[qubes-devel] Qubes OS 4.0.2-rc1 has been released!

2019-07-10 Thread Andrew David Wong
/reporting-bugs/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/07/09/qubes-4-0-2-rc1/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] XSA-300 does not affect the security of Qubes OS

2019-07-10 Thread Andrew David Wong
/security/xsa/#300 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl0lmDoACgkQ203TvDlQ MDBOcBAAwaKiAqCKO8Y6MWztvdQx5qYFN9bFYeuxiom6WyZWghT6Ga3M3MDE0VGt F1lGEIs4sQgJiXhIizWWnGq4tPKMbQ/wQfCQ

[qubes-devel] Qubes Canary #20

2019-07-04 Thread Andrew David Wong
] Don't just trust the contents of this file blindly! Verify the digital signatures! ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/07/04/canary-20/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -B

[qubes-devel] Whonix 15 has been released

2019-07-01 Thread Andrew David Wong
ps://www.qubes-os.org/news/2019/07/01/whonix-15-has-been-released/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAl0axvkACgkQ203TvDlQ MDA1bQ/6ArxTBwZFUDs/Y8tAafPkKNcDbYOfUg0r4zx

[qubes-devel] Marek Marczykowski-Górecki to speak at Xen Developer and Design Summit 2019

2019-06-27 Thread Andrew David Wong
-journey-to-mirage-os-as-xen-pvh-marek-marczykowski-gorecki-invisible-things-lab This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/06/27/marek-marczykowski-gorecki-xen-summit-2019/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.

[qubes-devel] Announcement: Fedora 30 TemplateVM available

2019-06-01 Thread Andrew David Wong
/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlzy4B4ACgkQ203TvDlQ MDCgTw//Yn4xHJxAIhGq6PgZW99FwAz+5/lI8JYy0H62aC5ngZG7MnNrRlw/+cx9 YtdtCXF

[qubes-devel] Fedora 28 has reached EOL

2019-05-29 Thread Andrew David Wong
/templates/fedora/#installing [5] https://www.qubes-os.org/doc/supported-versions/#note-on-dom0-and-eol This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/05/29/fedora-28-eol/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes

Re: [qubes-devel] Add Spectre-Meltdown-checker by default (important package)

2019-05-25 Thread Andrew David Wong
>>> >>> Maybe I'm wrong but it is just adding another tool for checking what it >>> should be done elsewhere. >>> >>> Best, >>> >>> On 5/25/19 3:13 AM, bo0od wrote: >>> >>>> This is very important package missed in

[qubes-devel] Looking for help with a Qubes crowdfunding campaign

2019-05-11 Thread Andrew David Wong
or legwork. Please send an email to Michael and me if you're interested. Thank you! - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlzWe8wACgkQ203TvDlQ

Re: [qubes-devel] documentation / GSoD & others

2019-04-23 Thread Andrew David Wong
n't specific to Qubes OS" by saying that we shouldn't even have such documents. I agree insofar as it doesn't make sense for us to write and maintain documentation about non-Qubes stuff when we still have so much work to do writing and maintaining Qubes documentation. However, your point that

Re: [qubes-devel] Re: [qubes-project] Re: Google "Season of Docs" -- deadline April 22

2019-04-21 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 19/04/2019 10.15 PM, Andrew David Wong wrote: > On 19/04/2019 1.12 AM, Michael Carbone wrote: >> On 3/20/19 3:53 PM, Michael Carbone wrote: >>> On 3/15/19 3:27 AM, Andrew David Wong wrote: >>>> On 14/03/2019

Re: [qubes-devel] documentation / GSoD & others

2019-04-21 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 21/04/2019 12.37 PM, Ivan Mitev wrote: > > > On 4/20/19 9:59 PM, Andrew David Wong wrote: >> On 20/04/2019 10.45 AM, Ivan Mitev wrote: >>> re- "Google "Season of Docs" -- deadline April 22" >&

Re: [qubes-devel] documentation / GSoD & others

2019-04-20 Thread Andrew David Wong
ing the *content* of the documentation is an important goal that is largely orthogonal to improving our documentation contribution workflow. We can find temporary ways to make it easier for GSoD contributors while we work on this workflow issue in parallel. Let's not allow th

[qubes-devel] Re: [qubes-project] Re: Google "Season of Docs" -- deadline April 22

2019-04-19 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 19/04/2019 1.12 AM, Michael Carbone wrote: > On 3/20/19 3:53 PM, Michael Carbone wrote: >> On 3/15/19 3:27 AM, Andrew David Wong wrote: >>> On 14/03/2019 8.28 AM, Michael Carbone wrote: >>>> https://opensource.goog

[qubes-devel] Announcement: Qubes Tor onion services are available again!

