Re: [qubes-users] Benefits of Sys-Firewall

2020-02-29 Thread Claudio Chinicz
Thanks you dhorf and Sven for explaining the subject. I've learnt from your 
words.

Best Regards

On Saturday, 29 February 2020 02:49:59 UTC+2, dhorf-hfr...@hashmail.org 
wrote:
>
> On Fri, Feb 28, 2020 at 06:00:04PM -0600, Sven Semmler wrote: 
>
> > You want your sys-firewall to be separate from sys-net for the same 
> > reason: compartmentalization. 
>
> as usual "depends on your threat model". 
>
> if you are into outbound-firewalling of appvms, not doing so in the 
> appvm makes a lot of sense for the reasons you stated. 
> but you could do that in sys-net too, entirely without sys-firewall. 
>
> unless your threat model involves the same (or cooperating) attackers 
> compromising your sys-net from the outside that want to break out of 
> your appvm... 
>
>
> > I hope others will correct me if I got anything wrong. 
>
> looks good to me. 
> but i would like to add some off-default-config considerations/rambling. 
>
> what if your attacker has some l2-ish network linux exploit? 
> lets take something like CVE-2018-15688 as an example. 
> ipv6 dhcp problem, in both systemd and networkmanager. 
>
> afaik no one ever really evaluated the impact on a qubes system. 
> because ipv6 is "disabled" in the default config. 
> but what does that mean? 
> "ipv6 disabled in qubes" means ipv6 is disabled _within_ qubes. 
> as in, it is actualy enabled (by default) in sys-net in some ways, 
> just not forwarding it on the qubes-internal network links. 
>
> so worst case, an attacker can compromise your sys-net, then compromise 
> your sys-firewall, then your appvm. all with the same exploit, just 
> having to go hop-by-hop. 
>
> one way to mitigate a scenario like that is to involve something that 
> is _very_ much not linux. like qubes-mirage-firewall. or a bsd fw. 
> which of course is a "threat model" and "subjective considerations" thing. 
>
> because one side of it is ... it makes it much more unlikely for a 
> single attacker to have a walkthrough with a single exploit. 
> == it makes it less likely for an attacker to compromise the whole chain. 
>
> otoh ... now there are two ip stacks involved, and the mirage one 
> certainly got a lot less eyeballing than the linux one. 
> == it makes it more likely for an attacker to compromise part of your 
> chain. 
>
> and there are "env" factors to consider too. 
> sure, if you dont have the ram to run separate linux based firewall vms, 
> go ahead and dump all of it (inkl sys-usb) into sys-net. 
> or your HW doesnt have (usable) IOMMU and you run your sys-net/sys-usb 
> pci-vms as "pv" instead of "hvm". 
> your overall security posture will (probably) still be better than with 
> a plain linux (or anything else) system, even though you take some 
> shortcuts that are not default config or recommended. 
>
> qubes provides a lot of different options there, with a reasonable 
> default config, but (depending on your threat model) going beyond 
> that can be quite reasonable too. 
>
>
>
>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/ffc9ee62-3159-40a8-b0a0-69910faecbfd%40googlegroups.com.


Re: [qubes-users] On "https://www.qubes-os.org/doc/tails/"

2020-02-29 Thread unman
On Sat, Feb 29, 2020 at 08:02:27PM +0100, Ulrich Windl wrote:
> Hi!
> 
> I have some questions that are not covered in 
> https://www.qubes-os.org/doc/tails/:
> 
> First what is the procedure to add the image the same way as the other 
> templates are installed?

There is no such procedure. Tails is a live OS intended to run from an
USB stick, or DVD. For convenience you may keep the disk image in one of
your qubes.

> If I have the image on a stick, the VM creation procedure does not copy the 
> image, to I would need the image all the time. 8-(

Copy the image, or download it, to one of your qubes
Then start the HVM with --cdrom=:

> 
> Then, when Tails starts, it switches graphics mode and complains 
> 
> "Error starting GDM with your graphics card: Device [1234:] (rev 02). 
> Please take note of this error and visit ... for trouble shooting"
> 
> How can I fix this? I had no luck with Google search...

