On Thursday, 20 November 2014 12:31:36 UTC, Dogged One wrote:
> That was indeed easy enough :) My understanding is that you don't really want to be installing software on Qubes due to opening it up to potential attack. Is there a best safe practice to add software to the core template? Should I, can I, be cloning the default template before adding to it?
In addition to what Francesco said, I find the wiki page at
https://qubes-os.org/wiki/SoftwareUpdateVM pretty coherent at explaining the issues.
I'm personally still feeling my way with when to clone a template, currently I have an additional one for the google chrome repo, this makes sense as I only use that browser in one domain, so it seems sensible not to add that additional trust to all domains.
I have yet another with wine installed as it again feels weird to have this software present in all vms.
Keeping all the clones up to date is laborious, so I would be curious as to when others are using cloned templates, the recent discussions on automating template updating seems to suggest quite a few of us may be cloning more than we ought (although this probably has a "be your own bitch" answer coming right to it :) )