On Mon, May 11, 2020 at 12:01:49PM +0000, Logan wrote:
> --
> You received this message because you are subscribed to the Google Groups "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to
qubes-users...@googlegroups.com.
> To view this discussion on the web visit
https://groups.google.com/d/msgid/qubes-users/e6af715a-fe00-46ec-ddde-24748076ad2b%40threatmodel.io.
> <html>
> <head>
> <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
> </head>
> <body>
> <div class="moz-cite-prefix">Would you be willing to share the URL
> here? If not, could you message me privately? I'm definitely
> interested in reading it.<br>
> <br>
> -Logan<br>
> </div>
> <div class="moz-cite-prefix"><br>
> </div>
> <div class="moz-cite-prefix">On 5/11/20 11:58 AM, Mark Fernandes
> wrote:<br>
> </div>
> <blockquote type="cite"
> cite="
mid:be02e5ea-f7a5-473b...@googlegroups.com">
> <meta http-equiv="content-type" content="text/html; charset=UTF-8">
> <div dir="ltr">On Monday, 11 May 2020 12:08:22 UTC+1, unman wrote:
> <blockquote class="gmail_quote" style="margin: 0;margin-left:
> 0.8ex;border-left: 1px #ccc solid;padding-left: 1ex;">??<br>
> </blockquote>
> <blockquote class="gmail_quote" style="margin: 0;margin-left:
> 0.8ex;border-left: 1px #ccc solid;padding-left: 1ex;">....
> Depending on your machine you
> <br>
> may be able to find ways to do this, by installing a kill
> switch, or by
> <br>
> BIOS configuration.
> <br>
> You may find that your BIOS allows you to disable certain
> devices pre
> <br>
> boot, and this may enable you to switch between active disks.??</blockquote>
> <blockquote class="gmail_quote" style="margin: 0;margin-left:
> 0.8ex;border-left: 1px #ccc solid;padding-left: 1ex;">....</blockquote>
> <div><br>
> </div>
> <div>I'm by no means an expert on Qubes or this particular
> issue. However, I am in the midst of writing a Wikibooks book
> on cost-effective end-user security that has a section about
> this. My thoughts in the book are more like RFCs (requests for
> comments) rather than definitive ideas (my hope is that other
> people will further develop, revise, and correct them, as
> applicable). <b>Please take that into account when reading
> them.</b> The section is shown below.</div>
> <div><br>
> </div>
> <div><span
> id="docs-internal-guid-5cb878be-7fff-1d6d-bc3d-05d7880773a7">
> <hr></span></div>
> <div><span
> id="docs-internal-guid-83215b1d-7fff-5294-3335-b19118084401"><span style="font-size: 12pt; font-family: Arial; color: rgb(102, 102, 102); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">
> </span>
> <h4 dir="ltr" style="line-height:1.38;text-indent:
> 36pt;margin-top:14pt;margin-bottom:4pt;"><a
> href="
https://en.wikipedia.org/wiki/Qubes_OS"
> moz-do-not-send="true"><span style="font-size: 12pt; font-family: Arial; color: rgb(102, 102, 102); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">Qubes OS 4.0.3</span></a><span style="font-size: 12pt; font-family: Arial; color: rgb(102, 102, 102); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> side-by-side with other </span><a
> href="
https://en.wikipedia.org/wiki/Operating_system"
> moz-do-not-send="true"><span style="font-size: 12pt; font-family: Arial; color: rgb(102, 102, 102); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">operating systems</span></a></h4>
> <p dir="ltr" style="line-height:1.38;margin-left:
> 36pt;margin-top:0pt;margin-bottom:0pt;"><a
> href="
https://en.wikipedia.org/wiki/Qubes_OS"
> moz-do-not-send="true"><span style="font-size: 11pt; font-family: Arial; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">Qubes OS 4.0.3</span></a><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> is </span><a
> href="
https://www.qubes-os.org/faq/index.html#can-i-run-applications-like-games-which-require-3d-support"
> moz-do-not-send="true"><span style="font-size: 11pt; font-family: Arial; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">documented as not coping well</span></a><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> with </span><a
> href="
https://en.wikipedia.org/wiki/Software"
> moz-do-not-send="true"><span style="font-size: 11pt; font-family: Arial; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">software</span></a><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> that specifically benefits from </span><a
> href="
https://en.wikipedia.org/wiki/Hardware_acceleration"
> moz-do-not-send="true"><span style="font-size: 11pt; font-family: Arial; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">3D-optimised hardware</span></a><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">. Since a user may well want to use such optimisation, the best way to use such optimisation on the same machine might be to do something like, or the same as, the following:</span></p>
> <br>
> <ol style="margin-top:0;margin-bottom:0;">
> <li dir="ltr" style="list-style-type: decimal; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;" role="presentation"><a href="