Works for me.
Did you download the version for virtual machines?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20200301012811.GE17379%40thirdeyesecurity.org.


Re: [qubes-users] Q: Monitoring Updates

2020-02-29 Thread unman
On Sat, Feb 29, 2020 at 07:40:02PM +0100, Ulrich Windl wrote:
> Hi!
> 
> I noticed that update of templates is rather silent when using the Updater 
> App. Opposed to that when I use "Update Qube" in the Qubes Manager, a text 
> window opens showing actual progress of the update. Unfortunately the 
> mechanism is different (i.e. no Managment DVM is being used).
> 
> Is there a way to follow update progress when using the Updater App?
> 
> Regards,
> Ulrich
> 

No.
The Updates does show you results from the update process. I do not know
what the Qube manager shows you that is different.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20200301010239.GD17379%40thirdeyesecurity.org.


Re: [qubes-users] Odd DigiNotar Certificates in Thunderbird

2020-02-29 Thread unman
On Sat, Feb 29, 2020 at 06:49:09PM +0100, Ulrich Windl wrote:
> Hi!
> 
> Examining the certificates in Thunderbird, I found two "suspect" ones under 
> "Servers":
> 
> DigiNotar PKIoverheid CA Organisatie - G2
> 
> DigiNotar Root CA
> 
> For a CA those have a very strange certificate  serial number, and most oddly 
> Thunderbird displays a "*" in the "Server" column.
> 
> Shouldn't CA certificates be found in Authorities?
> 
> Regards,
> Ulrich
> 
> 
If you had bothered to search for this you would have found that those
certificates are included BECAUSE THEY ARE NOT TRUSTED.
If you examine them you will see that this is the case.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20200301010028.GC17379%40thirdeyesecurity.org.


Re: [qubes-users] Q: (debian-10) Why Thunderbird "Daily"?

2020-02-29 Thread unman
On Sat, Feb 30, 2020 at 06:40:01PM +0100, Ulrich Windl wrote:
> Hi!
> 
> When launching Thunderbird via debian-10-dvm I'm greeted with "Welcome to
> Daily" ("You are using the daily version of Thunderbird, which means you get 
> to
> experience the absolute newest Thunderbird - fresh out of the build system! 
> But
> with great power comes great responsibility, we hope you???ll take the time to
> report bugs and provide feedback on your experience using the daily version 
> and
> help make the next Thunderbird release as awesome as possible.")
> 
> 
> The About says it's version 68.5.0 (64 bit).
> 
> Who can explain?
> 
> Regards,
> Ulrich
> 
> 

What's to explain? (Perhaps the fact that you get this message when I
dont when I opened Tbird for the firts time.?)
Debian has packaged a "daily build" to give the "newest" Thunderbird, at
the time of packaging. When the package is updated you'll get a newer
version.
68.5.0 is the latest build of Thunderbird.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20200301005205.GB17379%40thirdeyesecurity.org.


