On Tue, Jan 08, 2019 at 04:25:00AM -0800, simon.new...@gmail.com wrote: > As per subject, does anyone use things such as AIDE (or other file integrity > IDS) ? > > I understand the security model is "if dom0 is compromised, you are fscked" > but it would be at least nice to have something that gave me a heads up if > such an event happens. >
I use tripwire - primarily in dom0, but also in selected qubes. Also periodic rpm -aV in dom0. As you say, always nice to know if the games up. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/20190108160231.3s6kbtoetdbewpsj%40thirdeyesecurity.org. For more options, visit https://groups.google.com/d/optout.