-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512
Hi all,
Thanks to Frédéric, Qubes T-shirts, polos, and sweatshirts are now
available from HELLOTUX. A small portion of each purchase will be
donated back to the Qubes OS Project.
Please see this page for additional Qubes merchandise options and
gen
On Friday, 7 August 2020 02:40:58 UTC+8, Chris Laprise wrote:
>
> Yes. Note that Qubes Security Bulletins are issued for vulns that affect
> dom0 and they reference the package versions that contain the patches.
> For example:
>
>
> https://groups.google.com/d/msgid/qubes-users/34eddc9a-300c-743
Perhaps someone here can suggest something better than what I currently
have. A default Firefox on a default Fedora-32 template does not play
videos on something like Invidio.us. The video thumbnails display
everything looks exactly as it should just the videos will not play.
I've been scratch
On 8/6/20 12:23 PM, fiftyfourthparal...@gmail.com wrote:
On Friday, 7 August 2020 00:13:52 UTC+8, Chris Laprise wrote:
IIRC that setting refers to checking packages, not the repomd.xml
files.
That's why an attacker can't replace packages with their own versions;
they have to mani
s+unsubscr...@googlegroups.com.
To view this discussion on the web visit
https://groups.google.com/d/msgid/qubes-users/CA%2BeZGO0druUFgTHaCyPB2n9tHVM8Uh8-4fVUy0nm7CL9gFTq6A%40mail.gmail.com.
Qubes-HCL-Gigabyte_Technology_Co___Ltd_-Z97X_UD5H-20200806-134959.yml
Description: application/yaml
On Friday, 7 August 2020 00:13:52 UTC+8, Chris Laprise wrote:
>
> IIRC that setting refers to checking packages, not the repomd.xml files.
> That's why an attacker can't replace packages with their own versions;
> they have to manipulate the metadata to hold back packages from
> receiving update
On 8/6/20 10:37 AM, fiftyfourthparal...@gmail.com wrote:
I hate to break that feeling, but Fedora is unique in that it doesn't
sign its repo metadata, and sadly that is what matters. They put a
bandaid on it by fetching more hashes via https... so the update
security in Fedora is
>
> I hate to break that feeling, but Fedora is unique in that it doesn't
> sign its repo metadata, and sadly that is what matters. They put a
> bandaid on it by fetching more hashes via https... so the update
> security in Fedora is based on the strength of https. That is bad, as
> https can be s
On Thursday, 6 August 2020 18:05:25 UTC+8, Chris Laprise wrote:
>
> I hate to break that feeling, but Fedora is unique in that it doesn't
> sign its repo metadata, and sadly that is what matters. They put a
> bandaid on it by fetching more hashes via https... so the update
> security in Fedora i
On Thursday, 6 August 2020 17:36:05 UTC+8, Chris Laprise wrote:
>
> IIRC she gave some indication that guest VMs shouldn't be defenseless
> internally.
>
> --
> Chris Laprise, tas...@posteo.net
> https://github.com/tasket
> https://twitter.com/ttaskett
> PGP: BEE2 20C5 356E 764A 73EB 4AB3
On 2020-08-05 21:13, unman wrote:
On Wed, Aug 05, 2020 at 09:04:41PM +0200, Qubes wrote:
On 8/5/20 8:31 PM, Stumpy wrote:
On 2020-08-05 12:06, Stumpy wrote:
I have win installed on a drive with mbr, should I be able make a
vhd and convert that to a RAW and run it as a template in Qubes?
If i
On 8/6/20 3:54 AM, fiftyfourthparal...@gmail.com wrote:
On Thursday, 6 August 2020 12:31:44 UTC+8, Emily wrote:
-- I'm not unman, but I just checked the repo data and it appears
they use sha256
This is reassuring. Thanks, Emily
I hate to break that feeling, but Fedora is unique in t
On 8/5/20 11:48 PM, fiftyfourthparal...@gmail.com wrote:
On Thursday, 6 August 2020 00:37:08 UTC+8, Qubes wrote:
What risk(s) are you mitigating by disabling passwordless root?
You should look at this the other way around--what do I stand to lose
by keeping passwordless root? If I can t
On Thursday, 6 August 2020 12:31:44 UTC+8, Emily wrote:
>
>
> -- I'm not unman, but I just checked the repo data and it appears they
> use sha256
>
This is reassuring. Thanks, Emily
--
You received this message because you are subscribed to the Google Groups
"qubes-users" group.
To unsubscribe
14 matches
Mail list logo