https://en.wikipedia.org/wiki/Installation_(computer_programs)" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">Install</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> a </span><a href="
https://en.wikipedia.org/wiki/Linux" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">Linux</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> </span><a href="
https://en.wikipedia.org/wiki/Operating_system" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">operating system</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">, with good security but still with the capacity for being able to utilise 3D-optimised hardware, on an </span><a href="
https://en.wikipedia.org/wiki/SSD" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">SSD</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> external </span><a href="
https://en.wikipedia.org/wiki/Data_storage" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">drive</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">, such that this other operating system is not run over Qubes, but instead run separate to Qubes.</span></p></li>
> <li dir="ltr" style="list-style-type: decimal; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:5pt;" role="presentation"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">When wanting to use this other Linux OS, disable the internal drive (containing Qubes) in either:</span></p></li>
> <ol style="margin-top:0;margin-bottom:0;">
> <li dir="ltr" style="list-style-type: lower-alpha; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:10pt;" role="presentation"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">the </span><a href="
https://en.wikipedia.org/wiki/BIOS" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">BIOS</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">,??????</span></p></li>
> </ol>
> </ol>
> <p dir="ltr" style="line-height:1.38;margin-left:
> 108pt;margin-top:0pt;margin-bottom:10pt;"><span style="font-size: 11pt; font-family: Arial; color: rgb(153, 153, 153); background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">??????????????OR IF WISHING TO BE MORE SECURE,</span></p>
> <ol style="margin-top:0;margin-bottom:0;" start="3">
> <ol style="margin-top:0;margin-bottom:0;" start="2">
> <li dir="ltr" style="list-style-type: lower-alpha; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;" role="presentation"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">both the BIOS??</span></p></li>
> </ol>
> </ol>
> <p dir="ltr" style="line-height:1.38;margin-left:
> 108pt;text-indent: 36pt;margin-top:0pt;margin-bottom:0pt;"><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">as well as by physically disconnecting the internal drive</span></p>
> <p dir="ltr" style="line-height:1.38;margin-left:
> 108pt;text-indent: 36pt;text-align:
> right;margin-top:0pt;margin-bottom:0pt;"><span style="font-size: 11pt; font-family: Arial; color: rgb(153, 153, 153); background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">(this latter option might be a good idea to do??</span></p>
> <p dir="ltr" style="line-height:1.38;margin-left:
> 108pt;text-indent: 36pt;text-align:
> right;margin-top:0pt;margin-bottom:0pt;"><span style="font-size: 11pt; font-family: Arial; color: rgb(153, 153, 153); background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">because </span><a
> href="
https://en.wikipedia.org/wiki/Malware"
> moz-do-not-send="true"><span style="font-size: 11pt; font-family: Arial; background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">malware</span></a><span style="font-size: 11pt; font-family: Arial; color: rgb(153, 153, 153); background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> in a BIOS's </span><a
> href="
https://en.wikipedia.org/wiki/Firmware"
> moz-do-not-send="true"><span style="font-size: 11pt; font-family: Arial; background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">firmware</span></a><span style="font-size: 11pt; font-family: Arial; color: rgb(153, 153, 153); background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">??</span></p>
> <p dir="ltr" style="line-height:1.38;margin-left:
> 108pt;text-indent: 36pt;text-align:
> right;margin-top:0pt;margin-bottom:5pt;"><span style="font-size: 11pt; font-family: Arial; color: rgb(153, 153, 153); background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">can still connect to BIOS-disabled drives).</span></p>
> <ol style="margin-top:0;margin-bottom:0;" start="3">
> <li dir="ltr" style="list-style-type: decimal; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;" role="presentation"><a href="
https://en.wikipedia.org/wiki/Booting" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">Boot</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> off the SSD to run this other Linux.</span></p></li>
