isolated workflows - image converter - trusted jpg

100 views
Skip to first unread message

'091823'04918'032948'1093248018243

unread,
Nov 15, 2016, 9:00:21 AM11/15/16
to qubes-users
Hello,

wow cool, I found out that now QR32 also can convert pictures into a trusted image.

Only I got confused, because after the conversion, I got two files:

i) xy.jpg
ii) xy_untrusted.jpg

In the PDF work flow it was the opposite:

i) xy.pdf
ii) xy_trusted.pdf

I liked the last work flow much better, because after the conversion, I can see it, that this conversion took really place!
(especially after the copying around from files, so it will be easy to lost the overview...)

I don't found some docu for the untrusted.jpg, this means I must wipe the xy_untrusted.jpg and keep the xy.jpg, which is now the 100% dead jpg picture, right?

Merci for this very nice new feature and Kind Regards


P.S. Do I need also some Safty Linux Converter fro MP3 and MP4, or are this files always 100% dead, without any kind of embedded objects by default?


Andrew David Wong

unread,
Nov 15, 2016, 9:31:59 AM11/15/16
to '091823'04918'032948'1093248018243, qubes-users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2016-11-15 06:00, '091823'04918'032948'1093248018243 wrote:
> Hello,
>
> wow cool, I found out that now QR32 also can convert pictures into a trusted image.
>
> Only I got confused, because after the conversion, I got two files:
>
> i) xy.jpg
> ii) xy_untrusted.jpg
>
> In the PDF work flow it was the opposite:
>
> i) xy.pdf
> ii) xy_trusted.pdf
>
> I liked the last work flow much better, because after the conversion, I can see it, that this conversion took really place!
> (especially after the copying around from files, so it will be easy to lost the overview...)
>
> I don't found some docu for the untrusted.jpg, this means I must wipe the xy_untrusted.jpg and keep the xy.jpg, which is now the 100% dead jpg picture, right?
>
> Merci for this very nice new feature and Kind Regards
>

That does indeed appear to be an oversight. Tracking here:

https://github.com/QubesOS/qubes-issues/issues/2437

> P.S. Do I need also some Safty Linux Converter fro MP3 and MP4, or are this files always 100% dead, without any kind of embedded objects by default?
>

I think it's fair to say that *any* time complex input is being parsed, there's the potential for malicious input to be crafted to exploit a bug in whatever program is doing the parsing.

- --
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYKxxXAAoJENtN07w5UDAwAJIQAItCCYhGa7ry9GOEZRdXE9ps
cfSov4ghYnNFA1K1aZATxJa6h9h2v5GbdYhZGPIFE1Bp5kqghZ2Rfhl/S5koIY4I
XaWypv1gWAX95I3eG7WGX03sBp2tfSufe8yqJjevzXlttgS/Lg2fOnFmPPGGbS99
WV0KIXd+SFkG4NZ2EfN/dTA6ST0NlszaR680ZAa36ii9GVGMdWL3DqhjEslYYhWi
alYrqdD9odKq92uGNRFw8jA0+iSwYIICzCfDbLr0HKBy/8bCmYzGBLCCsa/HixN7
ek6PdZP9d6ZrcbeYt50hkar+RrC617Xj7k696XXiArkfD97NIweMYb4ksC8rcntm
zytsnLj72mXq1RJoxQFsOn73jmCfSbSktuQzFhDXarhh9nXDwgPtAfJLFKPs4fX+
U3odhxPuVPjKGtcXvUE3oxkePBSYUAW4tn1wVmjUgwpuYXh/dLKWuc2RgoPiCVWC
JsL/jzPY/ze8P2nHkBF/4Kj5nvJQEYLjtoueYCAJVPOdYUqGuZ2xP84vrpoNM/CN
YVQsminN6jOUOrP+nrmtffzupkCJ6gIig4kY/cdBRcxTgNlrQsnsSG4Ot1iUeQ6w
CIONUm4rq3BbwvUCujO2wetaPY+k0eqyFSkwSHOKOJLI9YdfTBoi3Jxr2jkRfcBI
DKVSjVCjqskcykYAuoPB
=nsan
-----END PGP SIGNATURE-----

Unman

unread,
Nov 15, 2016, 9:35:55 AM11/15/16
to '091823'04918'032948'1093248018243, qubes-users
Yes, you're right - they are handled and named inconsistently.
Perhaps this should be changed.
Also, if I remember correctly, the pdf converter will arbitrarily
overwrite another PDF with the same name.

