Re: [qubes-users] Anonymizing your MAC Address with macchanger and scripts

2018-03-02 Thread Chris Laprise
On 03/02/2018 05:43 AM, Unman wrote: On Thu, Mar 01, 2018 at 05:52:48AM -0800, billol...@gmail.com wrote: On Thursday, March 1, 2018 at 12:08:19 AM UTC-5, Chris Laprise wrote: On 02/28/2018 08:23 PM, 'awokd' via qubes-users wrote: BTW, as an example of Qubes-specifics in this issue, on sleep

Re: [qubes-users] Problems with qvm-run --pass-io

2018-03-02 Thread Chris Laprise
On 03/02/2018 05:56 AM, Unman wrote: On Fri, Mar 02, 2018 at 05:38:11AM -0500, Chris Laprise wrote: On 03/02/2018 04:04 AM, donoban wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 03/02/2018 08:38 AM, Robert Walz wrote: [robert@dom0 ~]$ qvm-run --pass-io tempDebian 'cat "/home

Re: [qubes-users] Problems with qvm-run --pass-io

2018-03-02 Thread Chris Laprise
e it fine. If source is sparse, you can also save it as sparse by piping through dd: qvm-run --pass-io tempDebian 'cat "/home/user/meta.raw"' | dd conv=sparse of=/var/lib/qubes/appvms/metasploitable/root.img -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter

[qubes-users] Netvm reassignment blocks network traffic - 4.0rc4

2018-03-01 Thread Chris Laprise
this may be a bug. Specifics don't seem to matter, the VMs can be plain firewall or vpn, debian or fedora on either side. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message

Re: [qubes-users] Little pb to understand how to add a FW rule on my proxyVM

2018-03-01 Thread Chris Laprise
On 03/01/2018 08:32 AM, ThierryIT wrote: Le jeudi 1 mars 2018 12:29:30 UTC+2, Chris Laprise a écrit : Note that the second link below is easy to setup and the 'qubes-vpn-ns' script accepts DHCP-generated variables from openvpn and automatically uses them to setup dnat. [1] https://www.qubes

Re: [qubes-users] Little pb to understand how to add a FW rule on my proxyVM

2018-03-01 Thread Chris Laprise
variables from openvpn and automatically uses them to setup dnat. [1] https://www.qubes-os.org/doc/vpn/ [2] https://github.com/tasket/Qubes-vpn-support/tree/qubes4 -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3

Re: [qubes-users] Anonymizing your MAC Address with macchanger and scripts

2018-02-28 Thread Chris Laprise
/blatant example). They didn't care to address the fact that the waking system was already broadcasting the original address before the user had a chance to restart sys-net (and not to mention the unmitigated headache of restarting/reassigning all the dependant VMs). -- Chris Laprise, tas

Re: [qubes-users] Anonymizing your MAC Address with macchanger and scripts

2018-02-28 Thread Chris Laprise
On 02/28/2018 03:58 PM, Yuraeitha wrote: On Wednesday, February 28, 2018 at 9:14:30 PM UTC+1, vel...@tutamail.com wrote: Chris if you could replicate the simplicity in your instruction for a "kill-switc-VPN" for the this feature that would be awesome... This seems like a great feat

Re: [qubes-users] Anonymizing your MAC Address with macchanger and scripts

2018-02-28 Thread Chris Laprise
. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] Anonymizing your MAC Address with macchanger and scripts

2018-02-28 Thread Chris Laprise
On 02/28/2018 01:49 PM, awokd wrote: On Wed, February 28, 2018 6:34 pm, Chris Laprise wrote: On 02/28/2018 11:31 AM, klausdiet...@mail2tor.com wrote: Hey guys, i have a big problem with "Anonymizing your MAC Address with macchanger and scripts". I used this Tutorial on the

Re: [qubes-users] Anonymizing your MAC Address with macchanger and scripts

2018-02-28 Thread Chris Laprise
On 02/28/2018 01:49 PM, awokd wrote: On Wed, February 28, 2018 6:34 pm, Chris Laprise wrote: On 02/28/2018 11:31 AM, klausdiet...@mail2tor.com wrote: Hey guys, i have a big problem with "Anonymizing your MAC Address with macchanger and scripts". I used this Tutorial on the

