On 07/11/2016 05:24 PM, Duncan Guthrie wrote: > On 11/07/16 15:14, [email protected] wrote: >> Is it possible that someone who compromised QUBES, could re-write >> the AppVM in a way that whenever it is loaded up, it re-infects the >> entire system all over again...? > > > If someone compromised dom0, then they would have to firstly have > compromised some AppVM in order to run arbitrary code. They would > [....] > the key) as you would revoke it. Just back up with Qubes tools, > assuming dom0 is clean. It is really hard to compromise dom0 so you > as an average person would probably be all right. I agree, it is extremely hard to actually compromise dom0 (i.e., escape Xen), and this type of attack will likely have to be so targeted that it will most likely affect ring -2/-3 (System Management Mode / Management Engine), so a simple restore will not be enough. A new machine will be better, and a completely free/libre hardware platform is the top of line for this paranoia.
Still I agree with Duncan, this easily borders on paranoia, and then we have the good ol' thermorectal cryptanalysis, which would be way more cost-effective than crafting such a complicated piece of software. To answer your actual question, it would not be possible to re-write an AppVM to re-infect the system if the hole through which the system was hacked in the first place is fixed before restoring the backup. There would be no good in formatting and restoring the backup, only a waste of time, if you are not going to fix the hole. It is possible to write auto-starting code in your AppVM, just add your commands to .bashrc / .bash_profile in your home directory (which is persisted across reboots). -- Alex -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/01efd248-1b4b-2f24-fb37-0439f1e47246%40gmx.com. For more options, visit https://groups.google.com/d/optout.
signature.asc
Description: OpenPGP digital signature