2019-04-17 Thread Andrew David Wong
bes-os.org/news/2018/01/23/qubes-whonix-next-gen-tor-onion-services/ [2] https://www.whonix.org/wiki/Onionizing_Repositories This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/04/17/tor-onion-services-available-again/ - -- Andrew David Wong (Axon) Communi

[qubes-devel] Qubes Canary #19

2019-04-08 Thread Andrew David Wong
k.git repo, and (2) via digital signatures on the corresponding qubes-secpack.git repo tags. [2] [2] Don't just trust the contents of this file blindly! Verify the digital signatures! ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/04/08/canary-19/

[qubes-devel] Update on Frédéric's recent kernel-related work

2019-04-06 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, Frédéric has given me permission to share this update about the great work he has recently been doing. - Forwarded Message Subject: Summary about recent work Date: Sat, 6 Apr 2019 17:37:36 +0200 From:

[qubes-devel] Announcement: Qubes OS 3.2 has reached EOL

2019-03-27 Thread Andrew David Wong
-and-the-future [6] https://www.qubes-os.org/news/2018/02/20/qubes-3-2-approaching-eol This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/03/28/qubes-3-2-has-reached-eol - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN

[qubes-devel] Announcement: Qubes Tor onion services will no longer be maintained

2019-03-24 Thread Andrew David Wong
available on the Qubes website: https://www.qubes-os.org/news/2019/03/24/tor-onion-services-no-longer-maintained/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlyYIQ8ACgkQ203TvDlQ MDDCfg

Re: [qubes-devel] New page with packages status

2019-03-19 Thread Andrew David Wong
in builder-github repository[2] (status-head.html > file). > > [1] https://github.com/QubesOS/updates-status/issues > [2] > https://github.com/QubesOS/qubes-builder-github/blob/master/templates/status-head.html > Nice, thanks! Is there any way we could add timestamps, perhaps i

[qubes-devel] Re: QubesOS 4.1 status

2019-03-05 Thread Andrew David Wong
updates here, and he may reply to you directly if he has time.) - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlx/KxgACgkQ203TvDlQ MDA7Pg//Ry/U00ZGVjRSo8SP3NqPkJRW4EY1+EAjika2

[qubes-devel] XSAs 284, 290, 291, 293, and 294 do not affect the security of Qubes OS

2019-03-05 Thread Andrew David Wong
available on the Qubes website: https://www.qubes-os.org/news/2019/03/05/xsa-284-290-291-293-294-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlx+neUACgkQ203TvDlQ

[qubes-devel] QSB #048: Multiple Xen vulnerabilities

2019-03-05 Thread Andrew David Wong
xen.org/xsa/advisory-288.html [4] https://xenbits.xen.org/xsa/advisory-292.html [5] https://www.qubes-os.org/doc/assigning-devices/ - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/03/0

[qubes-devel] Qubes OS 3.2 approaching EOL on 2019-03-28

2019-02-20 Thread Andrew David Wong
] https://www.qubes-os.org/downloads/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/02/20/qubes-3-2-approaching-eol/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

Re: [qubes-devel] Qubes 4.x Backup setting should not be set to save (replace) default settings by default

2019-02-13 Thread Andrew David Wong
is what one wants as > default: To actually save the new settings (loose/replace the last > default..) without making a concious choice, so for that reason > alone it should not be checked. > Please file an issue for this: https://www.qubes-os.org/doc/reporting-bugs/ - -- An

Re: [qubes-devel] More regular point releases schedule?

2019-02-06 Thread Andrew David Wong
ed with Qubes and makes it easier for existing users to upgrade. However, as others have pointed out, this benefit doesn't require *rapid* point releases, and there is little to be gained by trying to stick to a rigid schedule. Event-driven at roughly six-month intervals sounds fine. - -- Andrew

Re: [qubes-devel] apt RCE

2019-01-23 Thread Andrew David Wong
hanism that is currently missing in all distributions. In short: >> distributions have no mechanism to communicate with their users >> effectively in situations such as this one. More info: > >> https://www.whonix.org/wiki/Dev/project-news > > I think having something l

[qubes-devel] What is the point of qubes.StartApp?

