On Wednesday, December 13, 2017 at 1:53:01 PM UTC-5, Matteo wrote: > >> Can anyone give me the instructions necessaries to dump the bios of my PC. > >> So that I’m sure while using Qubes that I’m safe? > >> Best regards > >> Leonardo > > > > How exactly would dumping the bios make sure you're safe? > > > > You don't need to dump it to be safe. Qubes "shields" you from buggy > bios so you don't care if it has an exploitable vulnerability. > you only need to worry about supply chain attacks (you buy a new pc with > backdoored bios). > but again you don't need to worry about that, instead focus your efforts > in automatizing opening links and email attachments in the correct vm > (micah flee has made a tutorial for that). > > if you really want to dump the bios for fun or learn new things here is > my expirence: > you can use arduino or a raspberry pi (of course you can also buy a > programmer but they cost more). > > depending on the spi flash model and pc model you might need a power > adapter: > arduino is 5V > raspberry is 3,3V > spi flash are usually 3,3V but some are 1,8V (and you will burn them if > you attach 3,3V) > you might need to desolder the chip to be able to read it. > again, i think you should focus on other things. > > Qubes OS is a security oriented os but this doesn't mean that everyone > must come out with the most strange attacks... think about simpler one > and stop them, noone is going to backdoor your bios, and if it has > unfixed bugs you don't care thanks to Qubes. > > if you/someone wants more detailed info about bios dumping i'll be happy > to help but i think it's a bit off topic and an overkill.
I disagree when you say nooone is going to backdoor your bios. I think its very common nowadays. I don't think Qubes actually shields you from a buggy bios but its actually very dependent on a proper working bios, like any O/S. Especially since qubes uses features of bios most os doesn't. But I guess you are right not to worry about it, because there is not much you can do for a corrupted or buggy bios, except to buy a new pc, but it would be something most people would want to confirm before doing, or using it for sensitive tasks. I agree dumping the bios to have a snapshot of it would be very complicated and not practical at all. But I see nothing wrong with doing so if willing and able. You can also look into using AEM to see if something changes during boot. https://www.qubes-os.org/doc/anti-evil-maid/ -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/3393425a-edea-4dae-94d8-c59cd242c3d0%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
