On Friday, May 26, 2017 at 1:26:27 PM UTC-4, Eric Duncan wrote: > Thank you. But, my question was more about how Qubes gets installed and does > it use any system properties to customize the install? > > > I know what you are saying though. If running Windows/macOS, a piece of > firmware of a device (or bios) could be infected. And when booting Qubes > from the external device, it could infect it. > > Then again, that argument could be made against 100% of all PCs, laptops, > motherboards of custom builds, etc - even brand new devices. So are you ever > safe? Perhaps if you built your own device from scratch and coded your own > BIOS. > > The edge case you mention would most likely be valid only from a targeted > attack, not part of a toolkit. > > Say if a state actor wanted access to my Qubes install, they would need to > know some very specific information: > > * specific macbook with specific hardware (very likely, AppleCare registered > and all, blogging/bragging of hardware used, etc). > * the exact mSATA drive and USB device I use for Qubes OS (very likely, I can > just blog about it - or they can get NewEgg purchase history). > * knowledge of exact firmware versions installed on those devices. > > Virtually, they would need to exploit some Windows/macOS 0-day to gain access > to the machine (somewhat likely, sure). Physically, they would need to > evil-maid my machines when we are gone on vacation or something (plausible, > sure). > > The attack would have to look like this: > > 1) They could devise a custom mSATA firmware to install onto the device. > Well, that would require me having the Qubes OS usb device attached when > booting under some other OS installed on that machine. So, always disconnect > it before booting native OS. Easy. > > 2) They could use the exploit to infect the BIOS, or Nvidia GPU firmware - > something that would boot when booting the Qubes install. > > 2A) that could install a keylogger, to gain access to the /boot LUKS > partition password (like an evil-maid attack). plausible, yes - at a very > edge case. > > 2B) that could install some other firmware installer, that waits for the > linux kernel to boot and then side-loads itself into the boot process, or > exploit some Qubes 0-day to gain root on the device. very unlikely, but > plausible, yes. > > So plausible? Sure, with explicit details in hand. > > But that is acceptable to me as the level of sophistication required to pull > off that level of attack, with knowledge of devices and their exact firmware > versions, most likely would only come from state actors. (*cough* Stuxnet > *cough*) > > If you are worried about state actors, then yes format your machines and > install only Qubes. > > -E > > > > > On Thursday, May 25, 2017 at 11:14:30 PM UTC-4, cooloutac wrote: > > On Thursday, May 25, 2017 at 1:00:18 PM UTC-4, Eric Duncan wrote: > > > Hello: > > > > > > Does Quebes perform a machine-specific installation? IOWs, can I install > > > Quebes on a single USB device and share it across different machine > > > setups? > > > > > > E.g. if I install Qubes on an 8 core desktop, w/64GB ram, SSD (just keep > > > it simple - only 1 SSD), Nvidia GPUs, etc - can I then take that exact > > > same install and boot it in my Core i7 dual-core tablet with only 8 gb of > > > ram without any issues? > > > > > > I ask because of two reasons: > > > > > > * I cannot format entire HDDs to dedicate to Qubes OS. I still do some > > > Windows 10, iOS and Linux development and need macOS for other various > > > things. A dual-boot setup is not "secure." > > > > > > * I was thinking of setting up an mSATA drive and USB3 adapter for > > > Quebes, encrypt the partitions and evil-maid protection and etc, and boot > > > it in multiple devices. > > > > > > I currently have it installed as a dual-boot on my Lenovo Helix (full > > > support for 4.x btw!). But, I'd like to boot Quebes on my desktop and > > > other machines I use... > > > > > > ...while keeping it secure, by using the entire mSATA drive for Quebes. > > > > > > Thanks in advance! > > > -E > > > > > > Ps, I have already attempted to try this with a USB3 stick and had > > > possibly unrelated failures. Hence, why I am asking about the > > > installation process and hardware configurations- if any. > > > > > > Before I invest into an external drive setup, I'd like to know if there > > > are any foreseen issues first. > > > > I'm not sure it would really be keeping it secure that way either. dual > > boot is not only unsafe cause it can change /boot but also because other os > > could infect hardware. In other words windows or mac could infect the > > firmware or netcard, gpu, cdrom, etc... which could then sniff or infect > > your usb installation.
well yes, but then you couldn't blame the other os, which does not protect/isolate the hardware as well as Qubes. and ya, look at the latest intel news, just confirms what some already assume. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/527c7623-cec7-41ba-9223-6c4244115fa9%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
