[qubes-users] qvm-run, hangs and stacktrace.

2018-08-14 Thread tierlebu
Has anyone else experienced this? The application is launched, but it doesn't return correctly. I have to ctrl+c to improperly exit qvm-run, and it prints a stack trace: Traceback (most recent call last): File "/usr/bin/qvm-run", line 5, in sys.exit(main()) File "/usr/lib/python3.5/site

[qubes-users] Re: New CPU Bug Found

2018-08-14 Thread tierlebu
On Tuesday, August 14, 2018 at 12:44:18 AM UTC+1, jonbrown...@gmail.com wrote: > New CPU backdoor has been found with code available here: > https://github.com/xoreaxeaxeax/rosenbridge > > Anyone mind checking if Thinkpad 230 is affected? It is thought that only VIA C3 CPUs are affected by this

[qubes-users] Re: New CPU Bug Found

2018-08-14 Thread brendan . hoar
On Monday, August 13, 2018 at 7:44:18 PM UTC-4, jonbrown...@gmail.com wrote: > New CPU backdoor has been found with code available here: > https://github.com/xoreaxeaxeax/rosenbridge > > Anyone mind checking if Thinkpad 230 is affected? As per earlier in the thread, this only applies to some old

Re: [qubes-users] Re: yubikey password

2018-08-14 Thread brendan . hoar
On Monday, August 13, 2018 at 5:47:06 PM UTC-4, joev...@gmail.com wrote: > Are you sure they are using Yubikey's "Static Password" slot? That is the > only component that enumerates as a USB keyboard. The normal yubikey setup > enumerates as a Smartcard, which is how the challenge/response work

Re: [qubes-users] Whonix 14 - upgrade or re-install? Whats more smooth, less troublesome?

2018-08-14 Thread qubes-fan
Thanks Chris. If you dont mind, could you please elaborate more on your procedure which worked for you? These two guides are a bit confusing to follow. What I understand from your text is following: 1) you followed the guide on whonix page (not the one on qubes page) Q: http://dds6qkxpwdeubwuc

[qubes-users] [Qubes 4.0] How to reinstall an AppVM ?

2018-08-14 Thread schwoereraxel
Hello. I've installed Qubes 4.0 and it seems that the AppVM work is bugged. I cannot run an application on this VM, no matter the template... The other VMs (untrusted, personal...) works. So I want to know if it possible to reinstall this AppVM ? Axel -- You received this message because you are

Re: [qubes-users] Re: yubikey password

2018-08-14 Thread joeviocoe
On Tuesday, 14 August 2018 07:04:09 UTC-4, Brendan Hoar wrote: > On Monday, August 13, 2018 at 5:47:06 PM UTC-4, joev...@gmail.com wrote: > > Are you sure they are using Yubikey's "Static Password" slot? That is the > > only component that enumerates as a USB keyboard. The normal yubikey setup

Re: [qubes-users] how to connect USB to standalone HVM Kali

2018-08-14 Thread Djon Snow
понедельник, 13 августа 2018 г., 13:24:52 UTC+3 пользователь awokd написал: > On Mon, August 13, 2018 6:36 am, Djon Snow wrote: > > понедельник, 13 августа 2018 г., 0:05:35 UTC+3 пользователь awokd > > написал: > > > >> On Sat, August 11, 2018 11:56 am, bbbenjjjami...@gmail.com wrote: > >> > >>> ho

[qubes-users] qvm-run, hangs and stacktrace.

2018-08-14 Thread Pablo Di Noto
I updated last night to testing, and now qvm-run just hangs. Terminating it with CTRL-C gives the same traceback. Please note that in my case, starting any application from the dom0 menu is now working at all. Seems there is issue with the X session. -- You received this message because you ar

Re: [qubes-users] [Qubes 4.0] How to reinstall an AppVM ?

2018-08-14 Thread Unman
On Tue, Aug 14, 2018 at 05:45:09AM -0700, schwoerera...@gmail.com wrote: > Hello. > I've installed Qubes 4.0 and it seems that the AppVM work is bugged. > I cannot run an application on this VM, no matter the template... > The other VMs (untrusted, personal...) works. > So I want to know if it poss

[qubes-users] qvm-run, hangs and stacktrace.

2018-08-14 Thread Pablo Di Noto
Further troubleshooting shows last Debian template seems to be the reason (I normally use Debian for sys-* service VMs) -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an ema

[qubes-users] qvm-run, hangs and stacktrace.

2018-08-14 Thread Pablo Di Noto
Further troubleshooting shows last Debian template update I did recently seems to be the reason (I normally use Debian for sys-* service VMs) -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving email

[qubes-users] qvm-run, hangs and stacktrace.

2018-08-14 Thread Pablo Di Noto
Kudos to the `qvm-volume revert` feature! I just did ``` qvm-volume info debian-9-root qvm-volume revert debian-9-root XX-back ``` and went back to the pre-update template and the issue disappeared. Later today will try to see what happened by updating a clone of the template (as I shoul

Re: [qubes-users] Whonix 14 - upgrade or re-install? Whats more smooth, less troublesome?