2019-01-21 Thread Andrew David Wong
pplication via a maliciously crafted >> .desktop file). > > Relevant code here: > https://github.com/QubesOS/qubes-desktop-linux-common/blob/a7bba5a3901d142185702060ab64dbb33bf4bd9e/qubesappmenus/receive.py#L271-L279 > > Note that StartApp+arg is constructed in dom0 with stricter &g

[qubes-devel] XSA-289 does not affect the security of Qubes OS

2019-01-21 Thread Andrew David Wong
. This XSA has been added to the XSA Tracker. [2] [1] https://www.qubes-os.org/news/2018/09/02/qsb-43/ [2] https://www.qubes-os.org/security/xsa/#289 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2019/01/21/xsa-289-qubes-not-affected/ - -- Andrew David Wong

[qubes-devel] Re: 2019 Google Summer of Code? (deadline Feb 6)

2019-01-21 Thread Andrew David Wong
for this last week: https://groups.google.com/d/msgid/qubes-project/20190116180933.GE1292%40mail-itl - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlxFtdcACgkQ203TvDlQ MDCyhg//ZVV

[qubes-devel] What is the point of qubes.StartApp?

2019-01-20 Thread Andrew David Wong
explains this, and a search didn't turn up any relevant ML threads. - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlxE/hYACgkQ203TvDlQ MDDaKRAAxAiVwkpsRMwRcKVittZUBCY+4bNQ+xjMTHrsuCWkAac

Re: [qubes-devel] Re: Password encryption for individual vm's

2019-01-19 Thread Andrew David Wong
a can be stolen) > [...] We actually have an open issue for this: https://github.com/QubesOS/qubes-issues/issues/1293 (I didn't see this mentioned in your message, so you may not be aware of it.) - -- Andrew David Wong (Axon) Community Manager, Qubes OS https

Re: [qubes-devel] Documentation: https://www.qubes-os.org/doc/split-gpg/

2019-01-14 Thread Andrew David Wong
s get updated!) So, if you'd like to get involved with the project, this is a great way to do it. You can read more about how to submit documentation changes here: https://www.qubes-os.org/doc/doc-guidelines/ - -- Andrew David Wong (A

Re: [qubes-devel] Feature request: Encrypted guest VMs using loop-aes?

2019-01-10 Thread Andrew David Wong
; the loop driver (there is also a kernel module for it). > > Could you help to implement it? > > Cheers, > > Ludwig > You may want to take a look at this issue: https://github.com/QubesOS/qubes-issues/issues/1293 - -- Andrew David Wong (Axon) Community

[qubes-devel] Fedora 29 TemplateVM available for Qubes 4.0

2019-01-07 Thread Andrew David Wong
-template-available/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlw0HzcACgkQ203TvDlQ MDADmQ/9EWZs8+2wx/yN4gHSGHPBd79EtpF3oN3FoXB6Edhl0dniOjuenyhuWhEv Q

[qubes-devel] Qubes OS 4.0.1-rc2 has been released!

2018-12-18 Thread Andrew David Wong
/news/2018/12/18/qubes-401-rc2/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlwZ2joACgkQ203TvDlQ MDBFcA/8COFybMGZlmd5hzyyRbx3iD7O4bjOOVsS+B7WpmLf1FMsQoXknxMqZTF

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-11 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 12/11/18 6:21 AM, Chris Laprise wrote: > On 12/10/2018 08:27 PM, Andrew David Wong wrote: >> On 12/10/18 11:57 AM, Chris Laprise wrote: >>> On 12/10/2018 05:23 AM, Ivan Mitev wrote: >>>> That's really great work

Re: [qubes-devel] ANN: Fast incremental backups project

2018-12-10 Thread Andrew David Wong
arsebak and run backup sessions. The next step is including > VM settings along with the volumes in the backups, and integrating > encryption so the user doesn't feel compelled to setup a destination > LUKS volume. > Looks great, Chris! Would you be willing to submi

