I am looking for the best laptop for Qubes 4.0+ to take advantage of all the features along with Heads. I know Heads only officially supports Lenovo Thinkpad 230 but is that the best choice to future proof myself and take advantage of all security benefits?
How is the 230 on the binary blob front and other firmware? Is there any other technology besides Heads that could enhance Qubes or provide better/additional protection?
Here is more info on Heads http://osresearch.net/
Any help is greatly appreciated.
--
You received this message because you are subscribed to the Google Groups "qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscribe@googlegroups.com.
To post to this group, send email to qubes...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/98cebf55-53a2-4e24-9e35-575e9d023106%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
How bad does the RAM issue affect your VM number you want to run vs what you can run? Can it handle all the required VMs needed by default along with both Whonix templates and split GPG?
How does it actually run performance wise?
On 08/10/2018 08:25 PM, Franz wrote:
On Fri, Aug 10, 2018 at 5:23 PM, Jonathan Brown <jonbrown...@gmail.com <mailto:jonbrownmasterit@gmail.com>> wrote:
How bad does the RAM issue affect your VM number you want to run vs
what you can run? Can it handle all the required VMs needed by
default along with both Whonix templates and split GPG?
yes, a part from the system VMs, I usually run 6 VMs. When the machine is fresh started I can easily reach 9 VMs. But after a couple of days working it doesn't let me start new VMs.
How does it actually run performance wise?
Smooth and fast.
But I never tried gaming or specially intensive tasks.
The ivy bridge CPUs are pretty fast.. the last generation before Intel cut max wattage in half with haswell.
BTW there are little tricks to improving RAM usage, as my regular system has 8GB. Net and proxy VMs can usually be set to max 350MB RAM, and I find dom0+KDE works smoothly with max RAM at 1500MB. Most personal and work VMs do fine with max RAM at 1500 - 2000MB.
I use x220 tablet and it is great laptop for Qubes OS 4
1. Heads support (no problems, easy install, works on my machine, many great features kexec etc)
https://github.com/osresearch/heads/tree/master/blobs/x220
Alternative :
https://git.lsd.cat/g/thinkpad-coreboot-qubes
ME disabled (works!)
2. Tomu support (30$ ) (works fine!)
https://www.crowdsupply.com/sutajio-kosagi/tomu
porting gnuk to tomu (opensource analog yubikey, needed to use heads)
https://github.com/osresearch/heads-wiki/blob/master/GPG.md
Dev: https://github.com/aze00/gnuk/tree/efm32
PR: https://github.com/im-tomu/tomu-samples/pull/35
Issue: https://github.com/im-tomu/tomu-samples/issues/4
Alternative - Nitrokey
https://shop.nitrokey.com/shop/product/nitrokey-start-6 (based on gnuk)
3. https://inversepath.com/usbarmory nice compatibility (works without any issues)
4. for good work you need a bundle i7 2gen, 16 RAM and good SSD disk ( I completely lack 256 gigabytes )
main templates :
archlinux
artful
bionic
centos-7
debian-9
dev (buster)
fedora-28
kali-rolling
void-template
whonix-ws-14
whonix-gw-14
works fine and easy build from https://github.com/QubesOS/qubes-builder
+ 8-10 services (vpn,tor,wireguard etc)
+ 3-4 disp vm's (internet browsing)
+ 8+10 domains
Total disk usage : 20.4%
lvm : 36.2% 77.4GB/213.8GB
So, 256GB is enough.
5. You can use it like tablet ;)
https://github.com/martin-ueding/thinkpad-scripts
rotate/touchscreen works great and works on every VM machine.
6. TPM ownership/reset (work!)
7. 10 open vms
temp 52
fan 3496 rpm
8. +3G modem or raspberry pi features
Cheers!
On 08/20/2018 01:21 PM, stallm...@gmail.com wrote:
>
> ME disabled (works!)
It is a nice laptop and I recommend it sometimes BUT:
As someone with your screen-name I would hope you know that it is
impossible to disable ME.
In your case the BUP module still runs along with any mask roms - more
than enough to add a backdoor to your machine.
Of course in terms of laptops it is still better than newer intel stuff
like the skylake puri-craptops where the bup AND the kernel run on their
"disabled" ME - they changed the definition of disabled just like they
did with the definition of "open firmware" :[
The best and most free laptop is the lenovo G505S of which there is a
thriving little coreboot-qubes4 community thanks to me telling many
people to get it :D
G505S:
* pre-PSP AMD quad core cpu (the A10 model - the others suck)
* coreboot with open cpu/ram init (unlike the blobbed puri-craptop hw
init via the intel fsp binary blob)
* IOMMU that works with qubes 4.0 (Must apply latest microcode updates
or qubes wont work)
Blob status: video+EC but people are apparently working on freeing them
and the IOMMU protects you from any DMA issues.
--
You received this message because you are subscribed to the Google Groups "qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscribe@googlegroups.com.
To post to this group, send email to qubes...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/b13a5dc1-e446-888c-4d96-1e62abdf7e0b%40gmx.com.
>Nice! glad that still works
Ericsson F5521gw - 3G/GPS/HSPA work out of box in a dedicated USB VM but only clearnet/VPN/wireguard. For Whonix and Tor need reed this
https://www.whonix.org/wiki/Security_Guide#Anonymous_Mobile_Modems.
So, You can sit in the forest next to the telecommunications tower))
>The RPI is not an open source firmware device FYI and I recommend
instead purchasing a beagleboard or novena.
>G505S:
* pre-PSP AMD quad core cpu (the A10 model - the others suck)
* coreboot with open cpu/ram init (unlike the blobbed puri-craptop hw
init via the intel fsp binary blob)
* IOMMU that works with qubes 4.0 (Must apply latest microcode updates
or qubes wont work)
Blob status: video+EC but people are apparently working on freeing them
and the IOMMU protects you from any DMA issues.
Thanks for info :)
I first wanted to take a try one W520 (i7 quadcore coreboot/32GB ram and Quadro 1000m/2000m)
but
http://www.cs.utexas.edu/~hyu/publication/pdf/wddd17.pdf
https://wiki.xen.org/wiki/Xen_VGA_Passthrough_Tested_Adapters
This cards not listed and intel news are sad:(
So, idea - gpu passthrouth to hvm ?! unsuccessful
I have 16GB ram - Xentop says 15GB are used
11 domains: 2 running, 9 blocked, 0 paused.
Mem 16696288k total, 15389884k used, 1306404k free.
which is quite enough, but hvm maybe eat more ram.
but now I think it might be better to buy G505S for comparison :)
Thanks :)