We should start and maintain a UX and conceptual comparison of the SecureDrop Workstation versus a stock Qubes installation versus a non-Qubes system. For example:
Non-Qubes OS
SecureDrop Workstation
Stock Qubes OS
Once connected, a USB device is...
immediately available
immediately available to a quarantine VM (sd-devices)
not available until manually connected to a VM
This column layout both assumes and suggests that the Workstation's conceptual model is mostly intermediate between the non-Qubes model and the stock-Qubes model. Right now, this is a hypothesis; it may or may not turn out to be a principle we codify and follow affirmatively. An immediate counterexample:
Non-Qubes OS
SecureDrop Workstation
Stock Qubes OS
Copied text can be pasted...
anywhere
anywhere, with an extra modal copy-paste operation, except to and from VMs tagged sd-workstation
anywhere, with an extra modal copy-paste operation
We should start and maintain a UX and conceptual comparison of the SecureDrop Workstation versus a stock Qubes installation versus a non-Qubes system. For example:
sd-devices
)This column layout both assumes and suggests that the Workstation's conceptual model is mostly intermediate between the non-Qubes model and the stock-Qubes model. Right now, this is a hypothesis; it may or may not turn out to be a principle we codify and follow affirmatively. An immediate counterexample:
sd-workstation