2018-08-14 Thread Franz
On Tue, Aug 14, 2018 at 8:15 AM, wrote: > Thanks Chris. If you dont mind, could you please elaborate more on your > procedure which worked for you? These two guides are a bit confusing to > follow. > > What I understand from your text is following: > > 1) you followed the guide on whonix page (no

Re: [qubes-users] Whonix 14 - upgrade or re-install? Whats more smooth, less troublesome?

2018-08-14 Thread Patrick Schleizer
Franz: > when I try to uninstall whonix-ws > > sudo dnf remove qubes-template-whonix-ws* > > I get > No match for argument: qubes-template-whonix-ws* > Error: No packages marked for removal > > I followed this guide: https://www.whonix.org/wiki/Qubes/Uninstall > Output of...? dnf list | grep

Re: [qubes-users] Whonix 14 - upgrade or re-install? Whats more smooth, less troublesome?

2018-08-14 Thread Patrick Schleizer
Andrew David Wong: > On 2018-08-12 14:26, 'awokd' via qubes-users wrote: >> On Sun, August 12, 2018 6:16 pm, qubes-...@tutanota.com wrote: >>> I am planning to move from my Whonix 13 to Whonix 14 on Qubes. My >>> question is what way it should be easier, based on the Q user >>> experiences. What wo

[qubes-users] How do I install a Firewall ? Using Qubes as local Server !

2018-08-14 Thread Who Cares
Hello, I am using qubes 4.0 and i am trying to install a firewall. I try to isntall kerio control (http://www.kerio.de/products/kerio-control) as it supports VPN. At the end i want to use it as the firewall-VM rather than buy a physical firewall. Kerio-control got some several versions: 1:

[qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Who Cares
Hello, I am using qubes 4.0 and i am trying to install a firewall. I try to isntall kerio control (http://www.kerio.de/products/kerio-control) as it supports VPN. At the end i want to use it as the firewall-VM rather than buy a physical firewall. Kerio-control got some several versions: 1: s

Re: [qubes-users] Re: Whonix 14 installation problem...using 4.0?

2018-08-14 Thread Patrick Schleizer
sm...@tutamail.com: > Not sure it was happening in the background but waited for 1 1/2 hrs with no feedback after the "sudo qubesctl state.sls qvm.anon-whonix" command in Dom0. Created... add salt download progress indicator #4215 https://github.com/QubesOS/qubes-issues/issues/4215 ... for it.

Re: [qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Steve Coleman
On 08/14/18 13:40, Who Cares wrote: I am using qubes 4.0 and i am trying to install a firewall. Qubes comes with an integrated firewall in the sys-firewall VM. It uses managed iptables which provide the basic rules to protect the system, but also allow you to make adjustments as required for

Re: [qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Chris Laprise
On 08/14/2018 02:22 PM, Steve Coleman wrote: On 08/14/18 13:40, Who Cares wrote: I am using qubes 4.0 and i am trying to install a firewall. Qubes comes with an integrated firewall in the sys-firewall VM. It uses managed iptables which provide the basic rules to protect the system, but also

[qubes-users] XSA-268, XSA-269, XSA-271, and XSA-272 do not affect the security of Qubes OS

2018-08-14 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, The Xen Project has published Xen Security Advisories 268, 269, 271, and 272 (XSA-268, XSA-269, XSA-271, and XSA-272, respectively). These XSAs do *not* affect the security of Qubes OS, and no user action is necessary. These X

[qubes-users] QSB #42: Linux netback driver OOB access in hash handling (XSA-270)

2018-08-14 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, We have just published Qubes Security Bulletin (QSB) #42: Linux netback driver OOB access in hash handling (XSA-270). The text of this QSB is reproduced below. This QSB and its accompanying signatures will always be available i

Re: [qubes-users] Guide: Monero wallet/daemon isolation w/qubes+whonix

2018-08-14 Thread Patrick Schleizer
I didn't notice this thread until now. Interesting! Now reference here: https://www.whonix.org/wiki/Monero I am wondering how to save users from as many manual steps as possible. To save users from having to edit /rw/config/rc.local... > socat TCP-LISTEN:18081,fork,bind=127.0.0.1 EXEC:"qrexe

Re: [qubes-users] Guide: Monero wallet/daemon isolation w/qubes+whonix

2018-08-14 Thread Holger Levsen
On Tue, Aug 14, 2018 at 07:42:00PM +, Patrick Schleizer wrote: > Now reference here: > https://www.whonix.org/wiki/Monero > > > I am wondering how to save users from as many manual steps as possible. since a bit more than 2 weeks monero can be installed on stretch with 'sudo apt install -t s

Re: [qubes-users] Whonix 14 - upgrade or re-install? Whats more smooth, less troublesome?