Re: [qubes-devel] Dropping support for old templates

2018-12-06 Thread Andrew David Wong
. But as Patrick said, it >> makes it difficult to maintain. Especially since Debian 8 is >> much older than oldest supported Fedora... >> >> This already lead to one major problem: >> https://github.com/QubesOS/qubes-issues/issues/4443 >&g

[qubes-devel] QSB #45: Insecure default Salt configuration

2018-12-03 Thread Andrew David Wong
ment is also available on the Qubes website: https://www.qubes-os.org/news/2018/12/03/qsb-45/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlwGEq0ACgkQ203TvDlQ MDDZLQ/9E/Hyg6/v7GoOyY

Re: [qubes-devel] Dropping support for old templates

2018-11-30 Thread Andrew David Wong
distro in a sense. >> > > Completely agree with Chris. We should maintain oldstable throughout > LTS for Debian. > Whonix 13 already lacks suport from WhonixQubes, so perhaps it should > be dropped from Qubes support also - although

[qubes-devel] Fedora 27 has reached EOL

2018-11-30 Thread Andrew David Wong
/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlwCAlMACgkQ203TvDlQ MDBdqxAAoSjAP36xt0Is/bJPjUifzGR65d5hYVaQFVirQIXYYA0y7Mc35ZeCuzH5 4E66s

[qubes-devel] XSA-276, XSA-277, and XSA-279 do not affect the security of Qubes OS

2018-11-20 Thread Andrew David Wong
/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlv0yhMACgkQ203TvDlQ MDAcQA//Qj5Qk5VDED0mvUOBAoFl6EeQApBCPBDBosh6ORlazfQNSX1m0SvTwjck CheHiTBtW7qVjPafK

[qubes-devel] XSA-282 does not affect the security of Qubes OS

2018-11-06 Thread Andrew David Wong
/security/xsa/#282 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/11/06/xsa-282-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] Qubes OS 4.0.1-rc1 has been released!

2018-11-05 Thread Andrew David Wong
/doc/reporting-bugs/ [3] https://www.qubes-os.org/news/2018/10/05/qubes-321-rc1/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/11/05/qubes-401-rc1/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP

[qubes-devel] Qubes Security Team Update

2018-11-05 Thread Andrew David Wong
] https://www.qubes-os.org/team/#simon-gaiser-aka-hw42 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/11/05/qubes-security-team-update/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] A message from Marek Marczykowski-Górecki

2018-10-25 Thread Andrew David Wong
-workstation/ [Let's Encrypt]: https://twitter.com/RMLLsec16/status/749982515948027904 ``` - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlvSe88ACgkQ203TvDlQ

[qubes-devel] XSA-278 does not affect the security of Qubes OS

2018-10-24 Thread Andrew David Wong
/security/xsa/#278 This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/10/24/xsa-278-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] Qubes Canary #17

2018-10-15 Thread Andrew David Wong
signatures! ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/10/15/canary-17/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

Re: [qubes-devel] VM kernel panic on resume

2018-10-08 Thread Andrew David Wong
suspend/resume > for sure, but not sure exactly when it happens . Now I was able to > get the logs, in a hope that somebody can help to resolve it. > > Thanks. > Is it this same issue? https://github.com/QubesOS/qubes-issues/issues/3657 - -- Andrew David Wong (Axon) Com

[qubes-devel] Re: dom0 update for ppc64le support

2018-09-26 Thread Andrew David Wong
infrastructure for the mailing lists, and many people use the mailing lists without having Google accounts: https://www.qubes-os.org/support/#mailing-lists-vs-forums - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGI

[qubes-devel] Whonix version support policy

2018-09-13 Thread Andrew David Wong
/#whonix This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/09/13/whonix-version-support-policy/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] "Introducing the Qubes U2F Proxy" by Wojtek Porczyk

2018-09-11 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, Wojtek Porczyk has just published a new article titled "Introducing the Qubes U2F Proxy." The article is available on the Qubes website: https://www.qubes-os.org/news/2018/09/11/qubes-u2f-proxy/ - -- Andrew

[qubes-devel] QSB #43: L1 Terminal Fault speculative side channel (XSA-273)

2018-09-01 Thread Andrew David Wong
https://www.qubes-os.org/news/2018/09/02/qsb-43/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAluLWG8ACgkQ203TvDlQ MDBaFw/9FEA1pX0sxe7znUF3+waSNQ0HYW

Re: [qubes-devel] XSA-273 - security impact on Qubes?

