Question about the SECURITY of backing up QUBES.

65 views
Skip to first unread message

neilh...@gmail.com

unread,
Jul 11, 2016, 9:54:02 AM7/11/16
to qubes-users
I have a question about the security of backing up QUBES.

I see that the VM backup procedure lets you back up both template VMs and App VMs, as well as dom0.

The question is... let's say that we find out about another Xen escape, like the one from October 2015.

At this point, surely we now the consider that the entire system was compromised.

So let's then say that we download an entirely new version of QUBES, and upgrade to the latest Xen before doing anything else.

What is then the backup procedure for templates and App VMs..?

Surely this means that it's not safe to restore the backed up VMs.. seeing as they were present on the old compromised machine?

Or what..?

Alex

unread,
Jul 11, 2016, 10:07:17 AM7/11/16
to qubes...@googlegroups.com
If the new version patches the holes, the problems are contained; dom0
restore only works on files in the home directory, so the user should
make sure there is nothing relevant in his/her .bash_profile and
.bashrc, and they should be ok. One can even avoid restoring dom0 in a
first stage, and proceed only later when he's sure the dom0 backup is
safe. One way to do this would be to manually extract the files (there
should be only a few) and check them.

Should any template be compromised, the special care would be to start
it only to get the list of manually-installed packages and
customizations to manually apply them to a clean version of the same
template/os.

A thing to avoid would be restoring possibly-compromised templates that
act as base for netVM/firewallVM: if anything malicious persisted there,
they could contact a C&C center to download updated attacks or payloads.
Payloads would be lost upon vm reboot, but they may pose additional
hurdles to overcome and/or slow down network operations.

As for appVMs, if the threat is fully known, the AppVM may be started
and cleaned (there should be nothing persistent and dangerous apart from
autostarting scripts in the home directory of the user).

Summing up from my digressions, a nice feature that could help in
assisting this scenario would be a restore tool that allows for
decompression of files that would end up in dom0 into a dispVM, so that
they can be analyzed for malicious autostart scripts.

The rest seems pretty standard to me...

--
Alex

signature.asc

neilh...@gmail.com

unread,
Jul 11, 2016, 10:14:24 AM7/11/16
to qubes-users, alex...@gmx.com
Is it possible that someone who compromised QUBES, could re-write the AppVM in a way that whenever it is loaded up, it re-infects the entire system all over again...?

In that case, the only safe thing would be to manually back up the files within the AppVM with some sort of Fedora backup tool.

Or is that not an issue... and it's safe to just back up the entire AppVM using the QUBES tool...?

Chris Laprise

unread,
Jul 11, 2016, 11:24:11 AM7/11/16
to neilh...@gmail.com, qubes-users, alex...@gmx.com
On 07/11/2016 10:14 AM, neilh...@gmail.com wrote:
> Is it possible that someone who compromised QUBES, could re-write the AppVM in a way that whenever it is loaded up, it re-infects the entire system all over again...?

Excellent question. Let me just say that the restore would include other
files that are used directly by dom0... a potential problem. If you
wanted to truly protect dom0 in such a case, you could try manually
extracting the appvm's private.img from the backup. Then you could
create a new empty appvm, and move the restored img into that.

> In that case, the only safe thing would be to manually back up the files within the AppVM with some sort of Fedora backup tool.

If you really think dom0 had been compromised, that could be safer.

> Or is that not an issue... and it's safe to just back up the entire AppVM using the QUBES tool...?

