Re: [qubes-users] Re: How to share data between 2 Qubes installations via USB in a sensible way?

2016-09-05 Thread Drew White
On Monday, 5 September 2016 20:33:22 UTC+10, David Hobach  wrote:
> Yes, but can you attach data from a single drive to multiple VMs 
> automatically? I guess no?

Yes you can, it is scriptable.

> But that's what this was all about...
> In short: I like to plug in my USB drive and have all the data I need 
> from that drive in all VMs in a matter of seconds (& in a secure way).
> 
> So I guess there was a misuderstanding.
> 
> Other than that I mostly agree with your Opsec standards.
>
> At best I also wouldn't need to keep that drive secure, but since 
> there's hardware attacks around I better do it anyway.

The real issue is that with Qubes, it doesn't write back immediately when the 
device is attached, not does it update very well.

I can mount my drive under a VM, but Dom0 won't see the changes I made in DomU 
until I unmount an dallow the changes to be written, then unmount from Dom0, 
then remount in Dom0.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/776e8f10-52d2-42e4-b630-c0dc9f4a35f5%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Re: How to share data between 2 Qubes installations via USB in a sensible way?

2016-09-04 Thread Drew White
How about you just have 1 USB device that you keep secure?

I have a 128GB device that I ONLY use for Qubes, and is completely secure and 
safe.

Why go to all the trouble of having things set up so weirdly?

I have all USB devices go immediately to dom0.

They don't auto-play, they don't auto-mount, they don't do anything like that. 
so I'm safe.

If I have a device that I want to attach to a VM, then I attach it to that VM. 
simple.

But I NEVER attach my Qubes drive to anything, UNLESS I really really have to..

And in that case...

I create a VM with no networking, get the data off, transfer from the drive 
through the secure virtual to another VM that has networking, then use that to 
send the data to the network.

All while the drive is being used by Qubes for VMs.

It's safe, and reliable the way it can be done. But only if you have your 
system secured and safe. (without having the need for a separate USB Guest to 
have everything attached to when it gets attached to the PC.)

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/bc91338e-4706-4e02-9261-0c895ec899dd%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.