Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cubes OS care about this problem and have a really great solution. If you’re linux-savvy I would recommend it. There are some friction points but it is 100% usable even as a main work OS (I did this for a while in one of the startups I worked for).

As an example of something you can do trivially in cubes, say someone sends you a PDF that you don’t trust you can just right-click on it, the OS will spin up a temp vm, copy the PDF over and start the PDF viewer in the VM. When you’re done, the VM is nuked and any nefarious b/s the PDF tried to do is gone. Typically these tempvms have networking disabled so there’s no way it can communicate with the mothership either.



I have PDFs set to open with firejail. Adds about a second to launch times, acceptable IMO.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: