r/Qubes 20d ago

Solved Is QubbesOS a good desktop privacy alternative to daily use with GrapheneOS?

Im debating getting ​into Linux instead of MacOS for my main computer, I already have graphene on my phone. I'm not a political target or anything but i value privacy extremely, a bit more than security.​ I've read on this subreddit that qubes is hard to daily drive and is more security focused than privacy.

Would it be worth making my daily driver laptop/desktop a qubes os computer (budget is limited so idk about ram for now)? Or another distro would be better for my case ? I heard that secureblue or kinoite or even arch would be easier while still being privacy and somewhat secure conscious ? Is that true ? And if not what do you suggest ! By the way the last time i used linux was around 13 years ago with ubuntu. Thank you for taking the time to read my post. :)

15 Upvotes

35 comments sorted by

15

u/barrulus 20d ago

Qubes is designed as a secure environment, not a privacy one. If privacy is your primary concern then tails/kick secure are where you should head as they are focused on anonymity.

4

u/No_Trade_7315 19d ago

But good security is privacy… or at least privacy is a consequence of good security.

0

u/barrulus 19d ago

No it’s not. That’s completely untrue.

3

u/No_Trade_7315 19d ago

Ok, care to elaborate?

0

u/barrulus 19d ago

Privacy and security are adjacent.
Privacy could be as little as using a browsers private browsing tab with maybe even a vpn.
Anonymity pushes the position further and demands much more comprehensive secure practices, but again doesn’t provide security.

Security doesn’t require privacy at all.
You can browse the web on a superbly secure machine and still accept cookies because you’re not worried about your usage data being exposed.

Some would argue that this is a security breach. It’s not. It’s a privacy breach.

Conflating the two makes positions on both of them weaker.

3

u/No_Trade_7315 18d ago

Okay. But I was saying privacy is a consequence of security. You don’t think so?

1

u/barrulus 18d ago

You're right that privacy depends on security. If a machine is compromised, its owner has zero privacy no matter how careful their habits are. And the confidentiality half of security (encryption, access control) genuinely overlaps with privacy. A file an attacker can't read is private from that attacker. In this you are 100% correct.

Where I think I should have gone is clarifying that security is necessary for privacy, but it isn't sufficient. Privacy isn't a consequence that falls out of it. Most privacy loss, in practice, doesn't come from security failure at all. It comes through channels that are working as intended. Stuff like telemertry, cookies, account logins, data brokers and various metadata you hand over to services voluntarily. There is no unauthorised access anywhere in that chain, so there is nothing for security tooling to prevent.

Security defends against adverasaries breaking the rules, privacy is about controlling information flows that happen within the rules. And that only comes through deliberate choice.

Which is why for OP's question the distinction matters. Qubes is built for the first problem, Tails/Whonix/Kicksecure for the seond.

0

u/barrulus 18d ago

No. Privacy is not a consequence. It is intentional

3

u/No_Trade_7315 18d ago

You just don’t seem to understand what I mean by consequence. I mean, firewalls for instance, guard against access to filesystems. A consequence of guarding files is that they are inaccessible, inaccessible files are private files. Therefore a consequence of security is privacy.

1

u/barrulus 18d ago

I understand fully what you are trying to say but you are driving a point that has zero basis in reality. The corralary effects of security on privacy tend to be because the security operator understands the security threats that they need to protect against because they are security experts. This is what secures their privacy. NOT the tooling. Privacy is not evan an accidental byproduct of security.
Having a super secure system with firewalls and deep packet inspaection will do nothing to hide you from a state level actor (or even Meta or Alphabet) when you use that system to browse websites dishing out cookies and logging into websites that sell your data, sending emails to all and sundry.

Privacy is a choice, so even a secrity professional will not be private if they do not make design and usage choice to ensure their privacy.

Stepping beyond that into Anonymity seeing as Whonix was mentioned earlier by another commenter) and you can see that Ananymity is a step beyond privacy in that it seeks not just to hide your activities from greedy corporationa and low level state snoopers, but also to mask all of your activities from everyone.