2018-08-14 Thread Patrick Schleizer
Thank you for looking into this! Chris Laprise: > It was a bit confusing, but from the wiki Install page I picked out > these relevant steps for dom0 (Qubes 4.0): > > $ sudo qubes-dom0-update qubes-core-admin-addon-whonix > $ sudo qubesctl state.sls qvm.anon-whonix > > The second command will st

Re: [qubes-users] Whonix 14 - upgrade or re-install? Whats more smooth, less troublesome?

2018-08-14 Thread Patrick Schleizer
This is completely untested. Let me know what you think and if this works for you. * A backup of all Qubes VMs using the usual Qubes backup mechanism (independent from below) is advisable anyhow. * One who mind about their contents could clone their sys-whonix to sys-whonix-backup and clone their

[qubes-users] Re: Qubes OS dual boot question

2018-08-14 Thread Patrick Bouldin
On Monday, August 13, 2018 at 4:17:31 PM UTC-4, Patrick Bouldin wrote: > I have a goal to buy a new laptop, preconfigured with Windows, and then > within Windows I will reallocate disk space in order to install Qubes4.0. > > In the past with prior versions of Qubes that has sometimes been problem

[qubes-users] Re: Archlinux template for Qubes R4 build is working

2018-08-14 Thread stallmanrocks
release 4.1 build success you need comment out "ttf-symbola" line # Particularly good Unicode coverage: $HOME/qubes-builder/qubes-src/builder-archlinux/scripts/packages.list --- Cheers ;) On Wednesday, May 30, 2018 at 6:37:17 PM UTC+3, qubes...@secmail.pro wrote: > Archlinux template seems

Re: [qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Who Cares
I´m trying to implement this Kerio-control system. I thought this would have been a nice combo of firewall and VPN. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email t

Re: [qubes-users] How do I install this Firewall HVM ?

2018-08-14 Thread Steve Coleman
On 08/14/18 16:43, Who Cares wrote: I´m trying to implement this Kerio-control system. I thought this would have been a nice combo of firewall and VPN. You might want to read up on the Qubes Proxy VPN setup and compare how that works with what KerioControl is expecting for its environment. Th

Re: [qubes-users] Guide: Monero wallet/daemon isolation w/qubes+whonix

2018-08-14 Thread 0xB44EFD8751077F97
Patrick Schleizer: > I didn't notice this thread until now. > > Interesting! > > Now reference here: > https://www.whonix.org/wiki/Monero > > > I am wondering how to save users from as many manual steps as possible. > > > To save users from having to edit /rw/config/rc.local... > >> socat TC

Re: [qubes-users] Whonix 14 has been Released

2018-08-14 Thread mstvrlks
Given some recent edits on the whonix instruction pages I would like to take the opportunity to suggest a few others as well. >From minor to major: 1. https://www.whonix.org/wiki/Qubes/Uninstall a. On Qubes 4.0 the instruction "Qubes App Launcher (blue/grey "Q") -> System Tools -> Qube Manager

[qubes-users] Re: Can't use settings in fedora 28 vm.

2018-08-14 Thread Michael MENG
Any luck? I idid reinstall fedora 28 template, and install "fedora workstation", but still the same. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+

Re: [qubes-users] Re: Can't use settings in fedora 28 vm.

2018-08-14 Thread Ryan Tate
This happened to me, too, I Googled around and found setting an environment variable would make the Settings panel/app work: [user@fedora28vm ~] env XDG_CURRENT_DESKTOP=GNOME gnome-control-center (I re-typed the above while looking at another machine rather than copy/paste hopefully no typos!)

Re: [qubes-users] Re: Corrupted LVM Pool Metadata - no free space (recoverable?)

2018-08-14 Thread joeviocoe
I use a custom dracut module from the2nd, ykluks, so I don't know about how to modify it to unlock multiple volumes. Also, I may want to stick with LUKS instead of ecryptfs because yubikey support. Can you elaborate on the steps for using Btrfs during install of Qubes, the documentation is still

[qubes-users] Is Qubes vulnerable to CVE-2018-3620?

2018-08-14 Thread Sphere
https://www.bleepingcomputer.com/news/security/researchers-disclose-new-foreshadow-l1tf-vulnerabilities-affecting-intel-cpus/ There are other vulnerabilities disclosed along with this today and if possible, I would like to confirm that as well. On a side note, I have long disabled Hyperthreading

[qubes-users] Re: Is Qubes vulnerable to CVE-2018-3620?

2018-08-14 Thread Sphere
On Wednesday, August 15, 2018 at 10:33:09 AM UTC+8, Sphere wrote: > https://www.bleepingcomputer.com/news/security/researchers-disclose-new-foreshadow-l1tf-vulnerabilities-affecting-intel-cpus/ > > There are other vulnerabilities disclosed along with this today and if > possible, I would like to

[qubes-users] Re: Is Qubes vulnerable to CVE-2018-3620?

2018-08-14 Thread Sphere
CVE-2018-3646 in particular is alarming: "The third flaw, CVE-2018-3646, has a CVSS Base Score of 7.1 and enables bad actors to attack virtual machines (VM), via virtualization software and Virtual Machine Monitors (VMMs) running on Intel processors. A malicious guest VM could infer the values o