Re: [qubes-users] Anonymizing your MAC Address with macchanger and scripts

2018-02-28 Thread Chris Laprise
of the doc hasn't worked for a long time (search the mailing list to see issues) and it never did work correctly, IMO. What should i do? You should use the MAC randomization feature integrated into Network Manager, shown at the beginning of the doc. -- Chris Laprise, tas...@posteo

Re: [qubes-users] Re: Clearing qubes-dom0-cached packages

2018-02-27 Thread Chris Laprise
e) as well. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and s

Re: [qubes-users] qrexec policies broken after QSB #38 update

2018-02-20 Thread Chris Laprise
s anyone else running into this problem? Any solutions? Since several people are reporting this, I decided to try some simple qvm-copy tests and have been unable to reproduce the problem on R4.0-rc4. I updated with qubes*testing and then restarted per the QSB. -- Chris Laprise, tas...@pos

Re: [qubes-users] extract file from image backup

2018-02-20 Thread Chris Laprise
y). If you follow the emergency backup recovery docs, it lays out manual steps for recovering Qubes data as img files which you can then mount: https://www.qubes-os.org/doc/backup-restore/#emergency-backup-recovery-without-qubes -- Chris Laprise, tas...@posteo.net https://github.com/tasket https

Re: [qubes-users] qubes on ssd may not be secure on encryption

2018-02-16 Thread Chris Laprise
. When provisioning hardware, an extremely careful person would use HDDs only. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google

Re: [qubes-users] q4rc4 very slow. VMs take 23 - 33 seconds to start

2018-02-14 Thread Chris Laprise
; Try switching the mode to hvm (and this let you use debug mode). Then there are logs in dom0 /var/log/qubes for each VM. On the VM side you can try 'systemd-analyze blame' for start timings, also 'journalctl' and 'dmesg'. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https

Re: [qubes-users] q4rc4 very slow. VMs take 23 - 33 seconds to start

2018-02-14 Thread Chris Laprise
to start and the console window to go blank. Is this Debian or Fedora? If the latter, can you try Fedora? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you

Re: [qubes-users] Re: Setting up privateinternetaccess on qubes 3.2

2018-02-14 Thread Chris Laprise
On 02/13/2018 05:23 PM, vel...@tutamail.com wrote: Thanks Chris(and "tasket"!)took me a few tries but I managed to get it going, I tweaked the implementation a bit(scarey). I was not however able to get this command going from step #3 of the Github guide: sudo /usr/lib/qubes

Re: [qubes-users] Re: Setting up privateinternetaccess on qubes 3.2

2018-02-13 Thread Chris Laprise
re questions then answers. I'm preparing new vpn tunnel support in Qubes and a simplified doc to go with it. This should be available within a week or two. In the meantime I suggest using Qubes-vpn-support at the above link. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://

Re: [qubes-users] Re: Experimenting with Wireguard VPN @Mullvad.net

2018-02-12 Thread Chris Laprise
On 02/12/2018 07:43 AM, kerekesbar...@gmail.com wrote: 2017. november 6., hétfő 17:51:43 UTC+1 időpontban Chris Laprise a következőt írta: Mullvad recently added trial Wireguard VPN support, so I wrote a howto for setting it up on Qubes: https://github.com/tasket/Qubes-vpn-support/wiki

Re: [qubes-users] Re: performance hit with 4.0rc4

2018-02-07 Thread Chris Laprise
for the virt_mode? It is the hvm mode that starts most slowly and taxes the system. Most of the VMs (except sys-net and sys-usb) should be using pvh mode. If the VMs are taking a very long time to start you can try enabling debug mode from either 'qvm-prefs' or VM Settings dialog. -- Chris Laprise, tas

Re: [qubes-users] Issues with 4.0 rc4

2018-02-05 Thread Chris Laprise
On 02/04/2018 04:52 PM, Chris Laprise wrote: On 02/04/2018 07:10 AM, Nuno Branco wrote: 2) When restoring VMs from Qubes 3.2 the software does not seem to work if you select more than one VM to restore at a time. By this I mean the restore process launches and finishes and I do have a VM listed

Re: [qubes-users] Issues with 4.0 rc4

2018-02-04 Thread Chris Laprise
so decided to try a fresh RC4 install tonight and then restore an R3.2 archive (minus dom0 home) to see how that goes. Maybe I'll be able to recreate your issue... -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106

Re: [qubes-users] I am unable to verify my image. Please help?

