Re: [qubes-users] What is the best way to use i2p in Qubes? Wouldntit be great if we had native i2p support?

2016-12-08 Thread Chris Laprise
-installed. I'm not familiar with qBittorrent. Its best to stick with client software that is expressly written, adapted (or at least audited) for use on i2p. Chris Thanks for your answer. By ProxyVM you mean something like sys-whonix? If so how could one setup one, so that there can be no leaks

Re: [qubes-users] What is the best way to use i2p in Qubes? Wouldn't it be great if we had native i2p support?

2016-12-08 Thread Chris Laprise
a proxyVM or appVM (not a netVM). Otherwise, you could consider using a Tails HVM which would have it pre-installed. I'm not familiar with qBittorrent. Its best to stick with client software that is expressly written, adapted (or at least audited) for use on i2p. Chris -- You received

Re: [qubes-users] Re: Creating an OpenWrt netvm

2016-12-06 Thread Chris Laprise
an attacker to monitor and control your firewall, VPN etc. OTOH, combining firewall and VPN functions in the same VM is probably fine since those processes are relatively low-risk. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users&q

[qubes-users] Re: New Kernel Issues?

2016-12-06 Thread lowson . chris
Never mind I figured it out :) If anyone has the same issues you can change the booted version by editing /boot/efi/EFI/qubes/xen.cfg Update the default var at the top and reboot. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe

Re: [qubes-users] Qubes VM snapshots using git / SVN

2016-12-05 Thread Chris Laprise
' to create COW copies. LVM is less flexible and requires more commands, but your system may already be setup with it and it would at least give you snapshots without any need to copy large volumes of data unnecessarily. Chris -- You received this message because you are subscribed

Re: [qubes-users] AEM boot doesn't load serviceVM's since Xen 4.6.3

2016-12-04 Thread Chris Laprise
version but some other update installed at the same time, here is the update history: This sounds familiar. Try removing the network devices from sys-net to see if it will start then. Next, re-add the network devices and try starting sys-net again. Chris -- You received this message because

Re: [qubes-users] Yubikeys in Qubes

2016-12-01 Thread Chris Laprise
What is an acceptable / secure way to obtain a Yubikey fob? Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@google

Re: [qubes-users] TemplateVM Best-Practices?

2016-12-01 Thread Chris Laprise
compilers in systems that are meant for non-development use. If I were to merge any of those categories you listed, it would be Work and Regular. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] Re: TemplateVM Best-Practices?

2016-12-01 Thread Chris Laprise
-net and sys-firewall should be run with a minimal template without regular apps present... this makes them more like router installations and theoretically more secure. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubs

Re: [qubes-users] PAM errors after disabling password-less root

2016-12-01 Thread Chris Laprise
Would it have anything to do with upgrading to kernel 4.8 (both dom0 and domU)? Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-user

Re: [qubes-users] PAM errors after disabling password-less root

2016-12-01 Thread Chris Laprise
On 11/30/2016 03:55 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, Nov 30, 2016 at 02:44:17PM -0500, Chris Laprise wrote: On 11/28/2016 05:27 PM, Patrick Schleizer wrote: Probably related issues: - https://github.com/QubesOS/qubes-doc/pull/176

Re: [qubes-users] PAM errors after disabling password-less root

2016-11-30 Thread Chris Laprise
the auth requests are originating from dom0. I'd like to find a way to squelch them. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-user

Re: [qubes-users] ANN: Split Browser (disposable Tor Browser, persistent bookmarks/logins)

2016-11-30 Thread Chris Laprise
start the browser DisposableVM frequently (which shouldn't take more than 10-15 seconds) to 'shake off' such an attack." ... continued at https://github.com/rustybird/qubes-split-browser Rusty This looks very interesting... will be trying it our soon. Thanks! Chris -- You received this message b

Re: [qubes-users] [Security] Anti-evil-maid didn't notice Xen update ?

