unman
--
You received this message because you are subscribed to the Google Groups "qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscribe@googlegroups.com.
To post to this group, send email to qubes...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/20161010132724.GC18661%40thirdeyesecurity.org.
For more options, visit https://groups.google.com/d/optout.
look at finding right usb controller. https://www.qubes-os.org/doc/assigning-devices/
If really worried about using a usb keyboard you can use a ps2 one, or get a usb to ps2 adapter.
I don't think you really have 6 controllers do you? its probably only three. ohci0, ohci1, and ehci0 On mine I have only two echi's. one is for the two low speed ports, next to the ps2 port which i use for mouse and keyboard, and is assigned to dom0. The other controller is for everything else I have in sys-usb.
On another machine with xhvi (usb3.0) everything gets routed through that one controller. the two ehvi controllers get routed through the usb 3.0 making a single controller not 3. so its either use the two controllers the same way I have on this box with xhvi disabled, or enable it then only having a single controller if wanting 3.0 speeds (using the qubes input proxy). To get 3 controllers to have seperates usb 2.0 and usb 3.0 you need to find a lga 2011 socket mobo, like an x99, and make sure the bios supports the manual routing feature.
But I haven't tested the new ability to assign separate pci devices now in the new qubes 3.2. Maybe this changes things?
again though on my one machine i opted to have a single controller so I can have 3.0 speeds, and use a usb to pci adapter for the keyboard. I'm not as concerned about the mouse, at least I hope I don't have to be lol. I use the lockscreen.
go with B1 man. Like I said you can get a ps2 adapter for your usb keyboard and then can have all controllers in the sys-usb if you want. But I don't think there is anything to be worried about having your keyboard in dom0. Unless you got a real sketchy kb. (anything is possible)
As for how to hide all usb controllers except the rear OHCI0, you can't unless its on a separate controller. Otherwise just add every other controller to sys-usb except the OHCI0 one. Again to make sure you are correctly identifying your controller https://www.qubes-os.org/doc/assigning-devices/ You test with a device plugged in the port to identify the controller.
You can also just go into a vm settings and click on devices to get a list. look for what says usb, to see how many controllers you actually have.
dont' do B2 you need keyboard, not sure why you want b3, with b4 that means the usb ports aint hidden from dom0 during boot like luks passphrase I think that would be security risk unless you constantly unplugging every usb device except your keyboard when you reboot.
again,I use a ps2 keyboard. i have a little green inch long 99cent - 5 dollar adapter attached to the usb keyboard and in back of pc. on the newer computers the ps2 even hot plug n play whatever like a usb. it will re-initialize when re plugging it just like a usb as well in case you worried about something like that too. Its best practice imo for qubes. ps2 keyboard don't use a usb one.
yes more people should share their whole environment. Why be scared? I basically want qubes to be more popular. best way to learn is still word of mouth.
I determined its only two by plugging in a usb stick in all of them and seeing which controller its attached to, by following those directions.
although i'm sure this is some security risk in some way haha, but they all do it now. hey it might wake your pc from bad suspend though, unless disabled in bios. might just re-initialize if not working though when re-plugging.
dunno, never had a keyboard not work with a ps2 adapter.
wow! i guess you do haev 6 usb controllers. to hide them just add them all to sys-usb except for 12.0 what pc/mobo do you have out of curiosity?
I dunno what all that salt stuff means i'm a total noob. But I do know if you want to use a usb keyboard, you gonna have problems.
because i mean, well one prob i've run into is what happens if sys-usb messes up and you have no keyboard lol. I believe this is mostly a desktop pc problem, not a laptop.