Re: [qubes-users] the qubes clipboard

2020-02-29 Thread unman
On Sat, Feb 29, 2020 at 07:02:58PM +, 'Jackie' via qubes-users wrote:
> Ulrich Windl:
> > Hi!
> > 
> > I'm very much confused with the Qubes OS clipboard:
> > When trying to copy some text from a Temrinal, I mark the text with the 
> > mouse then press "Ctrl+Shift+C", and I get a confirmation that the text is 
> > copied.
> > However when I try to paste the clipboard in another machine, the contents 
> > is not what I had marked.
> > When I use the "Edit->Copy" menu in the Terminal after having marked the 
> > text, and then press "Ctrl+Shift+C" again, the correct text is put in the 
> > Qubes OS clipboard.
> > Confusingly the Terminal displays the shortcut "Ctrl+Shift+C" for 
> > "Edit->Copy".
> > 
> > Isn't that a highly confusing feature (slowing down productive work a lot 
> > IMHO)?
> > 
> > Regards,
> > Ulrich
> 
> Hi,
> 
> In general, copying text from one VM to another is a four step process.
> Highlight text in VM1 document and ctrl+C to copy to VM1 clipboard. Then
> ctrl+shift+C to copy to dom0 clipboard. Then in VM2 window ctrl+shift+V to
> copy to VM2 clipboard, then ctrl+V to paste into document.
> 
> It's pretty fast once you get used to it, just highlight, ctrl+C,
> ctrl+shift+C, alt+tab, ctrl+shift+V, ctrl+V.
> 
> Terminal is a special case because ctrl+C, ctrl+V doesn't work to
> copy/paste, and default terminal shortcuts are the same as qubes inter-vm
> copy/paste shortcuts that take precedence. To paste text into terminal i
> ctrl+shift+V like normal to copy into VM clipboard, then edit->paste to
> paste into terminal. Or to copy from terminal, highlight, edit->copy, then
> ctrl+shift+C to copy to dom0 clipboard.
> 
> Actually i think it's possible to change the dom0 shortcut so they no longer
> conflict, but the occasional edit->copy or edit->paste in terminal isn't too
> inconvenient for me.
> 

Also, it depends (naturally) on *which* terminal you use.
I have little experience with gnome-terminal, which is, I think, what
op is using.
Using xterm or uxterm, mouse selection *does* work to copy, and
Ctrl+Shift+C copies that text to clipboard for transmission to another
qube.
Does gnome-terminal need some extra configuration to enable "selection
by mouse"?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20200301003728.GA17379%40thirdeyesecurity.org.


[qubes-users] Re: SSD and safety.

2020-02-29 Thread brendan . hoar
The diskashur and similar projects will come under the same scrutiny as SED 
devices’ built-in TCG Opal: that the encryption layer is closed source and not 
publicly auditable (unlike LUKS w/dm-crypt under Linux which is auditable).

The summary of my position is: use the hw encryption features available, but 
also use open-source software encryption on top.  Belts and suspenders.

B

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/439e6634-11de-4d84-aabd-a0c89b06313a%40googlegroups.com.


Re: [qubes-users] the qubes clipboard

2020-02-29 Thread 'Jackie' via qubes-users

Ulrich Windl:

Hi!

I'm very much confused with the Qubes OS clipboard:
When trying to copy some text from a Temrinal, I mark the text with the mouse then press 
"Ctrl+Shift+C", and I get a confirmation that the text is copied.
However when I try to paste the clipboard in another machine, the contents is 
not what I had marked.
When I use the "Edit->Copy" menu in the Terminal after having marked the text, and then 
press "Ctrl+Shift+C" again, the correct text is put in the Qubes OS clipboard.
Confusingly the Terminal displays the shortcut "Ctrl+Shift+C" for "Edit->Copy".

Isn't that a highly confusing feature (slowing down productive work a lot IMHO)?

Regards,
Ulrich


Hi,

In general, copying text from one VM to another is a four step process. 
Highlight text in VM1 document and ctrl+C to copy to VM1 clipboard. Then 
ctrl+shift+C to copy to dom0 clipboard. Then in VM2 window ctrl+shift+V 
to copy to VM2 clipboard, then ctrl+V to paste into document.


It's pretty fast once you get used to it, just highlight, ctrl+C, 
ctrl+shift+C, alt+tab, ctrl+shift+V, ctrl+V.


Terminal is a special case because ctrl+C, ctrl+V doesn't work to 
copy/paste, and default terminal shortcuts are the same as qubes 
inter-vm copy/paste shortcuts that take precedence. To paste text into 
terminal i ctrl+shift+V like normal to copy into VM clipboard, then 
edit->paste to paste into terminal. Or to copy from terminal, highlight, 
edit->copy, then ctrl+shift+C to copy to dom0 clipboard.


