the need to try out new software or tweak any settings, so he can do everything
he needs to do on a daily basis without having to interact with the command
line.
Carol, the investor
Carol works hard and lives below her means so that she can save money and
invest it for her future. She hopes to become financially independent and maybe
even retire early someday, and she’s decided that her best bet for achieving
this is by investing for the long term and allow compounding to do its work.
However, after doing some research into her country’s consumer financial
protection laws, she learned that there’s no legal guarantee that customers
will be made whole in the event of theft or fraud. The various insurance and
protection organizations only guarantee recovery in the case of a financial
institution failing, which is quite different from an individual customer
being hacked. Moreover, even though many financial institutions have their own
cybercrime policies, rarely, if ever, do they explicitly guarantee
reimbursement in the event that a customer gets hacked (rather than the
institution itself).
Carol looked into how thieves might actually try to steal her hard-earned
wealth and was surprised to learn that they have all sorts of ploys that she
had never even considered. For example, she had assumed that any theft would,
at the bare minimum, have to involve transferring money out of her account.
That seems like a safe assumption. But then she read about "pump and dump"
attacks, where thieves buy up some penny stock, hack into innocent people's
brokerage accounts, then use the victims' funds to buy that same penny stock,
"pumping" up its price so that the thieves can "dump" their shares on the
market, leaving the victims with worthless shares. No money is ever
transferred into or out of the victims' account; it's just used to buy and
sell securities. So, all the safeguards preventing new bank accounts from
being added or requiring extra approval for outbound transfers do nothing to
protect victims' funds in cases like these. And this is just one example!
Carol realized that she couldn't assume that existing safeguards against
specific, known attacks were enough. She had to think about security at a
more fundamental level and design it into her digital life from the ground
up.
After learning about all this, Carol decided that it was ultimately up to her
to take care of her own cybersecurity. She couldn’t rely on anyone else to do
it for her. Sure, most people just use regular consumer tech and will probably
end up fine, but, she reminded herself, most people also don’t have as much to
lose. It’s not a risk that she was willing to take with her future, especially
knowing that there’s probably no government bailout waiting for her and that
all the brokerage firms’ vaguely reassuring marketing language about
cybersecurity isn’t legally binding. So, Carol started reading more about
computer security and eventually stumbled upon Qubes OS after searching the web
for “most secure operating system.” She read about how it’s designed and why.
Although she didn’t immediately understand all of the technical details, the
fundamental principle of security-by-compartmentalization (https://www.qubes-os.org/doc/architecture/)
made intuitive sense to her, and the more she learned about the technical
aspects, the more she realized that this is what she’d been looking for. Today,
her setup looks like this: