[qubes-devel] XSAs released on 2021-02-18

2021-02-19 Thread Andrew David Wong
/news/2021/02/19/xsas-released-on-2021-02-18/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this group and stop receiving emails fro

[qubes-devel] QSB-065: Missed flush in XSA-321 backport (XSA-366)

2021-02-19 Thread Andrew David Wong
Dear Qubes Community, We have just published Qubes Security Bulletin (QSB) 065: Missed flush in XSA-321 backport (XSA-366). The text of this QSB is reproduced below. This QSB and its accompanying signatures will always be available in the Qubes Security Pack (qubes-secpack). View QSB-065 in

[qubes-devel] XSAs released on 2021-02-16

2021-02-17 Thread Andrew David Wong
is also available on the Qubes website: https://www.qubes-os.org/news/2021/02/17/xsas-released-on-2021-02-16/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel&q

[qubes-devel] QSB-064: Linux: error handling issues in blkback's grant mapping (XSA-365)

2021-02-17 Thread Andrew David Wong
Dear Qubes Community, We have just published Qubes Security Bulletin (QSB) 064: Linux: error handling issues in blkback's grant mapping (XSA-365). The text of this QSB is reproduced below. This QSB and its accompanying signatures will always be available in the Qubes Security Pack

[qubes-devel] Qubes OS 4.0.4-rc2 has been released!

2021-01-23 Thread Andrew David Wong
/reporting-bugs/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2021/01/22/qubes-4-0-4-rc2/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-

[qubes-devel] XSAs released on 2021-01-21

2021-01-22 Thread Andrew David Wong
is also available on the Qubes website: https://www.qubes-os.org/news/2021/01/22/xsas-released-on-2021-01-21/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel&q

[qubes-devel] Re: Qubes Canary 025

2020-12-16 Thread Andrew David Wong
On 12/14/20 5:58 AM, Andrew David Wong wrote: Dear Qubes Community, Several users have pointed out a mistake in the canary below. "March 2020" should instead be "March 2021". This was just a typographical error. We will be fixing this and updating the signatures on th

[qubes-devel] XSAs released on 2020-12-15

2020-12-16 Thread Andrew David Wong
-os.org/news/2020/12/16/xsas-released-on-2020-12-15/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this group and stop receiving e

[qubes-devel] QSB-063: Multiple Xen issues (XSA-115, XSA-325, XSA-350)

2020-12-16 Thread Andrew David Wong
Dear Qubes Community, We have just published Qubes Security Bulletin (QSB) 063: Stack corruption from XSA-346 change (XSA-355). The text of this QSB is reproduced below. This QSB and its accompanying signatures will always be available in the Qubes Security Pack (qubes-secpack). View

Re: [qubes-devel] Re: Qubes Canary 025

2020-12-14 Thread Andrew David Wong
signed via the git commits and/or tags and, in the case of QSBs and Canaries, with detached signature files in the repos. -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-

[qubes-devel] Qubes Canary 025

2020-12-12 Thread Andrew David Wong
Dear Qubes Community, We have published Qubes Canary 025. The text of this canary is reproduced below. Note: We have decided to make some minor formatting changes to the way Qubes Canary and Qubes Security Bulletin (QSB) numbers are printed, such as dropping the '#' symbol and using hyphens

Re: [qubes-devel] Qubes Template

2020-12-09 Thread Andrew David Wong
.org/support/ Using Qubes under another hypervisor is not officially supported: https://www.qubes-os.org/faq/#can-i-install-qubes-in-a-virtual-machine-eg-on-vmware However, some users have been able to get it to work. -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.

Re: [qubes-devel] [GSoD] Final update and report

2020-12-05 Thread Andrew David Wong
g with you. Glad to hear you'll be sticking around! :) -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this group and stop recei

[qubes-devel] "Qubes Survey: The Results" by Marta Marczykowska-Górecka

2020-12-01 Thread Andrew David Wong
Dear Qubes Community, Marta Marczykowska-Górecka has just published an article covering the results of our recent survey: https://www.qubes-os.org/news/2020/11/26/qubes-survey-results/ For your convenience, the original plain text Markdown source of the article is reproduced below. However,

Re: [qubes-devel] Re: Seeking an additional HCL maintainer

2020-11-29 Thread Andrew David Wong
, but are not a good (docu-) writer and my programming experience is more embedded C (no Python and/or XEN knowledge). /Sven Fantastic, thank you! This is a huge help. :) -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you