2018-08-26 Thread Andrew David Wong
help but notice it's absence from > the Qubes XSA-tracker page (2). > Already addressed: https://groups.google.com/d/msg/qubes-users/Isn_hko7tQs/PcqIuUleEQAJ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org ---

[qubes-devel] Whonix 13 approaching EOL

2018-08-24 Thread Andrew David Wong
://www.qubes-os.org/news/2018/08/24/whonix-13-approaching-eol/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAluA5D0ACgkQ203TvDlQ MDBlmA//Vdkl2E+uxZMOJtIItg7aX95nfkGOFJXkNGBATIA325c

[qubes-devel] XSA-268, XSA-269, XSA-271, and XSA-272 do not affect the security of Qubes OS

2018-08-14 Thread Andrew David Wong
/news/2018/08/14/xsa-268-269-271-272-qubes-not-affected/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAltzKcwACgkQ203TvDlQ MDB9RA/+JGQLlCyOTw23zngxwT28f/yzl+hgE00maX1jgFayL500ErCjTttBpqez

Re: [qubes-devel] Inter-qube text copy/paste loses some (but not all) Unicode chars

2018-08-10 Thread Andrew David Wong
text from it. > > Ninja'd by Ryan Tate on qubes-users: > qubes clipboard mangles text character (emdash) > https://github.com/QubesOS/qubes-issues/issues/2845 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzB

Re: [qubes-devel] QSB #40: Information leaks due to processor speculative store bypass (XSA-263)

2018-05-25 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-05-25 09:45, Simon Gaiser wrote: > Marek Marczykowski-Górecki: >> On Fri, May 25, 2018 at 02:23:00AM +, Simon Gaiser wrote: >>> Andrew David Wong: >>>> ---==

Re: [qubes-devel] Fedora 26 and Debian 8 approaching EOL

2018-05-24 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-05-24 04:18, Holger Levsen wrote: > On Wed, May 23, 2018 at 08:21:12PM -0500, Andrew David Wong wrote: >> Fedora 26 will reach EOL ([end-of-life]) on 2018-06-01, and Debian 8 >> (["Jessie" full, not LTS][debian-

[qubes-devel] QSB #40: Information leaks due to processor speculative store bypass (XSA-263)

2018-05-24 Thread Andrew David Wong
website: https://www.qubes-os.org/news/2018/05/24/qsb-40/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlsHTIcACgkQ203TvDlQ MDCoHw//dx+GcN8QIz0ww1tUQZufTaDwSy0eiY

[qubes-devel] Re: Fedora 26 and Debian 8 approaching EOL

2018-05-23 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-05-23 20:21, Andrew David Wong wrote: > Dear Qubes Community, > > Fedora 26 will reach EOL ([end-of-life]) on 2018-06-01, and Debian 8 > (["Jessie" full, not LTS][debian-releases]) will reach EOL on > 2018-06-

[qubes-devel] Fedora 26 and Debian 8 approaching EOL

2018-05-23 Thread Andrew David Wong
/supported-versions/#note-on-dom0-and-eol This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/05/23/fedora-26-and-debian-8-approaching-eol/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP

[qubes-devel] QSB #39: Xen vulnerability (XSA-260) and GUI daemon issue

2018-05-08 Thread Andrew David Wong
/ ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/05/08/qsb-39/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlryTJAACgkQ203TvDlQ MDAbYw

[qubes-devel] Re: Announcement: Parts of the Qubes OS website are temporarily down

2018-04-30 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-04-30 08:54, Andrew David Wong wrote: > Dear Qubes Community, > > As many of you have noticed, parts of the Qubes OS website are > temporarily down. The reason is that GitHub is doing unplanned > maintenance on GitHub Pag

[qubes-devel] Announcement for users experiencing update errors in dom0 and Fedora TemplateVMs

2018-04-25 Thread Andrew David Wong
r instances of "http" to "https". 5. Click the "Save" button in the top-right corner of the window. 6. Close the window. 7. Check for updates normally. 8. Shut down the TemplateVM. Thank you to awokd for suggesting and testing these instructions! For further informat