Actually i think it's possible to change the dom0 shortcut so they no 
longer conflict, but the occasional edit->copy or edit->paste in 
terminal isn't too inconvenient for me.


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/053ac3c5-0ed6-65fc-10cb-dd22dd2dce4a%40danwin1210.me.


[qubes-users] On "https://www.qubes-os.org/doc/tails/"

2020-02-29 Thread Ulrich Windl
Hi!

I have some questions that are not covered in 
https://www.qubes-os.org/doc/tails/:

First what is the procedure to add the image the same way as the other 
templates are installed?
If I have the image on a stick, the VM creation procedure does not copy the 
image, to I would need the image all the time. 8-(

Then, when Tails starts, it switches graphics mode and complains 

"Error starting GDM with your graphics card: Device [1234:] (rev 02). 
Please take note of this error and visit ... for trouble shooting"

How can I fix this? I had no luck with Google search...


Regards,
Ulrich


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5E5AB54302A100037798%40gwsmtp.uni-regensburg.de.


[qubes-users] Q: Monitoring Updates

2020-02-29 Thread Ulrich Windl
Hi!

I noticed that update of templates is rather silent when using the Updater App. 
Opposed to that when I use "Update Qube" in the Qubes Manager, a text window 
opens showing actual progress of the update. Unfortunately the mechanism is 
different (i.e. no Managment DVM is being used).

Is there a way to follow update progress when using the Updater App?

Regards,
Ulrich


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5E5AB00202A100037782%40gwsmtp.uni-regensburg.de.


[qubes-users] Odd DigiNotar Certificates in Thunderbird

2020-02-29 Thread Ulrich Windl
Hi!

Examining the certificates in Thunderbird, I found two "suspect" ones under 
"Servers":

DigiNotar PKIoverheid CA Organisatie - G2

DigiNotar Root CA

For a CA those have a very strange certificate  serial number, and most oddly 
Thunderbird displays a "*" in the "Server" column.

Shouldn't CA certificates be found in Authorities?

Regards,
Ulrich


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5E5AA41502A1000374B2%40gwsmtp.uni-regensburg.de.


[qubes-users] Q: (debian-10) Why Thunderbird "Daily"?

2020-02-29 Thread Ulrich Windl
Hi!

When launching Thunderbird via debian-10-dvm I'm greeted with "Welcome to
Daily" ("You are using the daily version of Thunderbird, which means you get to
experience the absolute newest Thunderbird - fresh out of the build system! But
with great power comes great responsibility, we hope you’ll take the time to
report bugs and provide feedback on your experience using the daily version and
help make the next Thunderbird release as awesome as possible.")


The About says it's version 68.5.0 (64 bit).

Who can explain?

Regards,
Ulrich


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5E5AA1F102A1000374A6%40gwsmtp.uni-regensburg.de.


[qubes-users] the qubes clipboard

2020-02-29 Thread Ulrich Windl
Hi!

I'm very much confused with the Qubes OS clipboard:
When trying to copy some text from a Temrinal, I mark the text with the mouse 
then press "Ctrl+Shift+C", and I get a confirmation that the text is copied.
However when I try to paste the clipboard in another machine, the contents is 
not what I had marked.
When I use the "Edit->Copy" menu in the Terminal after having marked the text, 
and then press "Ctrl+Shift+C" again, the correct text is put in the Qubes OS 
clipboard.
Confusingly the Terminal displays the shortcut "Ctrl+Shift+C" for "Edit->Copy".

Isn't that a highly confusing feature (slowing down productive work a lot IMHO)?

Regards,
Ulrich


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5E5A9C1102A10003749A%40gwsmtp.uni-regensburg.de.


[qubes-users] Those "eintr" log messages from qrexec

2020-02-29 Thread Ulrich Windl
Hi!

I always thought it must be a bug, seeing "eintr" log messages like this:
Feb 29 17:05:19 host qrexec-agent[607]: eintr

When viewing the qrexec log, on only see "eintr" messages each in a line, 
nothing else.