Re: [qubes-devel] Re: Seeking an additional HCL maintainer

2020-11-26 Thread Andrew David Wong
On 11/25/20 1:56 PM, Sven Semmler wrote: On 11/25/20 6:05 AM, Andrew David Wong wrote: If you'd like to volunteer for this role, please let us know by replying to this thread or directly to me. Thank you! Started working on it: https://github.com/SvenSemmler/qubes-hcl/commits/master PR

[qubes-devel] Seeking an additional HCL maintainer

2020-11-25 Thread Andrew David Wong
-os.org/hcl/ [2] https://www.qubes-os.org/doc/hcl/#generating-and-submitting-new-reports [3] https://github.com/QubesOS/qubes-hcl -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-

[qubes-devel] Fedora 31 has reached EOL

2020-11-24 Thread Andrew David Wong
-os.org/doc/supported-versions/#note-on-dom0-and-eol This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/11/24/fedora-31-eol/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you

[qubes-devel] QSB #062: Stack corruption from XSA-346 change (XSA-355)

2020-11-24 Thread Andrew David Wong
://xenbits.xen.org/xsa/advisory-355.html -- The Qubes Security Team https://www.qubes-os.org/security/ ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/11/24/qsb-062/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org

Re: [qubes-devel] QSB #61 Information leak via power sidechannel (XSA-351)

2020-11-14 Thread Andrew David Wong
On 11/14/20 6:32 AM, Andrew Clausen wrote: Hi Andrew, On Sat, 14 Nov 2020 at 08:29, Andrew David Wong wrote: I have been meaning to update the Qubes documentation about this, but I have been a bit busy! Added. Thank you! https://github.com/QubesOS/qubes-doc/pull/1079/commits

Re: [qubes-devel] QSB #61 Information leak via power sidechannel (XSA-351)

2020-11-14 Thread Andrew David Wong
security bulletins should be signed with a Qubes project key? QSBs are already signed by individual Qubes Security Team members' Security Team keys, which are in turned signed by the Qubes Master Signing Key, so you already have the required chain of trust there. -- Andrew David Wong (Axon) Communi

Re: [qubes-devel] Travis-CI changes

2020-11-12 Thread Andrew David Wong
suggest using https://gitlab.com as opposed to hosting our own instance. Sincerely, Demi I agree with the GitLab CI option and using it in a way that minimizes the maintenance overhead to the greatest extent possible. -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes

[qubes-devel] Known bug: TemplateVM updates failing (fix in testing)

2020-11-09 Thread Andrew David Wong
pdates to migrate from testing to stable, please see: https://www.qubes-os.org/doc/testing/#updates -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group.

[qubes-devel] Qubes OS 4.0.4-rc1 has been released!

2020-11-05 Thread Andrew David Wong
is also available on the Qubes website: https://www.qubes-os.org/news/2020/11/05/qubes-4-0-4-rc1/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubs

[qubes-devel] Fedora 31 approaching EOL

2020-10-27 Thread Andrew David Wong
-os.org/doc/templates/#switching [9] https://www.qubes-os.org/doc/supported-versions/#note-on-dom0-and-eol This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/10/27/fedora-31-approaching-eol/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https

[qubes-devel] QSB #060: Multiple Xen issues (XSA-345, XSA-346, XSA-347)

2020-10-20 Thread Andrew David Wong
Dear Qubes Community, We have just published Qubes Security Bulletin (QSB) #060: Multiple Xen issues (XSA-345, XSA-346, XSA-347). The text of this QSB is reproduced below. This QSB and its accompanying signatures will always be available in the Qubes Security Pack (qubes-secpack). *Special

[qubes-devel] XSAs 286, 331, 332, and 345 do not affect the security of Qubes OS

2020-10-20 Thread Andrew David Wong
on the Qubes website: https://www.qubes-os.org/news/2020/10/20/xsa-286-331-332-345-qubes-not-affected/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To u

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-18 Thread Andrew David Wong
your audience. It's all about context. -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this group and stop receiving emails from it, send an em

