Qubes OS GUI for End Users

Qubes OS Is Complicated. KUHBS Makes It Easy!

KUHBS is an app store for Qubes OS. Install, upgrade, and back up your favorite applications with one click.

  • End-User-Friendly GUI
  • Securely Configured Application VMs
  • KUHBS Is Fully Open-Source Software

Screenshots: Browse app setups and their lifecycle status.

The KUHBS graphical interface showing application cards and lifecycle actions

1 of 5 Browse app setups and their lifecycle status.

What Is KUHBS?

KUHBS Enables Non-Technical Users to Use Qubes OS Without Becoming Linux Experts

Bringing High-Security Computing to End Users

Qubes OS was developed for human rights activists, lawyers, whistleblowers, and people with a high cyber security threat model. It makes computing more secure by isolating each application into its own virtual machine, thereby preventing one hacked VM from compromising others.

However, Qubes OS is rather hard to use for end users. It is not enough to simply install Qubes OS; configuring it properly is vitally important for it to provide enhanced cyber security.

KUHBS makes Qubes OS accessible to people who are not Linux experts. It lets you install, upgrade, and back up your favorite applications in a graphical interface that is intentionally very simple and intuitive.

Operating System

What Is Qubes OS?

Qubes OS is a security-focused operating system that runs applications in separate virtual machines. If an application in one virtual machine is compromised, this separation prevents malware from spreading to the other applications. This is the same separation model used by all large cloud providers.

Management System

What Is KUHBS?

KUHBS abstracts the setup and installation of virtual machines and applications in Qubes OS and makes it accessible through a simple-to-use GUI. This enables end users to very easily install, upgrade, and back up the applications they want to use without having to understand how any of the technical steps in Qubes OS work.

Who Should Use KUHBS?

Built for People with a High Cybersecurity Threat Model

For people who can face real harm if their computer gets compromised.

For people whose contacts and documents must stay confidential.

For people who need to keep different identities and activities separated.

How Does KUHBS Work?

Automating the Complex Steps Required to Manage Applications in Qubes OS

Installing, configuring and managing applications in Qubes OS requires multiple highly technical steps.

KUHBS abstracts these steps into an easier-to-understand configuration management layer that removes the necessity of understanding Qubes for the user.

01

Technical Users Put Each Step of Installing an Application into Code

Installing an application in Qubes OS requires multiple technical steps. Technically versed users abstract these steps into code. The coded abstraction for managing one application is called a KUHB.

02

Technical Users Share the Code for Installing the Application on GitHub

Once the KUHB is capable of installing, upgrading, and backing up an application, it is published on GitHub by the technical users. This way the steps required to manage applications can be shared from experts to end users.

03

End Users Use the Technical Users' Code to Install, Upgrade, and Back Up Applications

Non-technical users search for KUHB definitions on GitHub. After finding the KUHB they need, they run an AI audit on it and then simply import it using KUHBS. All that's left to do to use the application is to click in the KUHBS GUI.

What Are KUHBS Features?

Install, Back Up, and Upgrade Applications

A KUHB is a coded way of describing how to install, back up, and upgrade an application in Qubes OS. End users import a KUHB from GitHub and then just have to click to use the application in Qubes OS.

Install

Install Applications

Choose an application and let KUHBS create the Qubes OS VMs, network connections and launchers you need to use the application.

Backup

Back Up and Restore

KUHBS lets you back up and restore the applications' data and configurations with one click.

Upgrade

Upgrade Applications

KUHBS makes it incredibly easy to periodically upgrade all your applications and Qubes OS itself.

What Do Qubes OS and KUHBS Not Protect Against?

Qubes OS Isolates Each Application but Does Not Make the Applications Themselves More Secure

Qubes OS prevents one exploited application from infecting all other applications installed on your computer. This is achieved by installing applications in virtual machines. Qubes OS and KUHBS, however, do not enhance the security of the application code itself. They simply prevent the further spread of an infection.

Read the Security Limits
Highly Capable / Rich / State Attackers

The isolation Qubes OS provides using virtual machines massively increases the complexity and monetary cost (buying exploits on the black market) required for an attack to compromise your whole system remotely. However, governments and other well-funded actors can purchase sophisticated commercial surveillance software and access to zero-day exploits from private vendors. State actors or highly motivated criminals can also break into your apartment or office.

Zero-Day Exploits for Applications

Criminals and state actors use AI to find zero-day vulnerabilities in applications you use. Zero-day vulnerabilities can also be bought on the black market. Using a zero-day exploit on any application you use, for example a browser, will give the attacker complete control of that browser and possibly the VM it runs in. Qubes and KUHBS cannot prevent this, but massively minimize the risk of one exploited application infecting other applications. Qubes OS uses Xen for virtual machines , which isolate applications from one another. Xen is also used by very large cloud computing companies, and hence finding a zero-day exploit for Xen is highly complicated, and buying one is very, very expensive.

Infected Backups and Restored Files

If an application is exploited and the malware is persistently installed in the files the application permanently saves (like your downloaded emails), then this malware will persist even if you set up your laptop again from scratch and restore backups. KUHBS only backs up exactly the files required for each individual application. All of the operating system files of the VM the application is running in are not backed up, but are instead set up again using the KUHB code whenever you remove and install an application. Qubes OS also provides mechanisms to limit the persistence of exploits across VM reboots. However, if malware infects the files that are persistent in Qubes OS and backed up by KUHBS, Qubes OS and KUHBS cannot protect you from the persistence of malware.