It's up to you if you keep the original "untrusted" image. There might
be value in that.

As to mp3/mp4, absolutely NOT dead, and can easily carry embedded
objects. Definitely not to be trusted. If you are concerned always open
them in a dispVM.

unman

'019438'1094328'0914328'09143

unread,
Nov 15, 2016, 10:25:09 AM11/15/16
to qubes-users
Hello,

thanks for the feedback, now I can understand the behavior.

I would appreciate very much the same isolated work low for pictures / graphics like the PDF and the overwriting helps to keep the disk size tiny and the appendix secured really help to organize the files from the first step.

Now I deleted manual the unsecured files and proceed with my work-flow and so I don't know, which files are now processed and which one are still waiting...

Very nice is, that I can select more than one file and run this task in the background: Select & forget....

Many times photos get compressed better via JPG and grafics via PNG, I have seen also in other tasks very oversize huge files, if the format is not fitting to the content - I think this would be good to keep it in mind, so the quality should be ok and the size tiny - if possible.

Thanks and Kind Regards

Chris Laprise

unread,
Nov 16, 2016, 3:48:32 PM11/16/16
to Unman, '091823'04918'032948'1093248018243, qubes-users, Andrew David Wong
What is the command to do the trusted image conversion?

Chris

'0193284'0918432'0918432'091804329

unread,
Nov 18, 2016, 11:36:43 AM11/18/16
to qubes-users
Hello Chris,

here is a hint:

https://groups.google.com/forum/#!topic/qubes-users/Z7yx7li_SJo

The qvm-convert-pdf command does only one file at a time, so you would have use a complex command like this:

for p in *.pdf; do qvm-convert-pdf "$p"; done

DispVM > Downloads > PDF-File > right Mouse - Context Menue > Scripts... perhaps you can enhance here the reachable scripts?

Kind Regards

Andrew David Wong

unread,
Nov 19, 2016, 7:22:13 AM11/19/16
to Chris Laprise, Unman, '091823'04918'032948'1093248018243, qubes-users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2016-11-16 12:48, Chris Laprise wrote:
> What is the command to do the trusted image conversion?
>

The command is: qvm-convert-img

(Requires Qubes 3.2)

- --
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYMEPmAAoJENtN07w5UDAwI1YP/jZKAeQ/CdmaoO72fEJy7qvB
i95m9qqS/tzog+t8q2t84NpOypOe6foFPNS7wvuouMbQkKTju/xeh+0IkxuNXC+2
3T4abHuKFhoXXlOI9luBzANB7KpnZDm1NK+vYQnNVbL4pvq8BzrscYCudLI5bEj8
lRegBcWGpotRw51UMM60ltLmqEf/JRwhghgvAuc1Pq2AGzKkvy1RZx0rSThrCmCg
yH8tnD3iaaimM9/H7fhJ45lyV7IyRaqBJ+dZQ1oL/xk527x0nosjNVBMoRd2L5Bx
3yhErLfNaIiyDs120tdvgNIzGkhDq3cO+lrd1VzZXOYqbUaeZzzS6Nw/OmU3OCtl
hg3S+24ElMDbtxSc0Whii1xMjLQiD7seHAkKMsETerh/5EiOCEccMHn0LgAumytC
awF7Tn4EXffFeK3uUKs4qFeTc/Z2NMxGuy7pLvdTLUffVhdkzMeI20RYUMBHcP0t
VdIX+3l6pbnMKxcW0D/y4R/fpbl3MxzfzhnvjaLELk5iSMJYneHD6yw+yC9vJul8
VUNZcoiUFc9CURvtKku2ghtcu4DgA6A6/Yj37PAqjlQANwJcUttnpTj5Ol1gF5Bp
unyAvCLDdA+dn0c1xtZ6+PXT+p8zrpZLjdAZQxgN4x9X+V4H4ZtOfEap9JCNHOTs
9tknYBGnVQMoxmBjeWUK
=IgQu
-----END PGP SIGNATURE-----

Reply all
Reply to author
Forward
0 new messages