Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There's a man who hasn't tried running qubes-mirage-firewall.

Unikernels don't work for him; there are many of us who are very thankful for them.



> there are many of us who are very thankful for them.

Why? Can you explain, in light of the article, and for those of us who may not be familiar with qubes-mirage-firewall, why?


In Qubes you use VMs to separate your banking environment from the one where you pull npm dependencies and the one where you open untrusted PDFs.

Networking also happens in its own VM, and you can have multiple VMs dedicated to networking.

Much lower memory footprint running mirage firewall, and an attack surface orders of magnitude smaller (compared to a VM running a Linux distribution purely for networking).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: