Add introductory chapter on Qubes OS security architecture#1609
Conversation
This text is intended as an overview of Qubes' advanced security features. It could be used to help in the decision whether the introduction or at least test of Qubes OS is suitable in a given environment. It shows the adavntages of this system compared with more traditional approaches to system security.
|
Thanks for producing (generating?) this! Generally looks like a good introduction to Qubes OS, as the first document a user could read.
The former is easy to fix. The latter, I'm not sure. If it'd be shorter, I'd say to consider replacing some of the the existing page, but in it's current, longer form it might not be suitable for that (the doc has both generic introduction "why?", but also a bit more detailed "how?"). Images help breaking the "wall of text" impression, but still it's a fairly long doc. Splitting might be an option, but then the doc looses its benefit of being a single document (a single document to describe Qubes OS). Maybe make it explicit that it's an alternative introduction? Or maybe my impression that we need (also) a "short introduction" is wrong and just the long one would be okay? I guess that's up to our documentation maintainers. This also requires careful review. I've read select parts (probably like 20% of it), and generally looks accurate, but somebody needs to review it in full, especially if it was generated by AI. |
also replacing the AI-generated Qubes logo with the official one
|
I replaced the AI-generated logo with the official one. Your other comment is much more difficult to address, and I'm also not sure how to proceed there. Here are some considerations, which may help to find a way:
Regarding the review: I checked the text and images because I don't trust anything generated by AI, but I would be glad for any second opinion from the reviewers. Reading it again and again will, at some time, help nothing anymore, because I just won't recognize the errors. |
As a first step into understanding Qubes OS, some general diagrams may be helpful. While they do not explain the technical structure of the system, they may help to get a first idea of how it works and may motivate you to proceed deeper into the documentation.
|
Just to clarify for the review process, and in order to be compliant with the "use of AI policy": The material of this pull request was created, at least partially, using the NotebookLM AI tool.
Fortunately, I found not many errors in this process, showing that NotebookLM performs quite well if supplied with a sound basis. In my experience, the results of this way of working were much better than using ChatGPT, which produced mainly crap, and so could not be used for serious work. |
|
Fwiw I think it is superb to talk Qubes OS visually via infographics !!! It could make also a nice introductory presentation! ;) |
fb326e8 to
84445a2
Compare
|
Thanks for your work on this. |
|
There's something wrong here. What about - |
|
Can you change "traditional OSs" to "a traditional OS" In Glance_Qubes_philosophy - what is the purpose of the sub heading? Glance_Qubes_compartmentalization - There's a large amount of duplication between this and the previous image. Glance_Compartmentalization - I think this is a good image. I should say that I am not the best person to review this, as is probably obvious. |
|
I am uncertain about the last three images. |
|
Glance_Securing_IT - This repeats information provided previously. Glance_Blueprint - I am unclear how this links with Qubes. Also an emphasis on non-EU dependencies may not sit well with other countries. I think this could be dropped altogether. Glance_Open_Source_Path - I think that the main image is confusing. Who are these figures chained to the castle? Why is the same building where people are working falling down? Again, I think there is an emphasis on "european", and while I endorse the slide, I am unclear how it provides information on Qubes. These last slides could be removed without loss to the introduction.If you wanted to show how Qubes could work as a path to digital sovereignty, you could include one slide explicitly referring to that. It would need (I think) not to be state specific. |
Could you explain that? What's wrong? I made the suggested changes and hope that it's now somewhat clearer. Some of the problems you mentioned are nice examples of AI going wild. I used AI quite heavily to create the pictures, as my drawing abilities are near zero. But in any case, I had to do quite a lot of manual corrections until the output of AI became useful, but I obviously missed some points. So, if only I could draw better, I doubt if the use of AI could then still save work! Then I removed Glance_Qubes_compartmentalization and the last three pictures. Instead, I added two new pictures on Windows support and a more neutral one on sovereignty. Thank you for your help! Just one more point: I see these pictures just as demonstration material that could be used to tell the management what Qubes is, because many managers tend not to be willing or not able to read documentation. So, the really important part of this contribution is, in my opinion, the paper on Qubes security architecture, because that could help to understand the concepts. |
No description provided.