[qubes-devel] XSA-258 and XSA-259 do not affect the security of Qubes OS

2018-04-25 Thread Andrew David Wong
to the XSA Tracker: https://www.qubes-os.org/security/xsa/#258 https://www.qubes-os.org/security/xsa/#259 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlrhHcoACgkQ203TvDlQ

Re: [qubes-devel] Moving cache dirs out of /dev/xvdb

2018-03-30 Thread Andrew David Wong
a to explore whether its worth exploring. > This reminds me of a related discussion we had here several years ago: https://groups.google.com/d/topic/qubes-devel/j7fjU4Bevfo/discussion - -- Andrew David Wong (Axon) Community Manager, Qubes OS https:/

[qubes-devel] Qubes OS 4.0 has been released!

2018-03-28 Thread Andrew David Wong
+is%3Aissue+milestone%3A%22Release+4.1%22+label%3Aenhancement [26] https://www.qubes-os.org/doc/contributing/ [27] https://www.qubes-os.org/donate/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/03/28/qubes-40/ - -- Andrew David Wong (Axon) Community

Re: [qubes-devel] 20 Mar 2018 decide whether 4.0-rc5 is the final 4.0

2018-03-22 Thread Andrew David Wong
y separation provided by Qubes > and HVM/PVH. > > [1] https://github.com/QubesOS/qubes-issues/issues/3703#issuecomment-374931517 > Marek, did you mean security-testing instead of current-testing? According to QSB #37 [2], the Spectre SP2 mitigations are in security-testing, not cu

Re: [qubes-devel] Re: Timestamp canaries

2018-03-17 Thread Andrew David Wong
he NIST Randomness Beacon. Very interesting. Thanks for bringing it to my attention. As far as I can tell, this looks like a very good source for the Proof of Freshness. Would you like to submit a PR that adds it to the script? https://github.com/QubesOS/qubes-secpack/blob/master/utils/proof_of_fr

[qubes-devel] [UPDATE] QSB #37: Information leaks due to processor speculative execution bugs (XSA-254, Meltdown & Sepctre)

2018-03-15 Thread Andrew David Wong
llows: - Xen packages, version 4.6.6-37 [...] ``` This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/03/15/qsb-37-update/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org

Re: [qubes-devel] Timestamp canaries

2018-03-09 Thread Andrew David Wong
now you have to add the --rehash-trees option where the > ots-git-gpg-wrapper command is called. > > FWIW, as of this week, Bitcoin Core maintainer Wladimir J. van der > Laan started using OTS to timestamp Bitcoin Core commits and tags. > Related issue: https://github.com/Qubes

[qubes-devel] Qubes OS 4.0-rc5 has been released!

2018-03-06 Thread Andrew David Wong
://www.qubes-os.org/doc/software-update-dom0/#testing-repositories [domU-testing]: https://www.qubes-os.org/doc/software-update-vm/#testing-repositories This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/03/06/qubes-40-rc5/ - -- Andrew David Wong (Axon

Re: [qubes-devel] Qubes OS daily canary package

2018-03-01 Thread Andrew David Wong
ly, my own approach to this problem is essentially one of brute force: repeatedly checking for updates through a large number of different Tor circuits over several hours. - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SI

[qubes-devel] XSA-252, XSA-255, and XSA-256 do not affect the security of Qubes OS

2018-02-27 Thread Andrew David Wong
added to the XSA Tracker: https://www.qubes-os.org/security/xsa/#252 https://www.qubes-os.org/security/xsa/#255 https://www.qubes-os.org/security/xsa/#256 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

Re: [qubes-devel] Are there currently anyone assigned to update Qubes-Windows-Tools?

2018-02-03 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-02-03 07:16, Elias Mårtenson wrote: > On Saturday, 3 February 2018 12:06:20 UTC+8, Andrew David Wong > wrote: > >> As far as I know, Qubes Windows Tools continues to remain on >> indefinite hold. We welcome anyo

Re: [qubes-devel] Are there currently anyone assigned to update Qubes-Windows-Tools?

2018-02-02 Thread Andrew David Wong
> but not perfect. If so, maybe someone else can help with bringing > Qubes-Windos-Tools to Qubes 4? Unfortunately I have no coding > skills of this sort though, otherwise I'd give it a shot. > Sorry, I don't know

[qubes-devel] Qubes OS 4.0-rc4 has been released!

