Re: [qubes-users] XSA-273 - Impact on Qubes?

2018-09-01 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-08-25 16:50, Rusty Bird wrote: > Rob Fisher: >> I'm wondering when we can expect information on the impact of XSA-273 (1) on >> Qubes R4? > > I'd guess early next month: > https://groups.google.com/d/msg/qubes-users/Isn_hko7tQs/PcqIuUleEQAJ

Re: [qubes-users] XSA-273 - Impact on Qubes?

2018-08-26 Thread Rusty Bird
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Ivan Mitev: > On 08/26/2018 12:50 AM, Rusty Bird wrote: > > Rob Fisher: > >> what are the best options for a Qubes user right now? > > > > - - Add smt=off as a Xen boot parameter (which disables hyperthreading) > > smt=off doesn't seem to work

Re: [qubes-users] XSA-273 - Impact on Qubes?

2018-08-26 Thread Ivan Mitev
On 08/26/2018 12:50 AM, Rusty Bird wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Rob Fisher: >> I'm wondering when we can expect information on the impact of XSA-273 (1) on >> Qubes R4? > > I'd guess early next month: >

Re: [qubes-users] XSA-273 - Impact on Qubes?

2018-08-25 Thread Rusty Bird
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 'awokd' via qubes-users: > > Rob Fisher: > >> what are the best options for a Qubes user right now? ^ > Get Qubes running on non-x86 architectures less prone to > vulnerabilities! Don't hold

Re: [qubes-users] XSA-273 - Impact on Qubes?

2018-08-25 Thread 'awokd' via qubes-users
On Sat, August 25, 2018 9:50 pm, Rusty Bird wrote: > Rob Fisher: >> what are the best options for a Qubes user right now? > > - - Add smt=off as a Xen boot parameter (which disables hyperthreading) > to make the attack harder? - - If you're worried that some VM might want to > steal data from

Re: [qubes-users] XSA-273 - Impact on Qubes?

2018-08-25 Thread Rusty Bird
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Rob Fisher: > I'm wondering when we can expect information on the impact of XSA-273 (1) on > Qubes R4? I'd guess early next month: https://groups.google.com/d/msg/qubes-users/Isn_hko7tQs/PcqIuUleEQAJ > what are the best options for a Qubes user

[qubes-users] XSA-273 - Impact on Qubes?

2018-08-25 Thread Rob Fisher
I'm wondering when we can expect information on the impact of XSA-273 (1) on Qubes R4? I can't help but notice it's absence from the Qubes XSA-tracker page (2). Some OS Vendors have implemented kernel patches in an attempt to mitigate these vulnerabilities, but as of yet I haven't seen any