What is that supposed to tell me?

Regards,
Ulrich


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5E5A9AD902A10003748D%40gwsmtp.uni-regensburg.de.


[qubes-users] debian-10 dvm and Terminal

2020-02-29 Thread Ulrich Windl
Hi!

I have an odd issue with a debian-10 DVM and the Terminal: If I try to launch a 
DVM opening the Terminal, the VM starts, the terminal appears for a short 
moment, then disappears and the DVM is stopped.
However when I try the other commands (each starting a new DVM): Files, 
Firefox, Thunderbird, Help, the all work.
I'm writing this message with a debian-10 DVM using Firefox...

I'm rather clueless. When using "Terminal" on the fedora-30 based DVMs, it 
works as expected.

Any ideas?

Regards,
Ulrich


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5E5A99AE02A100037485%40gwsmtp.uni-regensburg.de.


Re: [qubes-users] Struggling with Debian Template VMs (Regular vs tmp...)

2020-02-29 Thread unman
On Sat, Feb 29, 2020 at 01:52:31PM +, unman wrote:
> On Sat, Feb 29, 2020 at 05:10:13AM -0800, maxime@gmail.com wrote:
> > Hello all,
> > Kind of a newbie with Qubes which I'm running for a few months now on a 
> > Thinkpad X1 Carbon (I took the same version as developers to limit 
> > surprises!! ;-)
> > 
> > I'm a bit lost with the Debian template VMs
> > After I installed Qubes following the instructions I ended up with two 
> > Template VMs for Debian:
> > > debian-9
> > > tmp-debian-9
> > 
> > The point is that I can only create AppVMs based on tmp-debian-9
> > If I try with the regular debian-9, the Qube is actually created but won't 
> > start... it halts straight away.
> > Q1: is this tmp VM normal and just a matter of naming?
> > Q2: if yes, should I remove the "regular" debian-9
> > 
> > Thanks for any help you can provide!
> > 
> > Max
> > 
> 
> Which version did you install?
> I would remove both, and install the latest template with
>  `sudo dnf install qubes-template-debian-10`

Stupid me - I mean
`sudo qubes-dom0-update qubes-template-debian-10`
run in dom0 terminal

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20200229135341.GB15394%40thirdeyesecurity.org.


Re: [qubes-users] Struggling with Debian Template VMs (Regular vs tmp...)

2020-02-29 Thread unman
On Sat, Feb 29, 2020 at 05:10:13AM -0800, maxime@gmail.com wrote:
> Hello all,
> Kind of a newbie with Qubes which I'm running for a few months now on a 
> Thinkpad X1 Carbon (I took the same version as developers to limit 
> surprises!! ;-)
> 
> I'm a bit lost with the Debian template VMs
> After I installed Qubes following the instructions I ended up with two 
> Template VMs for Debian:
> > debian-9
> > tmp-debian-9
> 
> The point is that I can only create AppVMs based on tmp-debian-9
> If I try with the regular debian-9, the Qube is actually created but won't 
> start... it halts straight away.
> Q1: is this tmp VM normal and just a matter of naming?
> Q2: if yes, should I remove the "regular" debian-9
> 
> Thanks for any help you can provide!
> 
> Max
> 

Which version did you install?
I would remove both, and install the latest template with
 `sudo dnf install qubes-template-debian-10`

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20200229135231.GA15394%40thirdeyesecurity.org.


[qubes-users] Struggling with Debian Template VMs (Regular vs tmp...)

2020-02-29 Thread maxime . hnh
Hello all,
Kind of a newbie with Qubes which I'm running for a few months now on a 
Thinkpad X1 Carbon (I took the same version as developers to limit 
surprises!! ;-)

I'm a bit lost with the Debian template VMs
After I installed Qubes following the instructions I ended up with two 
Template VMs for Debian:
> debian-9
> tmp-debian-9

The point is that I can only create AppVMs based on tmp-debian-9
If I try with the regular debian-9, the Qube is actually created but won't 
start... it halts straight away.
Q1: is this tmp VM normal and just a matter of naming?
Q2: if yes, should I remove the "regular" debian-9

Thanks for any help you can provide!

