubes-4-1-0/.
I think this OS deserves more attention. By the way, new version 4.1 is out: https://www.qubes-os.org/news/2022/02/04/qubes-4-1-0/.
Seems like one of the least interesting aspects of qubes. Was there a zero day in the font renderer? I would assume such a thing would be more about homograph attacks.
As far as I'm concerned, freetype is another spelling for CVE. There have been multiple high impact vulns. Though it usually seems to require crafted fonts, so I wouldn't be too concerned about window titles using system fonts. Web fonts on the other hand.. disable 'em.
Ah, the elusive quadruple-negative.
I didn't even notice the unicode thing. But it doesn't surprise me. They have various similar conservative features. For instance, by default an app in a VM cannot get full screen access. To full-screen a video in youtube you have to full-screen in app and then hit Alt-F11. The concern is that the app somehow tricks the user into thinking that they're interacting with the host OS desktop. Also the host OS doesn't have Internet access; update package files are downloaded by another VM and copied over.
It's fairly paranoid by design, and their tagline is "a reasonably secure operating system".
Qubes runs Debian in a VM and isolates it to defend the user from threats.