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-17 Thread Andrew David Wong
On 10/16/20 11:17 AM, Chris Laprise wrote: On 10/16/20 5:56 AM, Andrew David Wong wrote: On 10/14/20 3:01 AM, Chris Laprise wrote: On 10/11/20 8:58 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-17 Thread Andrew David Wong
opic. I'd say the solution is common sense: If you're new, stick with the basic docs meant for new users. Don't go into the advanced section and expect to understand it yet. -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Andrew David Wong
On 10/14/20 3:01 AM, Chris Laprise wrote: On 10/11/20 8:58 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Oct 11, 2020 at 06:45:26PM -0500, Andrew David Wong wrote: On 10/11/20 11:16 AM, Marek Marczykowski-Górecki wrote: On Sat, Oct 10, 2020

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Andrew David Wong
documentation changes here: https://www.qubes-os.org/doc/doc-guidelines/ P.S. -- Please avoid top posting. Em domingo, 11 de outubro de 2020 às 13:16:43 UTC-3, marm...@invisiblethingslab.com escreveu: On Sat, Oct 10, 2020 at 09:50:00PM -0500, Andrew David Wong wrote: I still upgrade dom0

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-16 Thread Andrew David Wong
options see qubesctl --help Just a quick note: When I try to use --templates and --standalones at the same time, I get: "qubesctl: error: argument --standalones: not allowed with argument --templates" -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.o

Re: [qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-11 Thread Andrew David Wong
On 10/11/20 11:16 AM, Marek Marczykowski-Górecki wrote: On Sat, Oct 10, 2020 at 09:50:00PM -0500, Andrew David Wong wrote: I still upgrade dom0 and templates the old-fashioned way, because I'm used to it, I understand it, and I already have custom scripts for daily maintenance that include

[qubes-devel] Is it more secure to update dom0 and templates via Salt?

2020-10-10 Thread Andrew David Wong
new update method with a command like the ones above? Are there drop-in replacements that I can use in my scripts? (I vaguely recall that this question may have been asked before, but I can't find that thread now, so I figured I'd ask again. Besides, things may have changed in the meantim

[qubes-devel] Calling all humans! (from Nina)

2020-10-09 Thread Andrew David Wong
[The following message is from Nina Eleanor Alter, our UX specialist.] Greetings, Qubes community! We are running our first ever survey of current, former, and future Qubes OS users. We invite you all to lend us 10-15min of your time, to participate.

[qubes-devel] Re: Updated Split GPG documentation for Thunderbird 78

2020-10-07 Thread Andrew David Wong
On 10/7/20 3:47 AM, Andrew David Wong wrote: On 10/7/20 3:46 AM, Andrew David Wong wrote: Hi all, Many of us have recently upgraded to Thunderbird 78, which changes the way OpenPGP keys are handled. Thanks to Frédéric, the Split GPG documentation was updated a little over a week ago

[qubes-devel] Re: Updated Split GPG documentation for Thunderbird 78

2020-10-07 Thread Andrew David Wong
On 10/7/20 3:46 AM, Andrew David Wong wrote: Hi all, Many of us have recently upgraded to Thunderbird 78, which changes the way OpenPGP keys are handled. Thanks to Frédéric, the Split GPG documentation was updated a little over a week ago with detailed new instructions, including a full

[qubes-devel] Updated Split GPG documentation for Thunderbird 78

2020-10-07 Thread Andrew David Wong
with Thunderbird 78 and higher. If you haven't already seen it, take a look: https://www.qubes-os.org/doc/split-gpg/#using-thunderbird -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups

[qubes-devel] Article: "New Gentoo templates and maintenance infrastructure" by Frédéric Pierret

2020-10-05 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, Frédéric Pierret has just published the following article: https://www.qubes-os.org/news/2020/10/05/new-gentoo-templates-and-maintenance-infrastructure/ The plain text of this article is reproduced below.

[qubes-devel] Announcement: "Qubes OS contributed packages are now available" by Marek Marczykowski-Górecki

2020-10-05 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, Marek has just published the following announcement: https://www.qubes-os.org/news/2020/10/05/qubes-os-contributed-packages/ The plain text of this announcement is reproduced below.

