What can I do on a fresh installation on a brand new laptop to ensure that once installed with Qubes the laptop firmware cannot be over written written (assuming I am using an optical drive for installation,) thx
Qubes installs a usbvm called sys-usb by default.
so where you get the iso I guess is the real question. And what usb stick you use to write it on. Maybe someone has some comments on a good usb brand to buy. I buy microcenter.
Where you get the iso is another story. so use your brand new computer to download it. hopefully its coming with an os pre-installed? maybe harden windows first follow these instructions before you boot the os. www.hardenwindows10forsecurity.com, (read the instructions on an older computer not your new one) make sure to follow the qubes install instructions how to verify the key signatures. and then hope for the best. use good security practices. keep stuff as compartmentalized as your mind can handle.
I been in my amazon videos qube mostly since the holidays. ANd so all i do in that vm is watch videos nothing else. I use about a dozen diff vms for different tasks I do on the pc. I log into this yellow colored qube, the default personal, to log into my webmail, google, stuff where i'm not devastated if the password gets stolen. more sensitive stuff in another.
Actually its not true about my amazon qube. I'm actually always in a disposable vm the most out of anything. I use it for all random tasks that don't need credentials.
use rawrite32.exe if your burning it from windows. https://www.netbsd.org/~martin/rawrite32/download.html
If the USB controller is installed in this sys-usb and a bad usb memory stick tried to write to the firmware, am I correct in assuming it is effectively writing to virtual firmware and therefore the actual firmware stays intact ?
I don't believe so but hopefully your machines bios supports enabling iommu/vt-d, so at least the controller will be isolated from the other vms.