With desktop software, especially development tooling, becoming increasingly more complex, I think process isolation will be an area that will be getting more important over time: things easier to use than but more isolated than "every weird utility can read your ssh keys".

I never got very excited by Wayland (it lacks some of the nice "separation of concerns" that X11 has), but it looks like GUI isolation might a good reason to get on board with it after all.

alyssa.is/using-virtio-wl/

Follow

Actually seem to have some success with isolating ... but I'm not sure I'll be able to get back out of the rabbithole now :D

qubes-os.org/doc/gui/

They are looking into Wayland as well though (saw github.com/qubesos/qubes-issue and some more recent activity in the / dev chat) but seem somewhat held back by the fact that they want to keep supporting older distro's in the VM's.

Having quite some fun with codeberg.org/raboof/volare here :D

@raboof Honestly, I think Wayland would be a better path to trod for them. It does a lot of isolation and security by default. And it's likely to be better maintained in the future.
Sign in to participate in the conversation
Merveilles

Revel in the marvels of the universe. We are a collective of forward-thinking individuals who strive to better ourselves and our surroundings through constant creation. We express ourselves through music, art, games, and writing. We also put great value in play. A warm welcome to any like-minded people who feel these ideals resonate with them.