The right way to do it usually fails the market due to backwards compatibility or developer pushback to adopt such features (see WinRT sandbox).
Mobile phones security has it easier, because there wasn't backwards compatibility to care about, and so far the stores gatekeeping means that developers that want to play there have to oblige anyway.
That pun was superb btw
Most desktop software needs to provide value for customers, or they would just build the web version of it. Being "native" isn't enough.
So, if you want to require that us developers run our stuff inside of sandboxes, that's fine. Just make sure the sandbox doesn't prevent our software from getting access to the same important desktop surfaces.
Qubes OS solves this with hardware virtualization, which is really fast and secure.
[0] https://www.qubes-os.org/doc/how-to-organize-your-qubes/
When I clicked the link I was expecting something like a unikernel, eg https://roscidus.com/blog/blog/2016/01/01/a-unikernel-firewa...
[0] https://forum.qubes-os.org/t/devuan-or-other-non-systemd-tem...
https://forum.qubes-os.org/t/alpine-linux-template-non-offic...
[1] https://forum.qubes-os.org/t/openbsd-as-a-ubes-os-component/...
[2] https://forum.qubes-os.org/t/mirage-firewall-0-9-0-released/...
Does it then become not a full OS anymore? Mirage is what I linked to above.
Probably not. I mentioned it, because you mentioned systemd. And yes, I saw your Mirage link and showed how you can use it on Qubes.
* music production software * discord * games * copy and pasting
[0] https://www.qubes-os.org/faq/#can-i-run-applications-like-ga...
[1] https://github.com/QubesOS/qubes-issues/issues/8552
[2] https://www.qubes-os.org/doc/how-to-copy-and-paste-text/
[3] https://forum.qubes-os.org/t/question-quality-of-external-us...
Discord runs fine both in-browser and in application. Raptor Lake seems to have zero issue with video voice chat, whereas Comet Lake can drag a bit in large rooms without a GPU. Qubes OS makes it dirt easy to multiprofile from all around the world.
I don't really game like others do; eye candy doesn't draw me in, but solving interesting puzzles/challenges does.
Copy & paste is superior in Qubes, skill issue sorry not-sorry. GIT GUD!
How is it superior? Gamer insults aren't going to win folks over here. They're more likely to cause people to dismiss you.
The copy-pasting between VMs, mentioned in a sibling, requires four steps: (1) copying to the source VM's clipboard, (2) copying to the global clipboard, (3) copying to the destination VM's clipboard, and (4) pasting to the destination. The shortcuts become part of your muscle memory after some use, but until they are, that is just one way in which Qubes gets in the way of productivity.
There are a bunch of minor quirks, often specific to the hardware, which the user needs to learn about and find workarounds for. But if they do, Qubes is probably the most seamless way to work with tons of (well-isolated) VMs. For example, SecureDrop [0] is based on Qubes and does seem to work well for journalists for securely receiving and working with documents from anonymous sources.
> The shortcuts become part of your muscle memory after some use
So you agree that it's doable, just that it requires a bit more effort. It's definitely true.
> bunch of minor quirks, often specific to the hardware
Which is why there is a list of recommended hardware: https://forum.qubes-os.org/t/community-recommended-computers...
And likely, upsetting power users who want to run with all the safeties off.
It’s more about not being locked out of actual admin access to my own computer.
I expect to have at minimum a developer mode that allows me to enter my password to allow me to run whatever code I want without OS vendor blessing. Heck, add a small coding challenge to unlock it. Whatever.
Here are high-profile examples of each:
https://en.wikipedia.org/wiki/Dutch_Sandwich
https://en.wikipedia.org/wiki/Intel_Management_Engine#Assert...
This blog post describes a class of vulnerabilities. That's why there are ten of them. A well-resourced adversary with the capability to influence software development would want their backdoor to be small and difficult to discover. In many cases they would like guarantees that they are the only entity to be able to abuse such a vulnerability. While one can argue that these bugs were difficult to find–they were only fixed now–they really aren't very good backdoor bugs. Why leave dozens of holes all over the place when you only need a few? It's much more likely that this is just a failure case that someone failed to consider.