I no longer use Windows on any of my PCs. I have currently two instances that run as VMs.
One dedicated solely for remote connection to my work. The company insists on software to scan that my PC is "secure", so I give them a finger with an almost virgin Windows install. Their crap can work only on Windows, so I don't actually have any choice.
Another is for any application that I use that I absolutely can't find replacement for on Linux.
I also have separate Linux VMs for suspect software like Zoom that I have to use but I don't trust to run on my machine or try to take over my desktop.
> The company insists on software to scan that my PC is "secure", so I give them a finger with an almost virgin Windows install. Their crap can work only on Windows, so I don't actually have any choice.
Maybe this software actually is crap and you know this for a fact. Maybe whoever is in charge doesn't know what they're doing. If so maybe ignore this comment.
With that said though, the principle to only allow "secure" systems for remote access sounds absolutely reasonable.
Having been on the other side of this situation, I have to say users like you are a real pain to deal with sometimes. There are always a few who "know their stuff thank-you-very-much", and feel that they need to "give the finger" to whatever measures are taken to secure things.
Try to see it from the IT-sec guy's perspective. Maybe some "crap" endpoint security software on the PCs isn't the end of the world if it helps keep things secure?
I have two laptops, a work laptop and a personal laptop. The work laptop is supplied by my employer and as far as I'm concerned they can install whatever they damn well please on it, because the only thing I use it for, and I mean the only thing, is work - no Internet searches, no random software downloads, not even HN. A patch of tape over the camera and away we go.
My personal laptop stays personal. It's mine and doesn't belong to anyone else. I never use it for work, even if alongside me during working hours. Zero crapware, minimal AV.
I have the same approach to phones. There's my phone, and my work phone. I was pressured to put Outlook, Teams on my personal phone since my work phone is switched off out of hours - I nearly succumbed, until that Office Portal app wanted to 'manage my device'. Nope. Our primary on-call comms mechanism remains SMS/direct call.
The issue is this practice does not achieve anything and only achieves to annoy me as a person who must navigate unnecessary complexity of trying to do honest work.
If employer is really interested in achieving some measure of security, there would have to be separate computer configured and locked to only allow it to be used for work.
That would, I think be "reasonable".
What I think is not reasonable is meddling in my own machine which I treated as my own until one day my employer said "Sorry, from now your private PC is ours to audit because we are not willing to spend equivalent of two days of your income to provide a machine for you to securely, conveniently and reasonably access our system".
Nobody really cared for the fact that my all machines are running Linux, they just have assumed that I must have some kind of PC and that that PC is running either Windows or Linux. And so they configured their system so that before I can use Citrix (which works perfectly fine on Linux) their piece of crap written for Windows or Macos (no Linux version) must run and report what is installed and running on my machine for their own silly needs.
No, that is not "reasonable" and for that my honest middle finger.
Ok so it seems the real problem is that your employer does not provide you with the tool you need to perform your work, i.e. a computer. If they did, they would have the responsibility and ability to secure it. By methods which could include installing some auditing software.
It's obviously not really reasonable to expect you to install such things on your private computer. Sounds like there could actually be some legal issues with such practice?
If it was your own choice to use your private computer then that's a different story. But it sounds like it is definitely not by choice.
> Nobody really cared for the fact that my all machines are running Linux
2021 is the year Linux becomes a mainstream desktop OS right? ;-)
> 2021 is the year Linux becomes a mainstream desktop OS right? ;-)
Except I have been running Linux on desktops since 1999. I have Debian server that has been regularly updated since 2000 (that includes hardware changes and moving OS image from HDD to HDD and finally to SSD).
I am in charge of IT security for my company and in my experience users like you get put in a tough place. On one hand, you want the freedom to work however you like, but on the other hand the company has real requirements and limitations imposed on them that necessitate dictating how end users compute. I am also guessing that for every user like yourself who would gladly use a company provided device to keep their personal and work computing separate, there is a corresponding user who absolutely will not tolerate being forced to use an additional corporate machine and will complain until blue in the face about it. It's a lose-lose situation for IT.
