-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
If someone compromised dom0, then they would have to firstly have
compromised some AppVM in order to run arbitrary code. They would then
have to use some zero-day in Xen in order to break out of the
hypervisor (hard but possible). To this extent they would have to be
very sophisticated, probably working for a nation-state.
If they compromise dom0, they could well compromise the BIOS and run
persistent rootkits. You probably have quite a lot on your plate in
that case. I would probably nuke it and start over on a new computer,
preferably running Libreboot with proper flash write protection. The
only files that really matter to me are documents I have backed up and
private keys. If they can run code in dom0 then assume private keys
are compromised, so there would no need to restore from AppVM backup
(you should make backups when you generate the key) as you would
revoke it.
Just back up with Qubes tools, assuming dom0 is clean. It is really
hard to compromise dom0 so you as an average person would probably be
all right.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBCAAGBQJXg7oLAAoJEPs8tiiQ8FTAzvcP/2AlNXIesVabiqBjs/soU0fx
aItAXM30Wad1ynsTVWwaTe9WEjwi2ZoZ+vVaN9NNzp/xRtdolCf/GkUTPJooEz0O
/oK+q3PSXp9cHjd9QlcV30g52LmeYGVNYLg4RXiM950q6ybqkz2rlBVArHMG7h2N
tFTilk1iBcE+HCSEIKF1onSrV3RfNE7uu1jE1W/OjYiDRIZADfJ96lpC+V1iFTDZ
Nr7/GZOPR4zndVvwJka8wuiy4Iqg+ksjv9wpi86n8ysZyB8A34nMHigqkxwZNhhh
ZkyM0feoB4/4GsasEG/TFgzeTc8vKwbU+6Y/U+QePLFMIH9U5OyOdrbtNgqIcaAu
+LV3Xm4wmiPbYqEsVq7H6QruGjTcahpPGdZ2+fM/26SNbx4WZv28rGZEvC8qud3Q
Hhsrv8jvgIxnNmhnskieAcNGfGC13qlqAX/rjL1YrgQT7oYn5TSZMYmygvMgdUx3
hHC+k9qgewcon8LdUq/UJtksBM9UIL/vDDw6t04gunBMsfwhwV72lCFNTm3SnUU0
/uPSkkw2hISoBx+pCzlJUFDlHsOvdB7Fg3AZ6qFDdTUDBWRJhtjGS3EF1UJqEj7t
7UJmr/HWuLycEGfTSwmjJGKxilJqIm+YE/aLS43wkcRPLPdqsxVULV9w9eTGVlgc
6CALd0uOTWlhuhiVr8sy
=VfQO
-----END PGP SIGNATURE-----