Chris

Duncan Guthrie

unread,
Jul 11, 2016, 11:24:59 AM7/11/16
to qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
If someone compromised dom0, then they would have to firstly have
compromised some AppVM in order to run arbitrary code. They would then
have to use some zero-day in Xen in order to break out of the
hypervisor (hard but possible). To this extent they would have to be
very sophisticated, probably working for a nation-state.
If they compromise dom0, they could well compromise the BIOS and run
persistent rootkits. You probably have quite a lot on your plate in
that case. I would probably nuke it and start over on a new computer,
preferably running Libreboot with proper flash write protection. The
only files that really matter to me are documents I have backed up and
private keys. If they can run code in dom0 then assume private keys
are compromised, so there would no need to restore from AppVM backup
(you should make backups when you generate the key) as you would
revoke it.
Just back up with Qubes tools, assuming dom0 is clean. It is really
hard to compromise dom0 so you as an average person would probably be
all right.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJXg7oLAAoJEPs8tiiQ8FTAzvcP/2AlNXIesVabiqBjs/soU0fx
aItAXM30Wad1ynsTVWwaTe9WEjwi2ZoZ+vVaN9NNzp/xRtdolCf/GkUTPJooEz0O
/oK+q3PSXp9cHjd9QlcV30g52LmeYGVNYLg4RXiM950q6ybqkz2rlBVArHMG7h2N
tFTilk1iBcE+HCSEIKF1onSrV3RfNE7uu1jE1W/OjYiDRIZADfJ96lpC+V1iFTDZ
Nr7/GZOPR4zndVvwJka8wuiy4Iqg+ksjv9wpi86n8ysZyB8A34nMHigqkxwZNhhh
ZkyM0feoB4/4GsasEG/TFgzeTc8vKwbU+6Y/U+QePLFMIH9U5OyOdrbtNgqIcaAu
+LV3Xm4wmiPbYqEsVq7H6QruGjTcahpPGdZ2+fM/26SNbx4WZv28rGZEvC8qud3Q
Hhsrv8jvgIxnNmhnskieAcNGfGC13qlqAX/rjL1YrgQT7oYn5TSZMYmygvMgdUx3
hHC+k9qgewcon8LdUq/UJtksBM9UIL/vDDw6t04gunBMsfwhwV72lCFNTm3SnUU0
/uPSkkw2hISoBx+pCzlJUFDlHsOvdB7Fg3AZ6qFDdTUDBWRJhtjGS3EF1UJqEj7t
7UJmr/HWuLycEGfTSwmjJGKxilJqIm+YE/aLS43wkcRPLPdqsxVULV9w9eTGVlgc
6CALd0uOTWlhuhiVr8sy
=VfQO
-----END PGP SIGNATURE-----

Alex

unread,
Jul 11, 2016, 12:01:56 PM7/11/16
to qubes...@googlegroups.com
On 07/11/2016 05:24 PM, Duncan Guthrie wrote:
> On 11/07/16 15:14, neilh...@gmail.com wrote:
>> Is it possible that someone who compromised QUBES, could re-write
>> the AppVM in a way that whenever it is loaded up, it re-infects the
>> entire system all over again...?
>
>
> If someone compromised dom0, then they would have to firstly have
> compromised some AppVM in order to run arbitrary code. They would
> [....]
> the key) as you would revoke it. Just back up with Qubes tools,
> assuming dom0 is clean. It is really hard to compromise dom0 so you
> as an average person would probably be all right.
I agree, it is extremely hard to actually compromise dom0 (i.e., escape
Xen), and this type of attack will likely have to be so targeted that it
will most likely affect ring -2/-3 (System Management Mode / Management
Engine), so a simple restore will not be enough. A new machine will be
better, and a completely free/libre hardware platform is the top of line
for this paranoia.

Still I agree with Duncan, this easily borders on paranoia, and then we
have the good ol' thermorectal cryptanalysis, which would be way more
cost-effective than crafting such a complicated piece of software.

To answer your actual question, it would not be possible to re-write an
AppVM to re-infect the system if the hole through which the system was
hacked in the first place is fixed before restoring the backup. There
would be no good in formatting and restoring the backup, only a waste of
time, if you are not going to fix the hole.

It is possible to write auto-starting code in your AppVM, just add your
commands to .bashrc / .bash_profile in your home directory (which is
persisted across reboots).

--
Alex

signature.asc
Reply all
Reply to author
Forward
0 new messages