A Desktop Security Journey that Ends (for now) with Qubes OS

No ratings

Presented at BSidesPhiladephia 2019 by

It started with the humble intention of making my company issued Windows laptop just a bit more secure and private. But my unassuming, minor configuration tweaks and small scripts needed constant improvements, and I soon found myself spending increasingly less time playing with the dog and more time at my desk, perfecting responsive tasks, super granular-permissioned processes, ephemeral VMs and sandboxes, honeypots, and making countless changes to user accounts and monitoring jobs. Gradually, my PC had evolved into a Rube Goldberg’s machine of defenses. Everything worked, but felt overly exaggerated and complicated. Tired of playing catch-up with Microsoft and with new attack tactics, I eventually switched to Qubes OS. This is my attempt at simple desktop security using basic tools and scripts, hoping to create defenses that would be straight-forward to understand and could be easily audited and replicated. I’ll explain what went well and what didn’t, discuss tricks and “gotcha” moments and things that I’d avoid if I was to repeat the effort. The second part of the talk will cover Qubes OS, "a reasonably secure operating system", which achieves isolation through multiple Xen-powered environments. I’ll go over my experience switching to Qubes OS, what I liked and what could be improved, and whether or not a system like Qubes can be used organizationally at scale.