On Friday, May 26, 2017 at 1:26:27 PM UTC-4, Eric Duncan wrote:
> Thank you.  But, my question was more about how Qubes gets installed and does 
> it use any system properties to customize the install?
> 
> 
> I know what you are saying though.  If running Windows/macOS, a piece of 
> firmware of a device (or bios) could be infected.  And when booting Qubes 
> from the external device, it could infect it.
> 
> Then again, that argument could be made against 100% of all PCs, laptops, 
> motherboards of custom builds, etc - even brand new devices.  So are you ever 
> safe?  Perhaps if you built your own device from scratch and coded your own 
> BIOS.  
> 
> The edge case you mention would most likely be valid only from a targeted 
> attack, not part of a toolkit.  
> 
> Say if a state actor wanted access to my Qubes install, they would need to 
> know some very specific information:
> 
> * specific macbook with specific hardware (very likely, AppleCare registered 
> and all, blogging/bragging of hardware used, etc).  
> * the exact mSATA drive and USB device I use for Qubes OS (very likely, I can 
> just blog about it - or they can get NewEgg purchase history).  
> * knowledge of exact firmware versions installed on those devices.
> 
> Virtually, they would need to exploit some Windows/macOS 0-day to gain access 
> to the machine (somewhat likely, sure).  Physically, they would need to 
> evil-maid my machines when we are gone on vacation or something (plausible, 
> sure).
> 
> The attack would have to look like this:
> 
> 1) They could devise a custom mSATA firmware to install onto the device.  
> Well, that would require me having the Qubes OS usb device attached when 
> booting under some other OS installed on that machine.  So, always disconnect 
> it before booting native OS.  Easy.
> 
> 2) They could use the exploit to infect the BIOS, or Nvidia GPU firmware - 
> something that would boot when booting the Qubes install. 
> 
> 2A) that could install a keylogger, to gain access to the /boot LUKS 
> partition password (like an evil-maid attack).  plausible, yes - at a very 
> edge case.
> 
> 2B) that could install some other firmware installer, that waits for the 
> linux kernel to boot and then side-loads itself into the boot process, or 
> exploit some Qubes 0-day to gain root on the device.  very unlikely, but 
> plausible, yes.
> 
> So plausible? Sure, with explicit details in hand. 
> 
> But that is acceptable to me as the level of sophistication required to pull 
> off that level of attack, with knowledge of devices and their exact firmware 
> versions, most likely would only come from state actors.  (*cough* Stuxnet 
> *cough*)
> 
> If you are worried about state actors, then yes format your machines and 
> install only Qubes.
> 
> -E
> 
> 
> 
> 
> On Thursday, May 25, 2017 at 11:14:30 PM UTC-4, cooloutac wrote:
> > On Thursday, May 25, 2017 at 1:00:18 PM UTC-4, Eric Duncan wrote:
> > > Hello:
> > > 
> > > Does Quebes perform a machine-specific installation?  IOWs, can I install 
> > > Quebes on a single USB device and share it across different machine 
> > > setups?
> > > 
> > > E.g. if I install Qubes on an 8 core desktop, w/64GB ram, SSD (just keep 
> > > it simple - only 1 SSD), Nvidia GPUs, etc - can I then take that exact 
> > > same install and boot it in my Core i7 dual-core tablet with only 8 gb of 
> > > ram without any issues?
> > > 
> > > I ask because of two reasons:
> > > 
> > > * I cannot format entire HDDs to dedicate to Qubes OS.  I still do some 
> > > Windows 10, iOS and Linux development and need macOS for other various 
> > > things.  A dual-boot setup is not "secure."
> > > 
> > > * I was thinking of setting up an mSATA drive and USB3 adapter for 
> > > Quebes, encrypt the partitions and evil-maid protection and etc, and boot 
> > > it in multiple devices.
> > > 
> > > I currently have it installed as a dual-boot on my Lenovo Helix (full 
> > > support for 4.x btw!).  But, I'd like to boot Quebes on my desktop and 
> > > other machines I use...
> > > 
> > > ...while keeping it secure, by using the entire mSATA drive for Quebes.
> > > 
> > > Thanks in advance!
> > > -E
> > > 
> > > Ps, I have already attempted to try this with a USB3 stick and had 
> > > possibly unrelated failures.  Hence, why I am asking about the 
> > > installation process and hardware configurations- if any.  
> > > 
> > > Before I invest into an external drive setup, I'd like to know if there 
> > > are any foreseen issues first.
> > 
> > I'm not sure it would really be keeping it secure that way either.  dual 
> > boot is not only unsafe cause it can change /boot but also because other os 
> > could infect hardware.   In other words windows or mac could infect the 
> > firmware or netcard, gpu, cdrom, etc... which could then sniff or infect 
> > your usb installation.

well yes,  but then you couldn't blame the other os,  which does not 
protect/isolate the hardware as well as Qubes.

and ya, look at the latest intel news, just confirms what some already assume.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/527c7623-cec7-41ba-9223-6c4244115fa9%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to