Interesting topic...

I would like to here more about how people handle this.

On my side, I'would never work on sensitive information in such a situation.
To make just some surfing in public place, my laptop is installed with a 
standard w10 that I use only to check a generic mailbox with on sensitive 
information, do some nonsensitive work and surf. By the way, the boot sequence 
of my laptop is set to boot this partition by default with no menu or prompt of 
any kind. If I want to boot into qubes, I have to do it manually by interupting 
the boot sequence.
This also serves as a decoy, if I'm forced to boot my laptop when passing 
borders or so.

Best,

0xdeadbeef



Sent with [ProtonMail](https://protonmail.com) Secure Email.


-------- Original Message --------
Subject: [qubes-users] Re: traveling - best practice
Local Time: February 8, 2017 8:30 AM
UTC Time: February 8, 2017 7:30 AM
From: pixelfa...@gmail.com
To: qubes-users <qubes-users@googlegroups.com>

On Tuesday, February 7, 2017 at 5:09:45 AM UTC-8, haaber wrote:
> Hello, I wonder how you behave when traveling, for example in places
> with cameras all around. I feel uncomfortable to enter my passwords in
> such situations. Of course I can simply not turn my computer on. But

most "security" cameras cant see much. but the cloud of cell phones
and any cameras worn by those looking to do this will have little trouble
seeing and hearing your passphrases.

you could use a yubikey to type your passphrase in, though be careful of
pick pockets.

you could also velcro some cloth around the lid like this, 
https://goo.gl/photos/py8qdxRPtoz3PGL19

if you do, make sure theres some going around the front too. then use it with 
your back to two corners.

someone could still pick up your typing with a good directional mic, but then
you have a different threat model.

in this case, you could have your laptop unlocked and suspended, with a
qrexec service to shut it down should it leave, for example, the vicinity of 
your cell phone or NFC implant.

> sometimes you have several hours in an airport .. I thought about 3
> options.
>
> 0) Change all (disk / user) pwd before & after traveling (how do I
> change the disk pwd?).

everything you ever wanted to know about luks, 
https://gitlab.com/cryptsetup/cryptsetup

> 1) Pull out my tails usbkey and surf with that?

yes. or, better yet, tails on a dummy netbook or chromebook.

>
> 2) maybe it woud be nice to have an additional "single cube"
> usr/password : when using this user name, one would get a single
> disposable untrusted VM, no dom0 acces, no USB, and so forth. Is that
> feasable / reasonable?

this goes back some earlier discussions. easiest way is to dual boot
your laptop.

>
> how do you cope with that? Thank you, Bernhard

leave it off, walk around, see the local art. sample the chocolate and coffee.
try not to work.

--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/1f778e42-ae04-4d12-ac5e-ae60e41c675f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/YHFVL6WipjnpOts4b64UoOrUkpRc0SYcbw3lWtKI845ETwRKbogKqMyt8ebXPi3k36ixukLPPEpvmaeNk7C_O4PrAGXa_4Z2jKK3GTzzK5I%3D%40protonmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to