> <li dir="ltr" style="list-style-type: decimal; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;" role="presentation"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">After using the non-Qubes installation, because of the possibility of malware being introduced into the BIOS firmware by the non-Qubes installation, optionally </span><a href="
https://en.wikipedia.org/wiki/BIOS#Reprogramming" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">flash</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> the BIOS's firmware to ensure better the Qubes installation isn???t compromised through firmware </span><a href="
https://en.wikipedia.org/wiki/Malware" moz-do-not-send="true"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; text-decoration-line: underline; text-decoration-skip-ink: none; vertical-align: baseline; white-space: pre-wrap;">malware</span></a><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"> when you next use Qubes.</span></p></li>
> </ol>
> <br>
> <p dir="ltr" style="line-height:1.38;margin-left:
> 36pt;margin-top:0pt;margin-bottom:5pt;"><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">By following the above steps, and choosing the most secure options in the steps, because of:</span></p>
> <ul style="margin-top:0;margin-bottom:0;">
> <li dir="ltr" style="list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;" role="presentation"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">the disabling of the internal drive via the BIOS,</span></p></li>
> <li dir="ltr" style="list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.7999999999999998;margin-top:0pt;margin-bottom:0pt;" role="presentation"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">the physical disconnection of the drive containing the Qubes installation, ?? </span><span style="font-size: 18pt; color: rgb(153, 153, 153); background-color: transparent; font-style: italic; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;"><span style="font-size:0.6em;vertical-align:sub;">and</span></span></p></li>
> <li dir="ltr" style="list-style-type: disc; font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre; margin-left: 36pt;"><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:10pt;" role="presentation"><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">the flashing of the BIOS firmware before the ???reconnection??? of the </span><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">
> </span><span style="font-size: 11pt; background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">Qubes installation,</span></p></li>
> </ul>
> <p dir="ltr" style="line-height:1.38;margin-left:
> 36pt;margin-top:0pt;margin-bottom:0pt;"><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">any such other OS should not be able to access or even ???touch??? the Qubes OS installation, thereby hopefully safeguarding the Qubes installation from attacks conducted through the other presumably-less-secure OS.</span></p>
> <div><span style="font-size: 11pt; font-family: Arial; color: rgb(0, 0, 0); background-color: transparent; font-variant-numeric: normal; font-variant-east-asian: normal; vertical-align: baseline; white-space: pre-wrap;">
> </span></div>
> </span></div>
> <div><br>
> </div>
> <div><span
> id="docs-internal-guid-5cb878be-7fff-1d6d-bc3d-05d7880773a7">
> <hr><br>
> </span></div>
> <div><span><br>
> </span></div>
> <div><span>Kind regards,</span></div>
> <div><span><br>
> </span></div>
> <div><span><br>
> </span></div>
> <div><span>Mark Fernandes</span></div>
> </div>
> -- <br>
> You received this message because you are subscribed to the Google
> Groups "qubes-users" group.<br>
> To unsubscribe from this group and stop receiving emails from it,
> send an email to <a
> href="mailto:
qubes-users...@googlegroups.com"
> moz-do-not-send="true">
qubes-users...@googlegroups.com</a>.<br>
> To view this discussion on the web visit <a
> href="
https://groups.google.com/d/msgid/qubes-users/be02e5ea-f7a5-473b-9fd0-1d06a9223f0c%40googlegroups.com?utm_medium=email&utm_source=footer"
> moz-do-not-send="true">
https://groups.google.com/d/msgid/qubes-users/be02e5ea-f7a5-473b-9fd0-1d06a9223f0c%40googlegroups.com</a>.<br>
> </blockquote>
> <p><br>
> </p>
> </body>
> </html>
>
> <p></p>
>
> -- <br />
> You received this message because you are subscribed to the Google Groups "qubes-users" group.<br />
> To unsubscribe from this group and stop receiving emails from it, send an email to <a href="mailto:
qubes-users...@googlegroups.com">
qubes-users...@googlegroups.com</a>.<br />
> To view this discussion on the web visit <a href="
https://groups.google.com/d/msgid/qubes-users/e6af715a-fe00-46ec-ddde-24748076ad2b%40threatmodel.io?utm_medium=email&utm_source=footer">
https://groups.google.com/d/msgid/qubes-users/e6af715a-fe00-46ec-ddde-24748076ad2b%40threatmodel.io</a>.<br />
Screeds and screeds of HTML.
Can you NOT do this?
Look at your settings and change to "plain text", at least for this
list, please