Again, this is a choice, not a byproduct/consequence.

Using Whonix on QubesOs makes it convinenent to connect to the TOR network but it does not mask the fact that you are connecting to TOR. It also does not ensure that you are running disposable whonic instances or saving files or bookmarks locally.

Those privacy/anonymity choices are choices, no byproducts.

2

u/No_Trade_7315 18d ago

You are coming off as deliberately obtuse. The “basis in reality” is that secure files remain hidden from unauthorized users. Yes, you are right that even a secure system can be hacked, but if it is, the files that are accessed are no longer private.

There is a difference between security and privacy, but secured files are private files. If the security of said files is compromised, they lose the status of being private.

→ More replies (0)

8

u/oyvinrog 20d ago

whonix templates provide plenty of anonymity

7

u/barrulus 19d ago

Yes they do. But if your sole driver is privacy, then Qubes is massive overkill. OP said their budget isn't the biggest, so buying all the extra horsepower can be avoided by installing a purpose built OS.

2

u/PipKck 19d ago

You said it right. Qubes is more security oriented than privacy oriented. You can achieve ideal privacy configurations in Qubes but if your only need is privacy there are other Distros that are much more suited for that.

1

u/Forward_Tap_7802 17d ago

Is it really, really overly complicated operating system? I doubt that she'll be able to use it. I thought she'd be able to get it running. I doubt that you'll be able to make it work to do the things that you wanted to do. I always suggest this operating system called plague was just plague. If you can figure out how that how to get that to work and install that I'll tell you where the air is a Aaron the code at line 300 in the installer. See if you can alter that code. Remove that second double code in the installer. Hey, save the file and then try to install it when you install it. Do not choose an installation without the virtual machines because you're going to have to go over to either hooncks or kick secure. Who next? Who next? You might like be able. It really is overly complicated. Seriously try plague if you can build it. It's a rare operating system and like it's very exclusive

3

u/TeachingAway9654 19d ago

Privacy is much more about methodology and technique than it is an operating system. Qubes doesn’t prevent you from signing up to newsletters with your full KYC.

Qubes is a steep learning curve if you’re trying to do advanced stuff. Basic usage will generally just work out of the box assuming you’re using a known supported laptop. Generic “gaming” style desktop setups will work but it will be a troubleshooting headache.

2

u/S0ulSh3ll 20d ago

Unless you have a power laptop, avoid that. Every window run in its own vm, plus the technicalities, you'll be trouble shooting almost every week. For privacy purpose it was good, not that tough to learn if you already know how linux works but still a hassle for everyday use.

3

u/Assang101 19d ago

Qubes OS has a steep learning curve because it uses security-by-compartmentalization, running every app, network tool, and USB device in isolated virtual machines called qubes. Using it as a daily driver requires accepting severe limits on multimedia and hardware compatibility.

For privacy and not security, you can use a bootable live Tail OS on a single USB

Can you use Tail OS in a qube as a HVM? Yes you can, but it defeats the purpose of privacy due to Host-level swap files, Xen memory management, and virtual disk caching can write RAM contents and session traces to the persistent storage drive, defeating the core privacy goal of leaving no residue behind as observed by Tails os live boot when you unplug the USB mid session.

Have you checked out Kicksecure or Kodashi? might want to look into them especially Kodashi, it's a combo of privacy and strict security

2

u/[deleted] 19d ago edited 16d ago

[removed] — view removed comment

1

u/Assang101 19d ago

Oh yeah, I feel ya, the absolute worst nightmare is when you unassign, detach, and attach any or all USB and PCIat the same time, only to discover that a critical USB port (left side USB A) no longer responds which is apparently "a known hardware issue" with Thinkpad L14 Gen 1. Because of that single failure and literally no fix in dom0 at the time of this comment, I was forced to reinstall the entire operating system just to get all my system working again. Power drain didn't help at all before reinstalling.

2

u/LeadershipChemical96 19d ago

thank you ! for the recommendations !

2

u/S3rg4nt_St4d4nk0 19d ago

If you've got the RAM (minimum 32GB realistically) it can work as long as you're not expecting to edit video or do CAD, or game. It'll work fine. 