2018-01-25 Thread Chris Laprise
id. At this point, if you have taken care to verify the Master key by retrieving it or viewing its fingerprint through other channels, then your keys are all set. (Some people skip most of this and only import the Singing key and verify its fingerprint, but I digress.) You can now do the --verify step.

Re: [qubes-users] Save virtual machine state?

2018-01-25 Thread Chris Laprise
is only in-memory stopping of the VM. Un-pausing makes the VM continue running. Qubes doesn't (yet) support saving to disk like hibernate. If this ever does become a feature it will probably be for use with HVMs in Qubes 4.x. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https

Re: [qubes-users] VPN issues after upgrading to fed26?

2018-01-24 Thread Chris Laprise
On 01/24/2018 06:10 PM, Chris Laprise wrote: On 01/24/2018 05:58 PM, Stumpy wrote: I recently upgraded to fedora 26 from 24 and since then I have not been able to get my VPN NetVM to work. I have tried some things mentioned in other posts to restart my vpnvm like qvm-run -u root my_vpn_vm

Re: [qubes-users] VPN issues after upgrading to fed26?

2018-01-24 Thread Chris Laprise
get a "VPN: Starting..." notification but that is it, it never actually starts/runs. As I am feeling a bit naked w/o my VPNvm I'd really appreciate any suggestions! Are you using the regular or minimal fedora template? The newest minimal template may require additional packages. --

Re: [qubes-users] Looking for an approach to change the borderline between /dev/xvda and /dev/xvdb

2018-01-24 Thread Chris Laprise
on Qubes 4. But I from my initial understanding I like the extra security it provides, although I've yet to better grasp its full potential. It seems like a pretty cool project you're working on there Chris. Unfortunately I don't have much experience as a coder either, so I can't make

Re: [qubes-users] Upgrade from 3.2 to 4.0 ?

2018-01-23 Thread Chris Laprise
. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] Looking for an approach to change the borderline between /dev/xvda and /dev/xvdb

2018-01-22 Thread Chris Laprise
-VM-hardening/tree/systemd The latter gives you the ability to have everything in /rw wiped with the exception of a whitelist that you specify. This is handled at boot time just before the normal /rw mount process. It is tested with debian-9 template on R3.2, current state is beta. -- Chris

Re: [qubes-users] R4.0 on T470, Suspend-to-RAM issues

2018-01-22 Thread Chris Laprise
. Of course, its wise to backup before trying out updates from 'testing' in case your system doesn't work with them. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message

Re: [qubes-users] how to install new template and appvm?

2018-01-22 Thread Chris Laprise
seen here: https://www.qubes-os.org/doc/whonix/install/ -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qub

Re: [qubes-users] files /etc/yum.repos.d/fedora.repo and fedora-updates.repo ?

2018-01-20 Thread Chris Laprise
guest VMs. The dom0 VM will remain fc23 on Qubes 3.2 even when the guest VM templates are properly upgraded to fc26. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message b

Re: [qubes-users] how to reinstall template? (i think it's not enabled by repo)

2018-01-13 Thread Chris Laprise
"reinstall". For Qubes 4.0rc3 this feature currently doesn't work. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google

[qubes-users] rc3: Split-gpg + enigmail frequent "qubes.Gpg" prompts

2018-01-12 Thread Chris Laprise
only once for the defined time interval). With the current behavior, I'll probably have to disable Enigmail. I've double-checked my settings with the split-gpg doc, but I'm wondering if this could be a bug or if I'm just missing something. Versions Debian 9 or Fedora 26 Thunderbird 52.5.2 Enigmail 1.9.9

Re: [qubes-users] Qubes 4.0-rc3

2018-01-11 Thread Chris Laprise
On 01/11/2018 10:31 PM, Andrew David Wong wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > On 2018-01-11 14:41, Chris Laprise wrote: >> >> At least no section repetition for the scripts should be necessary. But >> doing this for the dialogs still add

