On 07/11/2016 03:54 PM, [email protected] wrote: > I have a question about the security of backing up QUBES. > > I see that the VM backup procedure lets you back up both template VMs > and App VMs, as well as dom0. > > The question is... let's say that we find out about another Xen > escape, like the one from October 2015. > > At this point, surely we now the consider that the entire system was > compromised. > > So let's then say that we download an entirely new version of QUBES, > and upgrade to the latest Xen before doing anything else. > > What is then the backup procedure for templates and App VMs..? > > Surely this means that it's not safe to restore the backed up VMs.. > seeing as they were present on the old compromised machine? > > Or what..? > If the new version patches the holes, the problems are contained; dom0 restore only works on files in the home directory, so the user should make sure there is nothing relevant in his/her .bash_profile and .bashrc, and they should be ok. One can even avoid restoring dom0 in a first stage, and proceed only later when he's sure the dom0 backup is safe. One way to do this would be to manually extract the files (there should be only a few) and check them.
Should any template be compromised, the special care would be to start it only to get the list of manually-installed packages and customizations to manually apply them to a clean version of the same template/os. A thing to avoid would be restoring possibly-compromised templates that act as base for netVM/firewallVM: if anything malicious persisted there, they could contact a C&C center to download updated attacks or payloads. Payloads would be lost upon vm reboot, but they may pose additional hurdles to overcome and/or slow down network operations. As for appVMs, if the threat is fully known, the AppVM may be started and cleaned (there should be nothing persistent and dangerous apart from autostarting scripts in the home directory of the user). Summing up from my digressions, a nice feature that could help in assisting this scenario would be a restore tool that allows for decompression of files that would end up in dom0 into a dispVM, so that they can be analyzed for malicious autostart scripts. The rest seems pretty standard to me... -- Alex -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/c113f36b-0806-a038-75e7-aed93f6735d8%40gmx.com. For more options, visit https://groups.google.com/d/optout.
signature.asc
Description: OpenPGP digital signature