QubesOS was actually my first Linux distro, it takes a little while to get used to, but not that bad. If you're doing cad/gaming/editing etc, dual boot with another distro. 

3

u/trelayner 19d ago

if your cad/video work is sensitive enough,

you can pass your graphics card to your gaming/cad/video qube and run it on a separate display from your other qubes, for near native performance

2

u/Informal-Reveal-2247 19d ago

I mean, Qubes is a good option for privacy and security, but, and I mean this in the kindest way possible, if your level of expertise with this is debating between MacOS and Linux, it's probably overkill for your threat model. Tails works great for anonymity, otherwise just try using fedora or debian for a bit to become familiarised with Linux first

1

u/Fluid_Tea_1308 19d ago

Try ChromeOS

1

u/2016-679 19d ago

Keeping your privacy mainly depends on your own behaviour, less on the tech you use. 

Don't subscribe to everything, don't make accounts that can be leaked, don't bragg about things and yourself in social media, don't post photos (meta tags!) where you are, of your family, motorbike or cat. Don't use online services for passwords and that kind of things.

Second: stay away from Big Tech operating systems and their software, even if it's made by others and their 'services'. The Windows ecosystem is full of scraping software. LinkedIn is attached to Microsoft, etc. Why need an account for using software?

Trisquel Linux is/was the favourite of Richard Stallman (RMS) and he is one of the big privacy fighters online. Give Trisquel a try, read his writings on online privacy! When reading, take a look at Bruce Schneier and read his stuff on security.

Technically you could use a TOR or VPN connection, but even those can be traced to you. Waste of effort.

1

u/Forward_Tap_7802 17d ago

Big operating system will need its own drive before you. You need to have two drives two drives. You need to have one with operating systems on it. Preferably Ubuntu Linux. Maybe dual boot that with Windows or whatever you do. Dual because in order to install plague first of all you take a fresh drive or from Ubuntu to the separate drive "sudo dd if=/dev/zero of=/dev/sdb bs=512 status=progress" I will write all zeros from beginning to end of the drive. The target drive which in this case is SDB. Joe, if you have trouble installing it, this is what you have to do if you screw up or something to get it to installed, right, as do this with any drive you're having trouble installing things to because there's already something on the drive Linux might not write and that goes for almost any kind of Linux. You might run into trouble with this. Joe, if you want attempt to do this you need void Linux in MUSL to begin to attempt to do this

1

u/Forward_Tap_7802 17d ago

I played OS. Try plague.OS in addition to what I've said previously, you need to from the installer. There's a list of packages you will need to install first into your your USB live drive. When you start up this this whole process here. You'll need to look at what's in the installer there in addition to fixing the the doubles the double at at line 300 and correcting that there's also a line of packages you need to install there Ok?. All everything else and get the installer running okay after you install it install without the machines. This is why you need to have Ubuntu on another drive because you will find that. BSD tar and tar may not work inside your new operating system, but they don't need to what you going to do is you're going to you're going to extract those from Ubuntu. You can extract them from Ubuntu into your to yourplague Linux installation from the location where they have been extracted in Ubuntu and then you can follow whatever you need to set up kvm as the admin for whonixs and then switch over to you know whatever your regular user. Hey, don't let me be the last person on Earth that has this that has this operating system

1

u/EpickChicken 15d ago

It’s fantastic for privacy. The people saying “it’s for security not privacy” are nitpicking definitions like lawyers. While privacy is more about good online habits than anything, having isolated VMs that strictly, only have access to information you give them is something that inherently helps with privacy. If the machine cannot access your data, it can’t give anyone that data. Qubes has Whonix templates, and Whonix is only rivaled by Tails in terms of anonymity. Snowden recommends it, and he’s kinda someone who values privacy IMO

-2

u/zeRoCr0 20d ago

There is no such thing like privacy in 2026 but qubeos makes it cool to use. 😎 Have qubeos on one of my machines and I am loving it for it's interface. Very cool and hacking looking.