On 12/10/2016 12:36 PM, rtian...@gmail.com wrote:
On Saturday, December 10, 2016 at 6:03:17 AM UTC-7, jkitt wrote:
What's it like to update - is it relatively simple? Would you say it's more 
secure than Debian or Fedora?
It's easy. Shut down your Mirage OS Firewall VMs, copy over the new kernel 
files to the relevant directory in /var/lib/qubes/vm-kernels in dom0, and then 
restart the Mirage firewalls.

However, I don't know if it's more secure than using a Debian or Fedora based 
sys-firewall; it *might* help guard against a 0 day cascade though.

My feeling is this is a good step in exploring minimal resource use and attack surface. But in this particular role--firewalls--the risk is fairly low. Qubes configures sys-firewall as 'green' I think for this reason.

Where this kind of minimization may be more valuable is in running high-risk VMs like sys-net and sys-usb, but that is understandably more complex.

Chris

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/7f0309d3-207b-6b0a-40ce-a02124572066%40openmailbox.org.
For more options, visit https://groups.google.com/d/optout.

Reply via email to