Re: [qubes-users] Qubes 4.0-rc3

2018-01-11 Thread Chris Laprise
cripts still use iptables even in fedora-26. IIUC, iptables and nft are two different interfaces to netfilter. I don't know if it really matters, at least for the R4.0 window. I'd prefer to put the syntax change (for docs) off until a later release. -- Chris Laprise, tas...@posteo.net https:

Re: [qubes-users] Qubes 4.0-rc3

2018-01-11 Thread Chris Laprise
At least no section repetition for the scripts should be necessary. But doing this for the dialogs still adds a lot to an already long doc. I feel that, apart from making some docs look deceptively long and less readable, the most significant downside to melding 3.x/4.x instructions together wo

Re: [qubes-users] memory management in dom0 ?

2018-01-11 Thread Chris Laprise
ot/grub2/grub.cfg on the lines beginning with 'multiboot /xen'. Its currently at 1800M on this system and can probably go lower. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You rec

Re: [qubes-users] Qubes 4.0-rc3

2018-01-10 Thread Chris Laprise
On 01/10/2018 01:53 PM, 'Tom Zander' via qubes-users wrote: On Wednesday, 10 January 2018 18:32:39 GMT Chris Laprise wrote: I also have a download-able project that makes the scripted/antileak setup fairly simple in Qubes R4.0: Please consider updating the docs repo with this :-) I poked

Re: [qubes-users] rc04

2018-01-09 Thread Chris Laprise
and ARM. So he can not dance :) From my recollection of AMD statements: SP1: Very hard to exploit on any CPU SP2: Much harder to exploit on AMD than Intel SP3/Meltdown: AMD not affected -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5

Re: [qubes-users] Help verifying install files: how to verify the Release 3 Signing Key?

2018-01-01 Thread Chris Laprise
the same.) This lists the Qubes master key under the uid for the Qubes release key, showing the release key has been signed by the master. The exclamation mark after "sig" means the signature has been verified as good. -- Chris Laprise, tas...@posteo.net https://github.com/ta

Re: [qubes-users] Appvm - memory

2017-12-24 Thread Chris Laprise
when i add more apps . Any ideas ? R This sounds like Issue #3265. Workaround from dom0 is: sudo systemctl restart qubes-qmemman.service Repeat every so often as needed... -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A

Re: [qubes-users] Anyway to boot into only dom0 (4.0rc3)/sys-firewall stuck at boot

2017-12-24 Thread Chris Laprise
primary Qubes laptop is not usable state thanks to this issue. Any tips to solve this will be a big help. Kushal What worked for me is simply disable "Start on boot" for sys-net and sys-firewall. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/tt

[qubes-users] How to hide all except one USB controller?

2017-12-22 Thread 'Chris' via qubes-users
this. How can I configure Grub to ignore all usb controllers except one specific one? Cheers Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-user

Re: [qubes-users] Verifying Install Files: Confused About How to Verify R3 ISO file

2017-12-20 Thread Chris Laprise
t;. For more options, visit https://groups.google.com/d/optout. The Master key just verifies the release keys (one for each Qubes version). You need to import the v3 release key also. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 35

Re: [qubes-users] vms fail to return memory after pc idle for a long time.

2017-12-20 Thread Chris Laprise
is to do 'sudo systemctl qubes-qmemman.service' in dom0. It will stop working again, so you may need to repeat it or put it in a timed loop. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You

Re: [qubes-users] Bitmask log with errors - it's normal?

2017-12-18 Thread Chris Laprise
None:None - ('Connection aborted.', gaierror(-2, 'Name or service not known')) [2017-12-18 08:14:22] WARNING - L#None : None:None - Could not connect to OpenVPN yet: MissingSocketError() -- Its probably better to ask on the leap-discuss mailing list. BTW, I got the attention of a bitmask deve

Re: [qubes-users] Bitmask VPN DNS leaks

2017-12-18 Thread Chris Laprise
un bitmask in the appVM itself, instead of in a proxyVM. That might stop the leaks for that particular VM. Also see my other message in thread about stopping leaks in the proxyVM: https://groups.google.com/d/msgid/qubes-users/c0e97ad5-e448-6eef-8182-08e94316a6c1%40posteo.net -- Chris La

Re: [qubes-users] Bitmask VPN DNS leaks

2017-12-18 Thread Chris Laprise
/config/qubes-firewall-user-script and make it executable. On Qubes R4.0-rc you may have to do this for it to work: ln -s /rw/config/qubes-firewall-user-script /rw/config/qubes-ip-change-hook -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5

Re: [qubes-users] Q4rc3 debian-9 template fails to update.

