For example, running Chrome in a Docker container. Why not? Drawbacks? Security risks? Feasibility?
I understand that users download things but personally I can't recall doing that in recent memory, other than things like news/tech spec PDFs for later review. Moving downloaded files out of the browser's container would involve a fair bit of ceremony (physically selecting files/folders and dragging them out of the browsers "Download" folder and onto the host's file system, disallowing saving files outside of that folder, and so forth) but it doesn't seem that bad.
What do most users do with a browser other than open the thing, browse websites, and download files for later?
Except for the obscurity angle of course (nobody writes exploits against Chrome-under-Docker).
To be fair, VMs are also mostly about the obscurity angle too, and if you do all your browing in a VM the cookies alone will make the attacker sufficiently happy that they will probably not care. People don't hack because they want root on the bare-metal OS, people hack because they want to steal data. If it's in a VM or container, then getting there is enough.
Sorry, are you referring to Native Client or Chrome's site isolation?
(I hate VMs so much I just use two computers).
It's usable, just a bit annoying. I feel little option but to run Windows as a host OS in order to get best driver/video/battery support, so VMware is essentially mandatory.
It's also a huge attack surface.
Using an uncommon browser for something like banking (Opera or Vivaldi or something) would be a pretty good solution because no one would have bothered to develop the hooks for them, unless the malware is keylogging, which is not uncommon but less popular now than the smarter solution of watching browser form submits on known bank websites.
https://zeltser.com/security-risks-and-benefits-of-docker-ap...
The download part is the scary one. An average user can’t make the distinction between an OS message and a malware disguising as the former. Thus they download shit that wrecks havoc on their PCs. Besides, you could be infected by a compromised Flash banner so you don't even have to download anything.
And I don’t think that containers are a feasible approach for the average user. I doubt VMs are either. Our best bet would be browsers running in an isolation context simulating a VM. But that would require more RAM than the average user has available.
Please dear god no. Kill me now.
Of these someone who's installed their own OS has 2 slightly novel steps. So yeah trivial is maybe the wrong words but still easy.
Most people aren't. I think most people haven't installed on OS at all for that matter.
If so, have you ever forgot to use the virtual machine and instead browsed or read email on your host operating system? If so, what did you do?
Furthmore, is it possible to break out of the hypervisor and into the host operating system?
Note that that vuln is related to shared directories - anyone using a VM for isolation should probably not use these. I recently heard an amusing story of another infosec professional that cryptowalled their Macbook by testing on a VM with over-generous folder shares. Of course this is an extreme example caused by a clear mistake, but it's food for thought.
You can use Fedora, Debian, Whonix, or Windows in "seamless" mode with minimal effort. It has a composable networking architecture (e.g. easy to make all a VM's traffic go through Tor, whose traffic in turn goes over a VPN). Disposable VMs are a native feature. Template VMs reduce duplication of /; Application VMs use a template VM with CoW / and their own persistent /home.
Qubes uses Fedora 20 for Dom0, so you get all the same graphics support as Fedora gives you.
Debian is what I'm most familiar with, so that's my new place to go. Still quite big with a relatively basic install, but not as big as Ubuntu or Linux Mint.
Really lightweight stuff is Damn Small Linux (old) or Puppy Linux (never tried it), but I'm not sure how usable that is for day-to-day tasks.
Edit: I'm also surprised that we have such a large proportion of this discussion talking about something (using VMs) that is mentioned nowhere in the paper the thread is supposedly about. Perhaps if we were also discussing the (apparently) surprising fact that it was not mentioned it would make sense (to me, anyway).
I would never claim to know my email-renderer so well that I was 100% confident that it didn't have any attack vectors, particularly with all the crazy things you can do with unicode nowadays - much more straightforward to just read it in a virtual-machine. That way, even if you guessed wrong on the attack surface of your email client, the damage is contained.