There is also the matter of endpoint protection to consider. If I am allowing a personal device to connect to my environment, how do I know that device is secure? The only way to have any level of assurance to that fact is to install remote monitoring agents, inspect the configuration of the system, and restrict administrative permissions so the end-user (or an attacker who hijacks the end user's access) cannot mess with things in such a way as to compromise the already shaky ground the integrity of that system stands upon.
If I worked at your company, I would give two options: either use a corporate machine for work activities, or if using a personal machine for whatever reason then IT gets administrative control of the device. There is no third option. And before IT assumes administrative rights to manage the device, the end user is signing an acceptable use policy that they agree to any and all IT security controls placed upon the device. If that is unacceptable then the alternative is always to use the corporate device.
I am not sure if you're an FTE or a contractor or what your locale is, but IMO imposing that kind of control over a privately owned device without an agreement would be at best inappropriate, and potentially illegal. My response would have been "No, thank you." I do however sympathize that it is not always possible to take that stance.
I don't know what's the solution. I'm trying to get back to linux but then my suspend doesn't work, touchpad feels sluggish and my battery lasts 2 hours instead of 7+.
There are tools to debug power issues on Linux laptops. I use these from time to time especially when I am going to be sailing for couple of days.
I can use my t440s (7yo) for over 24 hours on three batteries, internal 3 cell, and external 3 cell and 9 cell. I use it for light development, reading PDFs, some web, etc.
There are also laptops that are more Linux friendly than others. It is best to buy laptop specifically for Linux use and do research before the purchase.
Maybe I'm being an asshole and should "submit a patch" but I really get annoyed when basic things don't work. I'm happy to debug custom software, but I don't understand how things like battery management isn't solved.
I've used it on many laptops including a fully specced Dell XPS 13 (which burned out after a small spill on the keyboard)
Mine was once drenched completely in hot sweet latte and once submerged in mineral water (don't ask how...) It still works with no issues even though both times I had to disassemble completely and wash all parts including motherboard. The mineral water got between lcd leaves so I had to separate, wash and dry individual layers of LCD.
My tip is to always have IPA, distilled water and tools to disassemble and clean your laptop.
Most boards can be washed safely but there are some components that can be damaged.
Safest method is to use distilled, deoxygenated water (aka electronic water) to remove most contaminants, followed by 99% isopropyl alcohol or 96% ethyl alcohol to remove the rest and also water.
Don't skimp on water and alcohol, submerge the board and use brush while submerged, to pull and dilute contaminants.
Just never use tap or mineral water. You can use regular distilled water as long as you do it quickly, but unless it is deoxygenated it will be corroding so don't leave it in water for long.
Alcohol is there mostly to dilute water so that it dries out very quickly. Without alcohol water could stay under components for a long time and kill or damage your board.
Alcohols can damage some plastic components, so don't keep it in alcohol fo too long, either.
I would add that washing with water is normal part of board production. Fluxes are designed to be water soluble and a lot of fluxes are washed with water with addition of saponifiers.
It is also normal to wash a board in ultrasonic cleaner after any rework or at the end of production process (especially in small scale production).
Depends. If you decide it is not possible for you to spill on your laptop or the loss of your laptop is worth less than half a day of your time and keeping two bottles one of clean water and one of clean alcohol, then sure, just ignore this.
On the other hand if you own an expensive machine that can be reasonably disassembled (ie. almost anything else than a Mac) and you plan to use it for a long time and you don't have any other insurance against spill, then you might be able to save a lot of money with a very small amount of effort.
My laptop was fully beefed up Lenovo T440s and I live in Poland. In Poland, this laptop represented about 3-4 average monthly salaries. Not much compared to half a day of effort to disassemble, clean and reassemble again.
Half a day assumes you have no idea what you are doing and you are need extra time to figure out what to do, find videos on Internet, figure out why you can't pull a part and what still keeps it in place, etc.