2017-12-18 Thread Chris Laprise
On 12/16/2017 07:49 AM, Yuraeitha wrote: On Saturday, December 16, 2017 at 10:51:30 AM UTC, Chris Laprise wrote: On 12/16/2017 04:21 AM, haaber wrote: I freshly installed debian-9 ; when installing packages, apt-get hangs for days(!) with 81% [waiting for headers] ... followed by Err:XX

Re: [qubes-users] DMA attacks are possible not only via USB?!

2017-12-17 Thread Chris Laprise
On 12/17/2017 03:23 PM, 'Chris' via qubes-users wrote: It seems as if Qubes OS is useless in protecting against hardware access. Even with TPM, I am not sure how realistic it is. Will AEM be triggered when changing USB controllers or adding hostile USB devices to the one whilelisted

[qubes-users] DMA attacks are possible not only via USB?!

2017-12-17 Thread 'Chris' via qubes-users
its really hard to find any useful information via Google about most topics regarding Qubes OS. Is Qubes OS somehow downranked intentionally? Cheers Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this

Re: [qubes-users] Re: VPN Disconnects when Qubes goes to sleep (and does not reconnect when coming out of sleep)?

2017-12-17 Thread Chris Laprise
t debian-9. This has been an off-and-on issue with notify-send over the years. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Goo

Re: [qubes-users] Trying to get my head around a configuration for a VPN-Proxy VM and its firewall?

2017-12-16 Thread Chris Laprise
rt and the sys-vpn config isolates the tunnel traffic as VPN doc and Qubes-vpn-support do. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to

Re: [qubes-users] Q4rc3 debian-9 template fails to update.

2017-12-16 Thread Chris Laprise
is running sys-net. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from

Re: [qubes-users] Trying to get my head around a configuration for a VPN-Proxy VM and its firewall?

2017-12-15 Thread Chris Laprise
d. [1] https://github.com/tasket/Qubes-vpn-support -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users&qu

[qubes-users] Qubes OS and latest hardware (8700K)

2017-12-14 Thread 'Chris' via qubes-users
Hi, will Qubes OS 3.2 work with the 8700K desktop CPU that was just released? I've heard conflicting reports. If not, will 4.0 support it? I read that you need Kernel 4.12 (I believe) but even Qubes 4.0 seems to be stuck with 4.8... Is this just a matter of "perfect" support or are they

Re: [qubes-users] Re: What are the disadvantages of NOT having vt-d?

2017-12-13 Thread 'Chris' via qubes-users
sers@googlegroups.com> > > Le jeudi 14 décembre 2017 01:27:23 UTC+1, Chris a écrit : > >> Hi, >> I am an avid user of Qubes OS and I love what you have done. Finally I have >> a feeling of security and a peace of mind... I am not a security person but >> I kinda

[qubes-users] What are the disadvantages of NOT having vt-d?

2017-12-13 Thread 'Chris' via qubes-users
Hi, I am an avid user of Qubes OS and I love what you have done. Finally I have a feeling of security and a peace of mind... I am not a security person but I kinda do care about it and have some basic understanding and am slightly paranoid. I am currently running a DELL Precision 5520, which

Re: AW: Re: [qubes-users] Qubes 4rc3 :: 50% reduced battery runtime compared to Qubes 3.2 on Lenovo X230

2017-12-13 Thread Chris Laprise
On 12/13/2017 01:30 PM, [799] wrote: Hello Chris, Original-Nachricht An 13. Dez. 2017, 19:15, Chris Laprise schrieb > Increased CPU usage is a known issue. > You can see it in the 'xentop' listing. > This may be one of the core tradeoffs > when moving to