Re: [qubes-devel] Fresh minimal template already has shell history: sudo mkfs.ext4 /dev/xvdi

2020-10-01 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2020-10-01 1:47 AM, Jean-Philippe Ouellet wrote: > On Wed, Sep 30, 2020 at 1:07 PM Andrew David Wong > wrote: >> On a freshly-downloaded fedora-31-minimal template, I noticed >> that the user account already has one co

[qubes-devel] Fresh minimal template already has shell history: sudo mkfs.ext4 /dev/xvdi

2020-09-30 Thread Andrew David Wong
curious why that happened to this minimal template before I even downloaded it. Is this part of the developers' process in preparing the template for users? - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

Re: [qubes-devel] [GSoD] Progress, plans and feedback request

2020-09-22 Thread Andrew David Wong
w timeline > soon, depending on how this and next week goes. > > *Refined TROUBLESHOOTING GUIDE layout* > > [...] - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBC

[qubes-devel] QSB #059: Multiple Xen issues (XSA-337, XSA-340, XSA-343)

2020-09-22 Thread Andrew David Wong
site: https://www.qubes-os.org/news/2020/09/22/qsb-059/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl9qE38ACgkQ203TvDlQ MDDesA/8C3/RhsCOJPGGytJEBkvgpa

[qubes-devel] XSAs 333, 334, 336, 338, 339, 342, and 344 do not affect the security of Qubes OS

2020-09-22 Thread Andrew David Wong
/#342 https://www.qubes-os.org/security/xsa/#344 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/09/22/xsa-333-334-336-338-339-342-344-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP

[qubes-devel] Get paid to support Qubes development through automated testing! (three-month contract)

2020-09-20 Thread Andrew David Wong
/viewRequisition?org=INTERNEWS=38=1186 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/09/20/get-paid-to-support-qubes-development-through-automated-testing/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP

[qubes-devel] Qubes Canary #24

2020-09-10 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, We have published Qubes Canary #24. The text of this canary is reproduced below. This canary and its accompanying signatures will always be available in the Qubes Security Pack (qubes-secpack). View Qubes Canary #24 in the

[qubes-devel] XSA-335 does not affect the security of Qubes OS

2020-08-24 Thread Andrew David Wong
/security/xsa/#335 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/08/24/xsa-335-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] Announcement: New community forum for Qubes OS users!

2020-08-20 Thread Andrew David Wong
icial-chat-channels [5] https://www.reddit.com/r/Qubes/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/08/20/new-community-forum-for-qubes-os-users/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP

Re: [qubes-devel] Are you guys looking for help in editing/creating technical docs?

2020-08-07 Thread Andrew David Wong
Please see this page for all the details: https://www.qubes-os.org/doc/doc-guidelines/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl8s+3wACgkQ203TvDlQ MDDXc

[qubes-devel] Internews short-term consultant opportunity

2020-07-26 Thread Andrew David Wong
://chm.tbe.taleo.net/chm04/ats/careers/v2/viewRequisition?org=INTERNEWS=38=1186 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl8ePVQACgkQ203TvDlQ MDAPpA//TTOQBzFwzT1x/XHAZB2S56tTxWhiiXZ2gaLz3RoUI9GBNf

[qubes-devel] XSA-329 does not affect the security of Qubes OS

2020-07-16 Thread Andrew David Wong
/security/xsa/#329 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/07/16/xsa-329-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] Re: new issue template "support / question"

2020-07-14 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2020-07-13 9:54 PM, Marek Marczykowski-Górecki wrote: > On Sat, May 23, 2020 at 11:16:13AM -0500, Andrew David Wong wrote: >> On 2020-05-23 7:48 AM, Marek Marczykowski-Górecki wrote: >>> Hi Andrew, >>> >>>

[qubes-devel] XSAs 317, 319, 327, and 328 do not affect the security of Qubes OS

2020-07-07 Thread Andrew David Wong
/news/2020/07/07/xsa-317-319-327-328-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl8EgO8ACgkQ203TvDlQ MDDesxAAqtWf0jMOHXTDDN5jZHa0p0R9W6dTqNpR2xDYO/2ZtYUlXNs9YrUnclvA

[qubes-devel] QSB #058: Insufficient cache write-back under VT-d (XSA-321)

2020-07-07 Thread Andrew David Wong
/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-deve

[qubes-devel] Fedora 32 TemplateVMs available

2020-06-30 Thread Andrew David Wong
-available/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl77HWkACgkQ203TvDlQ MDBEjA/+KvqIijaKuin+U2u3Yanv1JoIMOAIycxDP8bKfmQKdilAJx+Ga8uTDHmR

[qubes-devel] "Qubes Architecture Next Steps: The New Qrexec Policy System" by Marek Marczykowski-Górecki & Marta Marczykowska-Górecka

2020-06-22 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, A new article has just been published on the Qubes website: "Qubes Architecture Next Steps: The New Qrexec Policy System" by Marek Marczykowski-Górecki & Marta Marczykowska-Górecka

