from Hacker News

Show HN: Qvm-Create-Windows-Qube: The most secure and private way to run Windows

by elliotkillick on 10/17/21, 9:52 PM with 40 comments

  • by elliotkillick on 10/17/21, 9:53 PM

    Hi, HN! This is a small project I developed for Qubes OS that allows you to spin up new Windows qubes quickly, effortlessly and securely.

    Hope you don't mind the flamboyant title, but, I truly do believe that the small attack surface of the heavily minified Xen hypervisor, networking stack, GUI virtualization, and much more Qubes OS employs + the Whonix intergration implemented in this project (making it a Windows-Whonix-Workstation; thus also giving it Tor-only Internet access with stream isolation between other VMs) makes it the most secure and private way to use Windows currently available today. Those are just the two main points, besides that, there is also the fact that because everyone using this project is both having their Windows VMs set up in the same way and running Qubes OS, that greatly helps to keep the OS and hypervisor fingerprint homogeneous across all users. This effect will only grow stronger as the Qubes OS userbase increases. Lastly, if the user wishes to reset their fingerprint, they can automatically do so by reinstalling Windows with this project.

    Of course, I would be happy to go into detail and answer questions about any of this.

    Note that this project is the product of an independent effort which is not officially endorsed by Qubes OS or Whonix.

  • by RandomChimp on 10/20/21, 10:00 AM

    Awesome work Elliot, and much appreciated. I've just got Windows-10 ltsc working on qubes 4.1 with whonix 16. My 2 use cases are:

    1. A dev machine. I have a persistent and static disposable version of this build.

    2. An anon build connected to whonix. Again, I have persistent and disposable versions.

    One thing I had to do was compile the QWT v4.1.65 iso and install the resulting msi. Other than that it all works flawlessly and provides great peace of mind for those occasions when I have to use Windows.

  • by egberts1 on 10/18/21, 5:40 PM

    What I am really looking for in Qube is when the window of Windows VM gets minimized, it performs a CPU suspend, preferably within its VM.

    No need for chatty telemetry at Windows and app level in the background.

  • by TheFreim on 10/18/21, 1:25 PM

    I hope to try qubes one day, it's a shame that my current hardware isn't supported. If I wanted to learn how to add support for my own hardware where would I start (would probably be quite an undertaking, but might be worth learning about regardless of how far I'd get).
  • by ourbetterworld on 10/19/21, 1:30 AM

    I have been trying to buy a Librem 14 for Qubes but need a backup. What’s best-in-class?