For a person that knows what they are doing this is half an hour of effort.
It's indeed annoying. More so that it generally is solved but is to be found somewhere in the fragmented linux ecosystem.
I had no issues with my laptop and it worked better than windows which turns it into a jetengine for some reason except for bluetooth earbuds for which i needed a fork of pulseaudio or so....
Right now I'm back to osx but I'm really missing a good tiling manager like i3wm. As for the future I'm looking at system76 desktops, but still undecided (especially since apple's m1 hardware)
That horrible battery life on Ubuntu on an XPS 13 sounds like something else wrong. Several of my coworkers are running exactly that (over different generations even) and it's been with no tweaks.
You simply need a laptop which was designed for Linux, not the one on which you can install it. I recommend this one: https://puri.sm/products/librem-14.
In the march forwards, e.g. GNOME 2 -> GNOME 3, there are a number of regressions mixed in with the improvements. I think tackling overall UX may be seen as unattractive work compared to tacking on new features.
For example, GNOME Files (formerly Nautilus) and the GTK file chooser are not even as good as competitors from the 1990s (like the Mac or Windows equivalents). GIMP and Inkscape are also noticeable steps down from the equivalent software we used in the 1990s (not just the well-known Adobe products, but also products from Corel, Macromedia, etc.)
My impression is that the Linux desktop is playing catch-up with the Windows and Mac desktops, but since Microsoft and Apple have better funding it’s an impossible job—the target is moving too fast. In an effort to catch up with modern UIs, features that used to work are getting broken or the UX is degrading. The GNOME 2 -> GNOME 3 switch is just one example. I’m not saying GNOME 2 is better than GNOME 3 overall, just that large-scale changes are moving too fast and the polish and long-term fixes are coming too slowly by comparison.
Linux is usually my primary desktop and when I switch to my Mac it feels like a breath of fresh air.
Honestly I would love it if more users would adopt similar practices. My only question would be how do we validate that the Windows guests remain isolated from the host. Depending on the virtualization software that is an achievable task.
Imagine a world where users only ran the bare minimum software necessary for an atomically specific work task. It sounds like pure joy from my perspective.
I also have a bunch of other VMs. For example, I keep my toolchains for embedded development in separate VMs so that I can trust they still work years later when I need to do some quick correction to some project of mine. These have auto updates turned off. I hate when I want to quickly change something and program the device but first I have to investigate why the tool chain no longer works.
Not all of these VMs are active at the same time. I usually have 2 or 3 VMs active, some paused and most turned off.
I do similar things. Everything I run is built on top of LXD or KVM so that it remains compatible across time and is not beholden to anything but the Linux kernel, with disk images backed up at key points of the installation process. All of the build scripts are housed at [1] and then I have a set of machine-specific scripts that leverage those to rebuild any of my virtual systems in a single command with no data loss. Press a button, walk away, and in half an hour I have a pristine system with everything I need installed and my data drive mounted.
Any time I'm working on a machine that was set up non-deterministically, I feel vulnerable...
I recently started playing around with libvirt/QEMU on Linux and was amazed how well the VMs work, especially when you have two video cards plugged in and can do PCI passthrough.
It's so seamless. I now run my Windows "VM" on that, and works fantastically. I have it installed to a separate SSD as well (I was curious if it would work) and performance is excellent.
Yeah I was watching a video[1] about QEMU vs virtual box comparison yesterday on youtube and the guy doing it found that the QEMU version was faster than his host machine in some cases. It was confusing!
One dedicated solely for remote connection to my work. The company insists on software to scan that my PC is "secure", so I give them a finger with an almost virgin Windows install. Their crap can work only on Windows, so I don't actually have any choice.
Another is for any application that I use that I absolutely can't find replacement for on Linux.
I also have separate Linux VMs for suspect software like Zoom that I have to use but I don't trust to run on my machine or try to take over my desktop.