[qubes-devel] QSB #057: Special Register Buffer speculative side channel (XSA-320)

2020-06-11 Thread Andrew David Wong
/security/ ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/06/11/qsb-057/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

Re: [qubes-devel] organising github-issues

2020-06-04 Thread Andrew David Wong
logical operator "OR", but it does allow excluding labels by prepending a minus sign ("-"). Since every open issue that I've triaged should have a priority label ("P:[...]"), we can exclude all the priority labels we don't want. So, to use your example, the s

[qubes-devel] Re: new issue template "support / question"

2020-05-23 Thread Andrew David Wong
gt; What do you think of adding similar one, pointing at mailing list > or simply https://www.qubes-os.org/support/ ? > Good idea. I'll add this. - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH120

[qubes-devel] Google Summer of Code & Season of Docs 2020

2020-05-23 Thread Andrew David Wong
/season-of-docs/docs/timeline [7] https://www.qubes-os.org/gsod/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/05/23/google-summer-of-code-and-season-of-docs-2020/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org

[qubes-devel] Qubes awarded MOSS Mission Partners grant!

2020-05-22 Thread Andrew David Wong
s.org/team/#frédéric-pierret [3] https://www.qubes-os.org/team/#nina-eleanor-alter [4] https://www.mozilla.org/en-US/moss/mission-partners/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/05/22/moss-mission-partners-grant/ - -- Andrew David Wong (Axon)

[qubes-devel] Fedora 30 approaching EOL, Fedora 31 TemplateVM available, Fedora 32 TemplateVM in testing

2020-04-30 Thread Andrew David Wong
/templates/#switching [6] https://www.qubes-os.org/doc/testing/#providing-feedback This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/04/30/fedora-31-template-available/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org

[qubes-devel] XSAs 313, 314, 316, and 318 do not affect the security of Qubes OS

2020-04-15 Thread Andrew David Wong
/news/2020/04/15/xsa-313-314-316-318-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl6W10wACgkQ203TvDlQ MDAukRAAlLMv7+tEiSO9ue4ahy84jzu6vNojWLBr+uFCVU0/Fri4bBngzg2ZJ4lG

[qubes-devel] Qubes Canary #23

2020-04-15 Thread Andrew David Wong
ify the digital signatures! ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/04/15/canary-23/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNAT

Re: [qubes-devel] Re: "Qubes Architecture Next Steps: The GUI Domain" by Marek Marczykowski-Górecki & Marta Marczykowska-Górecka

2020-04-04 Thread Andrew David Wong
f luck in this difficult >> endeavor! >> > > Who is leading this charge? I would love to help or watch them in > the process. > I've been told that they plan to post their results to this mailing list soon. - -- Andrew David Wong (Axon) Community Manager, Qubes OS ht

[qubes-devel] "Qubes Architecture Next Steps: The GUI Domain" by Marek Marczykowski-Górecki & Marta Marczykowska-Górecka

2020-03-18 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, A new article has just been published on the Qubes website: "Qubes Architecture Next Steps: The GUI Domain" by Marek Marczykowski-Górecki & Marta Marczykowska-Górecka https://www.qubes-os.org/news/2020/03/18/gui-domain/ The

[qubes-devel] XSA-315 does not affect the security of Qubes OS

2020-03-12 Thread Andrew David Wong
/security/xsa/#315 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/03/12/xsa-315-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] Announcement: NitroPad X230 passes hardware certification for Qubes 4.0!

2020-03-04 Thread Andrew David Wong
-certification/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl5fqc0ACgkQ203TvDlQ MDCnpxAAzgjT1Vi3sICEtkPPC7v6FxsNUClYhj2V6308T+obEyu+GTTXYBgEooPX Hrq/TzCXDvVUBGaYuT7kcymfCYpzFmKZAfBfV

[qubes-devel] Qubes OS 4.0.3 has been released!

2020-01-23 Thread Andrew David Wong
/news/2020/01/23/qubes-4-0-3/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl4paCEACgkQ203TvDlQ MDDzoxAAvZtWxKGs2T3qM0U1w0NstEp5amxj5WjkUlCW5Vf45+QZXfnH9fXeI7gb 1LtpluKpc8SEQMLR+tch61c

[qubes-devel] XSA-312 does not affect the security of Qubes OS

2020-01-16 Thread Andrew David Wong
/security/xsa/#312 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/01/15/xsa-312-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] Qubes OS 4.0.3-rc1 has been released!

