A modest update to Qubes OS
lwn.net
lwn.net
The gnome desktop will be important for adoption. XCFE looks ugly in comparison. Equally important is the ease of installation, hardware support, documentation for the bios settings, etc.
Also:
>Another interesting change with this release the use of Xfce editions for Fedora and Debian instead of GNOME to reduce memory usage and provide a better selection of default applications. Marek Marczykowski-Górecki said that Fedora's GNOME template has too many ""problematic"" packages that ""either conflict with something or simply don't work with our GUI agent"".
I prefer Xfce FWIW.
Plenty of us consider both. Qubes is the only game in town, and also competing with macOS 14 and Windows 11. These systems look good and are quite usable out of the box.
The take-it-or-leave-it attitude popular with some community members doesn't help much with retention either.
I already know the Qubes-specific bits (templates etc). I don't want to have to put a lot of work into set up just to make it usable visually.
I left Qubes as a daily driver because I could never get watching videos to be a pleasant experience. I believe this is due to the lack of GPU acceleration.
For the modest amount of developer resources they have, 4.2 appears to be a rather significant release.
I found a very good looking theme for XFCE back then, but to make it usable I had to edit it myself and add the colored borders. It's been a while so no longer have all the files.
It needs to look good right out of the box to help adoption.
https://forum.qubes-os.org/t/improving-video-playback-speed/...
https://forum.qubes-os.org/t/hd-video-playback-on-qubes-os-o...
https://forum.qubes-os.org/t/improve-video-playback-performa...
and
How is your personal experience now? Does youtube in a browser work well for you? How about watching a movie saved locally?
I do not watch movies or Youtube very often, but it seems to be working fine.
In that context, security vulnerabilities in X11 don't have the same impact as they would in a normal distro. User processes running in a VM don't have the ability to exploit a problem in X11.
Go here https://www.qubes-os.org/faq/ and scroll down to "How does Qubes OS provide security?" to understand better.
Gnome is too opinionated to adjust it for Qubes: https://github.com/QubesOS/qubes-issues/issues/1806#issuecom...
However you can easily install KDE.
I've been giving serious thought to trying out Qubes lately, it looks like a pretty cool package.
> Qubes OS is designed to be a single-user desktop operating system
At the moment, it's true, but multi-user support is planned: https://github.com/QubesOS/qubes-issues/issues/8958
> Note that the Qubes website and documentation tend to use the term "VM" and "qube" interchangeably
This is because in the future a "qube" will be able to run on independent hardware: https://www.qubes-os.org/news/2018/01/22/qubes-air. Then, VM and qube will not necessarily be the same thing.
> For example, installing software on a Fedora desktop is usually as simple as "dnf install package". But installing software to use within a Fedora-based qube requires several additional steps on Qubes OS, plus restarting VMs
If the software is from the main repo, you do the same "dnf install package" in a template. There are no other steps apart from restarting the App VM (which can also be avoided if necessary).
> Then again, it's also not encouraged—Bluetooth isn't considered secure, so why focus on making it easier to configure?
You can use Bluetooth securely on Qubes OS (but it does require some effort to set up): https://github.com/QubesOS/qubes-issues/issues/7750#issuecom...
The github issues are nothing more than a wishlist. There doesn't seem to be any serious plans for this feature and no one seems interested in working on it. Limiting the user would require rewriting a large portion of the Qubes tools since they assume that the user has unrestricted access to the Xen API. I have looked at the feasibility of doing this myself in hopes of using Qubes in a corporate context but after looking into the architecture it became clear that I would never have time for such an undertaking.
>in the future a "qube" will be able to run on independent hardware
Qubes Air is vaporware and not under active development. There isn't much more to it beyond that blog post.
This is not exactly true, see the proof of concept:
More hardened templates, VM breakout detection and prevention and template integrity auditing with aide would be my top #3 wishlist items.