Max

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/b2be6219-549d-47fd-a015-6273dc44080e%40googlegroups.com.


[qubes-users] Re: SSD and safety.

2020-02-29 Thread Daniil Travnikov
What do you think about this product?
https://istorage-uk.com/product/diskashur-pro2/

Maybe this better then Opal?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/552498df-54ae-4545-b57d-0fa2924b473f%40googlegroups.com.


Re: [qubes-users] Mounting directories across VMs (losetup/block device solution for directories)?

2020-02-29 Thread David Hobach

On 2/28/20 2:40 PM, Johannes Graumann wrote:

On 2020-02-27 20:32, David Hobach wrote:


On 2/26/20 10:23 PM, Johannes Graumann wrote:

Hi,
I'm experimenting with creating a sys-dropbox vm that syncs with my
dropbox account. I would love to be able to then mount defined
subdirectories of the synced path to other vms (losetop/qvm-block-
style, which only works for files).
Is this possible? Where to find pointers?


qcrypt can do that: https://github.com/3hhh/qcrypt


Nice solution, but overkill in my case - I use tresorit's E2EE solution
(let's not get started on the closed source/snake oil discussion, I have
to consider noob-co-usage ...) and want to sync that storage to a
sys-tresorit, from where I want to grant access to certain subsections
of it to individual vms - without additional encryption.


I disagree with the idea that only pros deserve real security.

I'd recommend automating stuff so much that it can be used by "noobs". 
Only that automation programming might require some "pro" knowledge, but 
it needs to be done only once.



Any pointers on where to start exploring the above mentioned sshfs via
qubes-rpc solution?


Check the qubes-rpc doc on the Qubes website. I'm not sure whether 
someone already implemented that.


However wrt your apparently low profile threat model I don't see too 
much of a security benefit over doing it over battle-hardened TCP 
anyway. So you might just want to check the Qubes doc on opening ports 
to other VMs.


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/8bc714cd-03b3-8f7d-d84b-168f3a02ea45%40hackingthe.net.


smime.p7s
Description: S/MIME Cryptographic Signature


Re: [qubes-users] Where to find the directory of a attached mobile phone ?

2020-02-29 Thread dhorf-hfref . 4a288f10
On Sat, Feb 29, 2020 at 08:02:25AM +0100, A E wrote:
> When I execute "sudo mount /dev/xvdi /mnt" in the terminal of the VM, I get
> this error: “mount: /dev/xvdi/mnt: can’t find in /etc/fstab.

that error doesnt match the command. one of them must be incorrect.
if the error is real, it indicates you didnt put a space between
the device and the target path.
this part is "basic linux usage" btw, very much not qubes specific.
googling "how to mount a disk in linux" (or with the distro name
you are using instead of linux) might help.

check what xvd* device is actualy used by running "qvm-block" in dom0. 
or "cat /proc/partitions" or "ls -l /dev/xvd*" in the target vm. 
(hint: its not the xvda/b/c/d ones, those are the system "disks",
 user attached devices should be xvdi, xvdj...) 


> And I get this with both devices.

what "both devices"?


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20200229103559.GI8973%40priv-mua.


[qubes-users] Re: Telegram desktop installation

2020-02-29 Thread Daniil Travnikov
For Debian:

$ sudo nano /etc/apt/sources.list
# add 'deb http://ftp.debian.org/debian buster-backports main'
$ sudo apt-get update
$ sudo apt-get upgrade
# https://backports.debian.org/instructions/
$ sudo apt-get -t buster-backports install telegram-desktop


For Fedora:

$ sudo dnf install telegram-desktop

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/a0480ecb-d3cb-42e7-b6b7-dddbede7f965%40googlegroups.com.