2020-01-15 Thread Andrew David Wong
/qubes-4-0-3-rc1/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl4e/oMACgkQ203TvDlQ MDCqPw//ddfW08ObnL76ed87v0fkDLvViiC1S72udxlettb7pvhkIBv8emKE7YTR Sm4Wl9AkV

[qubes-devel] Qubes Canary #22

2020-01-15 Thread Andrew David Wong
res on the corresponding qubes-secpack.git repo tags. [2] [2] Don't just trust the contents of this file blindly! Verify the digital signatures! ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/01/15/canary-22/ - -- Andrew David Wong (Axon) Community Manager, Qu

[qubes-devel] Re: Qubes 4.0.3-rc1

2020-01-15 Thread Andrew David Wong
nly about final 4.0.3? > I think an announcement is still a good idea so that people know it's available for testing. I'll publish one now. - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl4e7

[qubes-devel] Re: Qubes OS 4.0.2 has been released!

2020-01-08 Thread Andrew David Wong
for the majority of users, we have temporarily removed it from the Downloads page and reinstated the latest release candidate (Qubes 4.0.2-rc3) in its place. On 2020-01-02 8:21 PM, Andrew David Wong wrote: > Dear Qubes Community, > > We're pleased to announce the release of Qu

Re: [qubes-devel] Qubes 4.0.2 severe issue - dom0 kernel crash

2020-01-04 Thread Andrew David Wong
ithub.com/QubesOS/qubes-issues/issues/5529#issuecomment-569312158 > The semantic versioning standard recommended by semver.org would suggest "R4.0.3". - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAd

[qubes-devel] Qubes OS 4.0.2 has been released!

2020-01-02 Thread Andrew David Wong
-guide/#copying-the-iso-onto-the-installation-medium [4] https://www.qubes-os.org/doc/reporting-bugs/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2020/01/02/qubes-4-0-2/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org

[qubes-devel] Qubes OS 4.0.2-rc3 has been released!

2019-12-13 Thread Andrew David Wong
/2019/12/13/qubes-4-0-2-rc3/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl3zp/4ACgkQ203TvDlQ MDDgVBAAo9cBaha4M9U3sDCFQsHHLN/XwJBY0kVNoI/reOLO3GLSRSyTh9lIiZC3

[qubes-devel] XSAs 307, 308, and 309 do not affect the security of Qubes OS

2019-12-13 Thread Andrew David Wong
/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl3zgAYACgkQ203TvDlQ MDAoOA//fkRL2DXYm7JYMk7gLEXu3SYdtaMg/Q/mI1HTY4qpERKY+FJepnRoKmJk YWHN0ZnC/hkX5ERxJcntJxo6NTaIqPY5Xs

[qubes-devel] Fedora 29 has reached EOL

2019-11-29 Thread Andrew David Wong
] https://www.qubes-os.org/doc/supported-versions/#note-on-dom0-and-eol This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/11/29/fedora-29-eol/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] QSB #054: Xen fix for XSA-302 found ineffective in Qubes configuration (XSA-306)

2019-11-26 Thread Andrew David Wong
Dear Qubes Community, We have just published Qubes Security Bulletin (QSB) #054: Xen fix for XSA-302 found ineffective in Qubes configuration (XSA-306). The text of this QSB is reproduced below. This QSB and its accompanying signatures will always be available in the Qubes Security Pack

Re: [qubes-devel] QSB #52: Xen issues affecting PCI passthrough and PV domains (XSA-299, XSA-302)

2019-11-19 Thread Andrew David Wong
incorrect key to verify it? > > Sincerely, > > Demi > It verifies correctly for me via Enigmail 2.1.2 on Thunderbird 68.1.1. As a reminder, you can always verify QSBs via the Qubes Security Pack: https://www.qubes-os.org/security/pack/ - -- Andrew David Wong (Axon) Community M

[qubes-devel] QSB #053: TSX Asynchronous Abort speculative side channel (XSA-305)

2019-11-14 Thread Andrew David Wong
-305.html - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/11/13/qsb-053/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] XSA-304 does not affect the security of Qubes OS

2019-11-14 Thread Andrew David Wong
/security/xsa/#304 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/11/13/xsa-304-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

Re: [qubes-devel] GuiVM window title prefix

2019-11-05 Thread Andrew David Wong
ized. I presume "GuiVM" is capitalized this way to distinguish the "GUI" and "VM" parts. One alternative is to use something like "GUI Qube" or "GUI Domain" instead. Also, if you want to include the actual VM name, you could do so in parentheses, e.g.