Re: [qubes-users] Re: Q4R3 - debian-stable

2017-12-13 Thread Chris Laprise
starting programs. A fix is in the works, and a workaround is deleting an @service link like so: sudo rm /etc/systemd/system/multi-user.target.wants/wpa_supplicant@.service -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB

Re: [qubes-users] vpn's log option

2017-12-13 Thread Chris Laprise
On 12/13/2017 11:21 AM, charly LEMMINKÄINEN wrote: Le mercredi 13 décembre 2017 15:55:39 UTC+1, Chris Laprise a écrit : On 12/13/2017 08:38 AM, charly LEMMINKÄINEN wrote: is there any possibility to put a log option in the vpn scripts described in the wiki? To know the reason why a vpn has

Re: [qubes-users] Qubes 4rc3 :: 50% reduced battery runtime compared to Qubes 3.2 on Lenovo X230

2017-12-13 Thread Chris Laprise
Increased CPU usage is a known issue. You can see it in the 'xentop' listing. This may be one of the core tradeoffs when moving to R4.0. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- Yo

Re: [qubes-users] vpn's log option

2017-12-13 Thread Chris Laprise
pn-support This will ensure openvpn gets re-started anytime it exits. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qub

Re: [qubes-users] [HOWTO] use 2nd drive partition as 'home' drive.

2017-12-12 Thread Chris Laprise
/mnt/newdisk To have it come online automatically, add entries in /etc/crypttab and /etc/fstab respectively. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because

Re: [qubes-users] [HOWTO] use 2nd drive partition as 'home' drive.

2017-12-11 Thread Chris Laprise
inside a new volume group) then use qvm-pool to add it to Qubes. Then you can specify it when using qvm-create etc. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because

Re: [qubes-users] 3.2 gpg verification works no more

2017-12-09 Thread Chris Laprise
e, instead of pasting the signature? If you think the .iso downloaded incorrectly, first thing to check is the exact number of bytes with 'ls -l' in case the download stopped prematurely. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E

Re: [qubes-users] What happened to domain manager in 4?

2017-12-08 Thread Chris Laprise
On 12/08/2017 04:29 AM, 'Tom Zander' via qubes-users wrote: On Friday, 8 December 2017 06:09:32 CET Chris Laprise wrote: There is the question of whether someone should try porting the original Qt-based Qubes Manager to R4.0. I mention this since the biggest complaint so far is not having

Re: [qubes-users] What happened to domain manager in 4?

2017-12-07 Thread Chris Laprise
people think... -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from

Re: [qubes-users] What happened to domain manager in 4?

2017-12-07 Thread Chris Laprise
. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] dom0 update in Qubes 4.0

2017-12-07 Thread Chris Laprise
wrong. question 2: Is there a standard way one is supposed to sign up for VM update availability notices in the new world? I'm not aware of an update notifier (yet) in R4.0. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D1

Re: [qubes-users] What happened to domain manager in 4?

2017-12-06 Thread Chris Laprise
hat will not get you the attention of the DE projects or potential userbase. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google G

Re: [qubes-users] R3.2: Debian 9 template fails to update 50% of the time

2017-12-06 Thread Chris Laprise
On 12/06/2017 10:21 AM, dim...@united.gr wrote: Sorry, I didn't notice the stale part. I am using an upgraded 8 to 9 Debian and in my case it is actually updating. The best way I found is to disable apt-daily.service, not apt-daily.timer. -- Chris Laprise, tas...@posteo.net https

Re: [qubes-users] What happened to domain manager in 4?

2017-12-06 Thread Chris Laprise
the same window is bad design and/or intimidating to users. Now we have two tiny icons on opposite sides of the screen and the user is starved of info. I would welcome the return of Qubes Manager. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2

Re: [qubes-users] Re: VPN Disconnects when Qubes goes to sleep (and does not reconnect when coming out of sleep)?

2017-12-03 Thread Chris Laprise
On 12/03/2017 10:30 PM, Michael Siepmann wrote: On 12/02/2017 11:14 PM, Chris Laprise wrote: Looking at openvpn entries in 'journalctl' can give you a better idea. I've seen instances where openvpn versions starting with 2.4 have this bad reaction to disconnection (which is what sleep/wake

Re: [qubes-users] Re: VPN Disconnects when Qubes goes to sleep (and does not reconnect when coming out of sleep)?