2018-01-31 Thread Andrew David Wong
bes website: https://www.qubes-os.org/news/2018/01/31/qubes-40-rc4/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlpyfsUACgkQ203TvDlQ MDDB3w/+M0JJTT1cWeQNe1fZgQXkKE9dY/lJ

[qubes-devel] Re: [qubes-project] Hosting for OpenQA instance

2018-01-26 Thread Andrew David Wong
nt of developer time ~70 EUR/month would pay for.) However, I'd be surprised if there were no one in the Qubes community willing to share a suitable machine for this purpose. My guess is that there aren't as many readers on qubes-project as there are on qubes-devel and qubes-users, so I'm CCing those ot

[qubes-devel] [UPDATE] QSB #37: Information leaks due to processor speculative execution bugs (XSA-254, Meltdown & Sepctre)

2018-01-24 Thread Andrew David Wong
es | PV |HVM| HVM | Stub domains - Default VMs w/o PCI | N/A |PV | N/A | Stub domains - Default VMs w/ PCI | N/A |PV | PV| Stub domains - HVMs| PV |PV | PV| ``` On 2018-01-11 08:57, Andrew David Wong wrote: > Dear Qubes C

[qubes-devel] Qubes and Whonix now have next-generation Tor onion services!

2018-01-22 Thread Andrew David Wong
/trac.torproject.org/projects/tor/wiki/doc/NextGenOnions [3] https://www.whonix.org/blog/whonix-new-v3-onion-address This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/01/23/qubes-whonix-next-gen-tor-onion-services/ - -- Andrew David Wong (Axon) Community Man

[qubes-devel] "Qubes Air: Generalizing the Qubes Architecture" by Joanna Rutkowska

2018-01-22 Thread Andrew David Wong
s-air.html And on the Qubes website: https://www.qubes-os.org/news/2018/01/22/qubes-air/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlpmBMEACgkQ203Tv

Re: [qubes-devel] Upgrade instructions for R3.2 and QSB37 patches

2018-01-14 Thread Andrew David Wong
al upgrade (or refrain from taking the steps required to initiate it), and complete qubes-dom0-update normally. This is important, because even if the user wants to perform the special upgrade, she must be allowed to decline it initially so that she

Re: [qubes-devel] What is your development environment ?

2018-01-13 Thread Andrew David Wong
ing through this !! > > Mohit > Thanks for your willingness to help! If you haven't already done so, please take a look at the Contributing page for ideas, especially the "Contributing Code" section: https://www.qubes-os.org/doc/contributing/ - -- Andrew David Wong (Axon) Communit

[qubes-devel] Qubes Manager is coming back in Qubes 4.0-rc4!

2018-01-12 Thread Andrew David Wong
provided by the new 4.0 widgets. Specific examples include attaching and detaching block devices, attaching and detaching the microphone, and VM CPU usage. - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

[qubes-devel] QSB #37: Information leaks due to processor speculative execution bugs (XSA-254, Meltdown & Sepctre)

2018-01-11 Thread Andrew David Wong
s-qrexec-to-tcp [8] https://www.qubes-os.org/news/2017/04/26/qubes-compromise-recovery/ [9] https://lists.xenproject.org/archives/html/xen-devel/2018-01/msg00403.html [10] https://www.qubes-os.org/news/2017/10/03/core3/ [11] https://blog.xenproject.org/2018/01/04/xen-project-spectremeltdown-faq/ - -- The Qub

Re: [qubes-devel] Invitation to submit ideas for Google Summer of Code (GSoC) 2018

2018-01-09 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-01-09 20:32, Andrew David Wong wrote: > In preparation for Google Summer of Code (GSoC) 2018 [1], we > invite the Qubes community to contribute ideas to the Qubes ideas > list. [2] You can find our 2017 ideas list here: &

[qubes-devel] Invitation to submit ideas for Google Summer of Code (GSoC) 2018

2018-01-09 Thread Andrew David Wong
.) Please feel free to submit pull requests against that page or send replies to this thread. [1] https://summerofcode.withgoogle.com/ [2] https://summerofcode.withgoogle.com/rules/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