Compromised Computer Firmware

Firmware is code that is unrelated to the operating system you install on your computer, for example the BIOS of your computer. If this is infected, the attacker has total control over your computer regardless of which operating system you install. Qubes OS and KUHBS cannot detect or remove malware from BIOS, UEFI, or other device firmware. In order for malicious firmware to be remotely installed on your computer, access to Qubes OS’s most secure VM (dom0) is required. If an attacker has physical access to your computer, the attacker can just install firmware on your device (a BIOS password can help).

Physical Access to an Unlocked Computer

The disk encryption provided by the default Qubes OS installation prevents an attacker from gaining access to the application files saved on your computer (for example your photos). They can, however, modify the files in the /boot partition of Qubes OS, which would allow them to later gain access to your applications’ files and the whole operating system (Qubes OS). As stated above in “Compromised Computer Firmware”, physical access also allows an attacker to modify the firmware of your computer. Physical access to your computer, especially while it is unlocked, should always be synonymous with a complete breach of security.

Stolen Passwords and Accounts

The isolation of applications provided by Qubes OS has nothing to do with the passwords you use for your online accounts. If your account username and passwords are compromised, for example through a successful phishing attack (a well-crafted email that asks you to log in to your email account to “fix something”, with a link to a website that almost looks like gmail.com), neither Qubes OS nor KUHBS can protect you from that.

Getting Started with Qubes OS and KUHBS

Installing Qubes OS, KUHBS, Applications and Migrating Data

You do not need to be a Linux expert to use Qubes OS with KUHBS.

Our documentation guides end users through the installation of Qubes OS, the installation of KUHBS, and how to install, upgrade, and back up your applications.

  1. 01 Prepare

    Back Up Your Old OS

    Before migrating from your old operating system to Qubes OS, create a full backup first so you can restore the files in Qubes OS later.

  2. 03 KUHBS

    Install KUHBS in Qubes

    Our documentation shows how to install KUHBS in Qubes OS; it’s easy even for end users. After this, you only need to use the GUI for everything.

  3. 04 Create

    Install Applications

    Using the KUHBS GUI, you only need to click to install all the applications you need. After that, we guide you through restoring your old backups.

Frequently Asked Questions

Questions People Ask Before Trying KUHBS

Short answers about hardware, applications, data and security. If you are interested in using Qubes OS and KUHBS for your business, please contact us .

Do I Need to Be a Linux Expert?
No. KUHBS is made for people who need the security of Qubes OS but do not have the time to learn how Qubes OS works in detail. You still need to install Qubes OS and follow the setup guide. It is VERY helpful if you can invest time to learn more about how Qubes OS and KUHBS work to further increase your security, but it is not strictly required to get started and have a MASSIVE security advantage over your previous operating system.
What Computer Do I Need?
Many modern computers and laptops run Qubes OS without issues, but some can have hiccups here and there. It helps to first check the Qubes OS Hardware Compatibility List . Most Lenovo ThinkPads are very well supported. Especially before buying a computer, it makes sense to ask in the Qubes OS User Support forum . Vendors represented on the official Qubes-certified hardware list offer the best out-of-the-box Qubes OS compatibility and include NovaCustom.com , Nitrokey.com , Star Labs.systems , 3mdeb.com and Insurgo.ca .
Can I Use Familiar Applications?
As briefly described above, the “way to install an application” in KUHBS is abstracted into code called a “KUHB”: for example, a browser KUHB, a Signal-Desktop KUHB, or a Thunderbird email client KUHB. The developers of KUHBS provide a collection of KUHB definitions on GitHub . KUHBS makes it easy for technically versed Linux users to create custom KUHB definitions. You can also easily do this with your AI model of choice. So yes, you can use any Linux application that runs in Debian Linux. Windows is currently not (yet) supported by KUHBS, but you can install Windows VMs in Qubes OS besides KUHBS and use them normally (just not managed by KUHBS).
How Is My Data Stored in KUHBS?
Each application, for example Signal-Desktop, is installed in its own Qubes OS VM (said in an oversimplified or end-user-friendly way). The actual application data is then inside the Signal VM in the path /home/user/.config/Signal. KUHBS backs up only this exact path and nothing else. Hence, simply put, your application data, whether it is downloaded emails in the Thunderbird VM in /home/user/.thunderbird or private holiday pictures in the media VM in /home/user/Pictures, is stored in each individual VM. If you back up a VM, only the relevant paths are backed up.
Does KUHBS Make Applications Safe?
Qubes OS uses the Xen virtualization tool to provide virtual machines. Each application (Signal-Desktop, Thunderbird email client, browser, …) is installed inside of its own virtual machine. In KUHBS, all virtual machines run the Debian Linux operating system , which is similar to Ubuntu Linux but a bit more focused on security and stability. The security inside each virtual machine is not modified in any way (but can be modified using KUHBS if the developer of the KUHB chooses to do so). A KUHB for signal-desktop is commonly simply a bit of code that installs Signal-Desktop inside of a Debian VM. Nothing further is (commonly) done to make Signal more secure. Qubes OS security is provided mainly by securely isolating applications from one another using Xen so that if one is compromised, other applications will not get infected.

Where Can You Get Help?

Get Help from the Community or from Professionals

Blunix GmbH provides support for Qubes OS and KUHBS to businesses in the EU and the USA that have a valid business tax ID.