2017-12-02 Thread Chris Laprise
On 12/03/2017 12:09 AM, Michael Siepmann wrote: On 11/30/2017 10:14 PM, Chris Laprise wrote: On 11/30/2017 11:44 PM, Michael Siepmann wrote: On Jun 12, 2017, Andrew Morgan wrote: Did you follow the "Set up a ProxyVM as a VPN gateway using iptables and CLI scripts" section of the

Re: [qubes-users] Re: VPN Setup on qubes 4 RC3

2017-12-01 Thread Chris Laprise
the Qubes VPN guide. Then, where it says to save the script as "qubes-firewall-user-script" save it as "qubes-ip-change-hook" instead. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D

Re: [qubes-users] Re: VPN Disconnects when Qubes goes to sleep (and does not reconnect when coming out of sleep)?

2017-11-30 Thread Chris Laprise
ProxyVM as a VPN gateway using iptables and CLI scripts" instructions but for me executing "/rw/config/rc.local" doesn't make it work again. I've also tried commenting out or deleting "persist tun" from my OpenVPN config file, as Chris Laprise as suggested in the thre

Re: [qubes-users] qvm-backup-restore --verify-only broken ?

2017-11-29 Thread Chris Laprise
about this. I've started to fix the code, and can verify backups already. So far all my backups appear to be OK, so I think qvm-backup is creating the backup files correctly. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A

Re: [qubes-users] Qubes OS 4.0-rc3 has been released!

2017-11-27 Thread Chris Laprise
-community: key 1 import failed. error: can't create transaction lock on /var/lib/rpm/.rpm.lock (Resource temporarily unavailable) error: /etc/pki/rpm-gpg/RPM-GPG-KEY-qubes-4-unstable: key 1 import failed. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP

Re: [qubes-users] Qubes OS 4.0-rc3 has been released!

2017-11-27 Thread Chris Laprise
On 11/27/2017 03:41 PM, Chris Laprise wrote: On 11/27/2017 10:29 AM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear Qubes Community, We're pleased to announce the third release candidate for Qubes 4.0! Our goal for this release candidate is to improve

Re: [qubes-users] Qubes OS 4.0-rc3 has been released!

2017-11-27 Thread Chris Laprise
starve some of your VMs of RAM, making them run very slowly. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "

Re: [qubes-users] Re: R4-rc2 consuming all my disk space (250MB)

2017-11-26 Thread Chris Laprise
On 11/26/2017 11:55 PM, Yuraeitha wrote: On Sunday, November 26, 2017 at 10:05:46 PM UTC, Chris Laprise wrote: I currently have 4GB remaining on my drive according to the 'lvs' based script from issue #3240. However, I know I don't have nearly that much in templates and data; there was a lot

[qubes-users] R4-rc2 consuming all my disk space (250MB)

2017-11-26 Thread Chris Laprise
. So I'm wondering if this is a real problem with R4 and what can be done about it. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed

Re: [qubes-users] Re: will uninstalling a base template delete a clone of the template?

2017-11-26 Thread Chris Laprise
, would this also remove the cloned kali template vm? The answer is No. Cloned templates are not dependent on each other. If you have appVMs dependent on the debian-8 template, you'll have to re-assign them to another template before you do the removal. -- Chris Laprise, tas...@posteo.net

Re: [qubes-users] Local network access when using ProxyVM as VPN gateway using iptables and CLI scripts?

2017-11-24 Thread Chris Laprise
On 11/21/2017 04:07 PM, Michael Siepmann wrote: On 11/16/2017 09:50 PM, Michael Siepmann wrote: On 11/16/2017 08:11 AM, Chris Laprise wrote: On 11/15/2017 10:17 PM, Michael Siepmann wrote: I've followed the instructions to "Set up a ProxyVM as a VPN gateway using iptables and CLI sc

Re: [qubes-users] mount root.img files

2017-11-22 Thread Chris Laprise
On 11/22/2017 10:01 AM, Chris Laprise wrote: Glad you recovered OK. The best way to execute the vm-sudo instructions is to switch to root user first with 'sudo su'. Notice that all the shell prompts in the document are '[root@vmname]#'. BTW I have a project Qubes-VM-hardening that uses vm