Re: [qubes-devel] Announcement: Fedora 26 TemplateVM Upgrade

2018-01-07 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-01-07 14:28, Peter Todd wrote: > On Sat, Jan 06, 2018 at 06:15:21PM -0600, Andrew David Wong wrote: >> Dear Qubes Community, >> >> Fedora 25 reached EOL ([end-of-life]) on 2017-12-12. We sincerely >> apologize

[qubes-devel] Re: Announcement: Fedora 26 TemplateVM Upgrade

2018-01-07 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-01-06 18:15, Andrew David Wong wrote: > Dear Qubes Community, > > Fedora 25 reached EOL ([end-of-life]) on 2017-12-12. We sincerely > apologize for our failure to provide timely notice of this event. It > is strongly rec

[qubes-devel] Announcement: Fedora 26 TemplateVM Upgrade

2018-01-06 Thread Andrew David Wong
/templates/fedora-minimal/ [Note on dom0 and EOL]: /doc/supported-versions/#note-on-dom0-and-eol This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/01/06/fedora-26-upgrade/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org

[qubes-devel] XSA-253 does not affect the security of Qubes OS

2018-01-04 Thread Andrew David Wong
/security/xsa/#253 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlpOTI0ACgkQ203TvDlQ MDBIWxAAoX+LoHZ1U4sBy+INvGSv29gOW/3uV+XA34CucqkNjROSio6h08I2xnQb cuxNmyUf65JbecQlV3mSeyRSJJ96EA

[qubes-devel] Announcement regarding the Meltdown and Spectre attacks

2018-01-04 Thread Andrew David Wong
/bulletins/ This announcement is also available on the Qubes website: https://www.qubes-os.org/news/2018/01/04/xsa-254-meltdown-spectre/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE

Re: [qubes-devel] Any chance of moving dom0 to F26 for 4.0 final release

2017-12-13 Thread Andrew David Wong
/software-update-dom0/#why-would-one-want-to-update-software-in-dom0 > Also see the note here specifically regarding the dom0 OS reaching EOL: https://www.qubes-os.org/doc/supported-versions/#dom0 - -- Andrew David Wong (Axon) Community Manager, Qubes

[qubes-devel] XSA-248 through XSA-251 do not affect the security of Qubes OS

2017-12-12 Thread Andrew David Wong
Tracker: https://www.qubes-os.org/security/xsa/ https://www.qubes-os.org/security/xsa/#248 https://www.qubes-os.org/security/xsa/#249 https://www.qubes-os.org/security/xsa/#250 https://www.qubes-os.org/security/xsa/#251 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes

[qubes-devel] Qubes Canary #14

2017-12-11 Thread Andrew David Wong
le blindly! Verify the digital signatures! ``` - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIcBAEBCgAGBQJaLqYHAAoJENtN07w5UDAwfp4QAIRkJqGbks85dHhznfwFA6CY PL8xplv8oiZiIxV6dLI+96uXccuqzyDZMN22RpvxORO/U2vmcPB3DpCXS/1/Mcp2 Xa6TW5YhuTWbm

[qubes-devel] QSB #36: Xen hypervisor issue in populate-on-demand code (XSA-247)

2017-11-28 Thread Andrew David Wong
its.xen.org/xsa/advisory-247.html [2] https://xenbits.xen.org/xsa/advisory-246.html - -- The Qubes Security Team https://www.qubes-os.org/security/ ``` - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIcBAEBCgAGBQJaHYLnAAo

[qubes-devel] Qubes OS 4.0-rc3 has been released!

2017-11-27 Thread Andrew David Wong
]: https://www.qubes-os.org/doc/releases/4.0/release-notes/ [Downloads]: https://www.qubes-os.org/downloads/ - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIcBAEBCgAGBQJaHC81AAoJENtN07w5UDAwRk0QALTnXVP1O7F/Wl+7sl8Gs4Gp 2MYaTsTNxP

Re: [qubes-devel] Re: Community Contributor PGP fingerprints and keys

2017-10-31 Thread Andrew David Wong
s. in the case you agree: here are the emails: > > my email: blacklight...@protonmail.com toki's email: > toki...@posteo.de > > cheers, > > blacklight > Yes, thank you for reminding me! I've just added you, Desobediente Civil, and Tobias as Community Contributors. Thank you

<    1   2   3   4   5   6   >