[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread Brendan Hoar
Thank you, Marek et al, for your work over what was presumably a longer than usual work day. B -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubs

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread seshu
On Wednesday, January 23, 2019 at 5:32:38 PM UTC, Brendan Hoar wrote: > Thank you, Marek et al, for your work over what was presumably a longer than > usual work day. > > > B Agreed, thanks everyone! One question Marek, the ubuntu distros you recently made available to the community could be

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread gone
seshu wrote on Wed, 23 January 2019 17:49 > On Wednesday, January 23, 2019 at 5:32:38 PM UTC, > Brendan Hoar wrote: > > Thank you, Marek et al, for your work over what was > > presumably a longer than usual work day. > > > > > > B > > Agreed, thanks everyone! > > -- I'd also like to thank

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread seshu
On Wednesday, January 23, 2019 at 8:06:20 PM UTC, gone wrote: > seshu wrote on Wed, 23 January 2019 17:49 > > On Wednesday, January 23, 2019 at 5:32:38 PM UTC, > > Brendan Hoar wrote: > > > Thank you, Marek et al, for your work over what was > > > presumably a longer than usual work day. > > > >

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread gone
@seshu: OK, thanks, so I'll try and reboot. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread gone
unfortunately the reboot brought no change. Still the 201812091508 version. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.c

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread Chris Laprise
On 01/23/2019 12:05 PM, Marek Marczykowski-Górecki wrote: Patching = If you are a Qubes user, you should remove all APT-based (including Debian and Whonix) TemplateVMs and StandaloneVMs, then install fresh ones. You can do this by performing the following steps on each such TemplateVM:

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread John S.Recdep
On 1/23/19 9:08 PM, gone wrote: > unfortunately the reboot brought no change. Still the > 201812091508 version. > this is for Fedora, is there something akin to this for Debian ? -- What you can do to get the differences between two templates: 1) run "dnf list installed > packagelist1.tx

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread gone
has worked fine with debian-9. Thank you Chris. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, s

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-25 Thread gone
Chris Laprise wrote on Wed, 23 January 2019 21:52 > On 01/23/2019 12:05 PM, Marek Marczykowski-Górecki > wrote: > > A shortened update procedure for debian-9: > > . > > This method also works with whonix-gw-14 and > whonix-ws-14 templates. > > -- This worked very well on the debian-9 templ

[qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-25 Thread John S.Recdep
On 1/23/19 9:52 PM, Chris Laprise wrote: > On 01/23/2019 12:05 PM, Marek Marczykowski-Górecki wrote: > >> Patching >> = >> >> If you are a Qubes user, you should remove all APT-based (including >> Debian and Whonix) TemplateVMs and StandaloneVMs, then install fresh >> ones. You can do this

Re: [qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-23 Thread goldsmith
On 2019-01-23 21:08, gone wrote: > unfortunately the reboot brought no change. Still the > 201812091508 version. Try sudo qubes-dom0-update --enablerepo=qubes-templates-itl-testing qubes-template-debian-9 -- You received this message because you are subscribed to the Google Groups "qubes-users"

Re: [qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-24 Thread Fidel Ramos
‐‐‐ Original Message ‐‐‐ On Wednesday, January 23, 2019 9:52 PM, Chris Laprise wrote: > On 01/23/2019 12:05 PM, Marek Marczykowski-Górecki wrote: > > > Patching > > > > = > > > > If you are a Qubes user, you should remove all APT-based (including > > Debian and Whonix) TemplateVMs

Re: [qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-24 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 23/01/2019 3.52 PM, Chris Laprise wrote: > On 01/23/2019 12:05 PM, Marek Marczykowski-Górecki wrote: > >> Patching >> = >> >> If you are a Qubes user, you should remove all APT-based (including >> Debian and Whonix) TemplateVMs and Standa

Re: [qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-25 Thread Chris Laprise
On 01/24/2019 10:12 PM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 23/01/2019 3.52 PM, Chris Laprise wrote: On 01/23/2019 12:05 PM, Marek Marczykowski-Górecki wrote: Patching = If you are a Qubes user, you should remove all APT-based (including Debian

Re: [qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-25 Thread Chris Laprise
On 01/25/2019 02:03 PM, gone wrote: Chris Laprise wrote on Wed, 23 January 2019 21:52 On 01/23/2019 12:05 PM, Marek Marczykowski-Górecki wrote: A shortened update procedure for debian-9: . This method also works with whonix-gw-14 and whonix-ws-14 templates. -- This worked very well on

Re: [qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-25 Thread Chris Laprise
On 01/25/2019 03:01 PM, John S.Recdep wrote: On 1/23/19 9:52 PM, Chris Laprise wrote: On 01/23/2019 12:05 PM, Marek Marczykowski-Górecki wrote: Patching = If you are a Qubes user, you should remove all APT-based (including Debian and Whonix) TemplateVMs and StandaloneVMs, then install

Re: [qubes-users] Re: [qubes-devel] QSB #46: APT update mechanism vulnerability

2019-01-25 Thread john s.
>> >> Tasket, >> >> Does this mean that a upgrade to testing  is as good as   uninstalling - >> re-installing templates ? > > Yes. Everything in the template's root and private volumes is wiped > before the new package is added. > > However we found out this doesn't work for Whonix if your upda