Re: [qubes-users] mount root.img files

2017-11-22 Thread Chris Laprise
documentation either. So I ask in despair for some help. Bernhard Glad you recovered OK. The best way to execute the vm-sudo instructions is to switch to root user first with 'sudo su'. Notice that all the shell prompts in the document are '[root@vmname]#'. -- Chris Laprise, tas...@po

Re: [qubes-users] A lot of trouble with qubes 4.0 rc2

2017-11-20 Thread Chris Laprise
, and I believe its the latter you should be concerned about. Not sure just how you are using rsync... a lot depends on what your source and target are. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1

Re: [qubes-users] Possible privacy concerns with Qubes 4 and the transition away from paravirtualization?

2017-11-20 Thread Chris Laprise
makes Qubes great for privacy is that privacy is best implemented on top of strong security. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you

Re: [qubes-users] Copying file from Debian8(or Whonix) to a Fedora VM?

2017-11-20 Thread Chris Laprise
On 11/19/2017 07:55 PM, vel...@tutamail.com wrote: On Sunday, November 19, 2017 at 4:03:44 PM UTC-6, Chris Laprise wrote: On 11/19/2017 01:48 PM, v wrote: I have been using Qubes 3.2 for about 5 months and love it...thank you all who have contributed! I am a noobie so be gentle...I am also

Re: [qubes-users] Copying file from Debian8(or Whonix) to a Fedora VM?

2017-11-19 Thread Chris Laprise
tall the python-gtk2 package separately). The easiest way to get this working like it does in Fedora is to run 'sudo tasksel' and select the Gnome desktop for installation. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4

Re: [qubes-users] Qubes4 rc2 - sys-firewall fails at 1st boot

2017-11-17 Thread Chris Laprise
- No 3153 on 8 October 2017 against Qubes4 rc1 Any solution yet? A recent update seems to have helped on my system. If you can get sys-net working, try updating dom0 with: sudo qubes-dom0-update --enablerepo=qubes*testing -- Chris Laprise, tas...@posteo.net https://github.com/tasket https

Re: [qubes-users] Hope to install the OS on an SSD and /home on a spinning disk

2017-11-17 Thread Chris Laprise
/ The first uses symlinks for each appVM folder. I'm not sure but I think you can symlink the whole appvms folder if you want all appVM storage to go to the other drive automatically. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E

Re: [qubes-users] Local network access when using ProxyVM as VPN gateway using iptables and CLI scripts?

2017-11-16 Thread Chris Laprise
ain kinds of threats. If your use case does not call for an appVM accessing both VPN and LAN at the same time then there should be no reason to make the compromise. -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D1

Re: [qubes-users] When transferring file between Qubes, MD5 changes.

2017-11-16 Thread Chris Laprise
VMs? Is the same mdsum program being using on both ends? -- Chris Laprise, tas...@posteo.net https://github.com/tasket https://twitter.com/ttaskett PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886 -- You received this message because you are subscribed to the Google Groups "qu

Re: [qubes-users] Re: Installing Debian template 4.0rc2

2017-11-11 Thread Chris Laprise
On 11/11/2017 08:51 AM, Yuraeitha wrote: @ Chris Laprise On Saturday, November 11, 2017 at 1:45:07 PM UTC, Chris Laprise wrote: On 11/11/2017 07:54 AM, Yuraeitha wrote: On Saturday, November 11, 2017 at 12:23:28 PM UTC, JPL wrote: For some reason the debian template didn't install when I

Re: [qubes-users] Qubes & Quantum decryption Immunity

2017-11-11 Thread Chris Laprise
On 11/11/2017 08:31 AM, Yuraeitha wrote: On Saturday, November 11, 2017 at 12:44:54 PM UTC, Chris Laprise wrote: On 11/10/2017 05:51 PM, taii...@gmx.com wrote: In this case you should ask the luks/dmcrypt mailinglist as that is what qubes uses for disk crypto. Would be simpler off the bat

<    2   3   4   5   6   7   8   9   10   11   >