On Sat, Jun 24, 2017 at 12:16 PM, Alan Got <[email protected]> wrote:

> Hi,
> I'm using usb mouse and keyboard attached to InputVM (usb controler 1).
> Another usb controller (2) is attached to UntrustedVM. When I need to
> restart computer I'm disconnecting physically all usb devices attached to
> controller (2). It is possible that controller (2) would compromise Qubes
> at boot time?
>

I suppose that with the word "attached" you mean what in  Qubes definitions
is called "assigned".

In this case can tell that when I tried to assign two different USB
controllers to two different VMs, dom0 refused to do that claiming that the
controllers were sharing some resources and so there was a security risk.
So, if in  your case you were allowed to do that, then your controllers
should be really separated and that may be encouraging.

best
Fran


> My mainboard don't have any PS/2 ports and my processor don't support TXT
> (to use AEM), it only support IOMMU.
>
> --
> You received this message because you are subscribed to the Google Groups
> "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To post to this group, send email to [email protected].
> To view this discussion on the web visit https://groups.google.com/d/
> msgid/qubes-users/trinity-3093bf13-e38c-4a32-ac84-
> 39474894bdd3-1498317379448%403capp-mailcom-lxa06
> <https://groups.google.com/d/msgid/qubes-users/trinity-3093bf13-e38c-4a32-ac84-39474894bdd3-1498317379448%403capp-mailcom-lxa06?utm_medium=email&utm_source=footer>
> .
> For more options, visit https://groups.google.com/d/optout.
>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAPzH-qDfjM0Er3RtUTAWpZXN79UY25S-4qKLPEbXrFGwbo1vyA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to