[qubes-devel] Qubes OS 4.0.2-rc2 has been released!

2019-11-03 Thread Andrew David Wong
-bugs/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/11/03/qubes-4-0-2-rc2/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl2

[qubes-devel] XSAs 296, 298, 301, and 303 do not affect the security of Qubes OS

2019-10-31 Thread Andrew David Wong
/news/2019/10/31/xsa-296-298-301-303-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl27n7UACgkQ203TvDlQ MDChBA/7BbDaZClar2zTHk3VXfcn8i1nvsqaoK3JaUtEmPvDYujoUHjdB46yu9Ww

Re: [qubes-devel] Changelogs

2019-10-23 Thread Andrew David Wong
elease notes, which are available here: https://www.qubes-os.org/doc/releases/notes/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl2v8RU

[qubes-devel] Qubes Canary #21 (signed email)

2019-10-14 Thread Andrew David Wong
y! Verify the digital signatures! ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/10/13/canary-21/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDA

[qubes-devel] Qubes Canary #21

2019-10-14 Thread Andrew David Wong
/2019/10/13/canary-21/ -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -- You received this message because you are subscribed to the Google Groups "qubes-devel" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-dev

Re: [qubes-devel] backup of dom0

2019-09-30 Thread Andrew David Wong
what is missed by the official restore > process. > You are correct. There's an open issue to include some of the other items you listed: https://github.com/QubesOS/qubes-issues/issues/1635 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN P

Re: [qubes-devel] Can’t configure network so as to connect to Internet

2019-09-18 Thread Andrew David Wong
end these sorts of questions to the qubes-users mailing list rather than qubes-devel. (I moved your previous thread, linked above, from qubes-devel to qubes-users.) You can read more about the different mailing lists here: https://www.qubes-os.org/support/ - -- Andrew David Wong (Axon) Commun

[qubes-devel] Upcoming Qubes presentations at Platform Security Summit 2019

2019-09-17 Thread Andrew David Wong
o-privacybeast-qubes-certification/ [8] https://www.qubes-os.org/doc/certified-hardware/#qubes-certified-laptop-insurgo-privacybeast-x230 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/09/18/qubes-presentations-at-platform-security-summit-2019/ - -- And

[qubes-devel] Reminder: Please help test new updates and provide feedback!

2019-08-28 Thread Andrew David Wong
tant as the negative feedback, since this helps us decide when it's okay to migrate packages to stable. This results in a faster development cycle for Qubes and a better experience for everyone. Thank you for contributing! - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os

Re: [qubes-devel] Re: AEM

2019-08-23 Thread Andrew David Wong
ere another copy somewhere ? > > https://github.com/QubesOS/qubes-antievilmaid > Link fixed. - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFA

[qubes-devel] Announcing our 2019 Season of Docs project: Onboard with Qubes OS!

2019-08-07 Thread Andrew David Wong
rticipants/project-qubes [4] https://www.qubes-os.org/doc/doc-guidelines/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/08/07/announcing-our-2019-season-of-docs-project/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qu

[qubes-devel] [Update] QSB #050: Reinstalling a TemplateVM does not reset the private volume

2019-08-01 Thread Andrew David Wong
- -- The Qubes Security Team https://www.qubes-os.org/security/ ``` This announcement has also been updated on the Qubes website: https://www.qubes-os.org/news/2019/07/24/qsb-050/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] QSB #050: Reinstalling a TemplateVM does not reset the private volume

2019-07-24 Thread Andrew David Wong
-linux/commit/552fd062ea2bb6c2d05faa1e64e172503cacbdbf#diff-6b87ee5cdb9e63b703415a14e5a505cdL192 - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/07/24/qsb-050/ - -- Andrew David Wong

[qubes-devel] Announcement: Insurgo PrivacyBeast X230 Laptop meets and exceeds Qubes 4.0 hardware certification

2019-07-18 Thread Andrew David Wong
website: https://www.qubes-os.org/news/2019/07/18/insurgo-privacybeast-qubes-certification/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl0xRMEACgkQ203TvDlQ MDAEVQ

<    1   2   3   4   5   6   >