2016-11-30 Thread Chris Laprise
ge as usual, without any unusual behaviour or warning whatsoever. So I wonder : Is AEM actually working on my system ? Any clue appreciated. TIA. Kind regards. Hi, Can you restore your system to the point it was just before the Xen update? This would allow you to reproduce the behavior. Ch

Re: [qubes-users] 2/3 of VMs randomly lose network access; sys-net, sys-firewall, and others normal

2016-11-26 Thread Chris Laprise
l. No time to troubleshoot it. You may want to switch to debian for your service VMs... Versions 8 and 9 are working well for me. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving

Re: [qubes-users] Qubes Security Bulletin #27

2016-11-22 Thread Chris Laprise
yet... I'm assuming if I have Xen 4.6.3-21 from testing, the update from standard repo should go OK. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email

Re: [qubes-users] Re: Is Qubes for the Asus X205ta ?

2016-11-21 Thread Chris Laprise
to work with Linux. Using these resources will improve the chances that Qubes will work well on a computer model that is not on the Qubes HCL. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this grou

Re: [qubes-users] HCL - Lenovo X230

2016-11-19 Thread Chris Laprise
On 11/19/2016 06:15 PM, Aaron Jefferson wrote: Hadn't turned it on. On Sat, Nov 19, 2016 at 6:08 PM, Aaron Jefferson <ajefferson1...@gmail.com <mailto:ajefferson1...@gmail.com>> wrote: Thanks, I'll check it out. On Sat, Nov 19, 2016, 18:06 Chris Laprise <tas...@

Re: [qubes-users] HCL - Lenovo X230

2016-11-19 Thread Chris Laprise
, ethernet and USB. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to q

Re: [qubes-users] PAM errors after disabling password-less root

2016-11-18 Thread Chris Laprise
, this should be logged on the VM itself, anyway, no? Maybe I'm wrong. Look through journalctl and see. Andrew Andrew, thanks for the pointers. Chris resolved before I even looked: https://forums.whonix.org/t/fixing-whonix-boot-issue-after-securing-qubes-root-auth/3155 https://github.com/QubesOS

Re: [qubes-users] isolated workflows - image converter - trusted jpg

2016-11-16 Thread Chris Laprise
What is the command to do the trusted image conversion? Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.co

Re: [qubes-users] Incremental / continuous backups?

2016-11-16 Thread Chris Laprise
as incremental backup files. A search on 'btrfs send backup' will bring up some guides. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-user

Re: [qubes-users] PAM errors after disabling password-less root

2016-11-16 Thread Chris Laprise
On 11/16/2016 01:26 PM, Andrew wrote: 3n7r0...@gmail.com: On Wednesday, November 16, 2016 at 1:22:43 PM UTC, Chris Laprise wrote: On 11/15/2016 04:04 PM, Unman wrote: On Tue, Nov 15, 2016 at 02:26:12PM -0500, Chris Laprise wrote: On 11/15/2016 07:20 AM, Unman wrote: On Tue, Nov 15, 2016

Re: [qubes-users] PAM errors after disabling password-less root

2016-11-16 Thread Chris Laprise
On 11/15/2016 04:04 PM, Unman wrote: On Tue, Nov 15, 2016 at 02:26:12PM -0500, Chris Laprise wrote: On 11/15/2016 07:20 AM, Unman wrote: On Tue, Nov 15, 2016 at 11:55:13AM +, Unman wrote: On Tue, Nov 15, 2016 at 05:53:56AM -0500, Chris Laprise wrote: Following the instructions

[qubes-users] PAM errors after disabling password-less root

2016-11-15 Thread Chris Laprise
/common-auth'. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to q

Re: [qubes-users] Re: mounting a disk image or volume in app-vm, fast backups

2016-11-14 Thread Chris Laprise
On 11/14/2016 05:20 PM, pixel fairy wrote: On Monday, November 14, 2016 at 5:09:41 PM UTC-5, Chris Laprise wrote: Using btrfs as the dom0 filesystem (or a btrfs volume added to a dom0 pool) could enable the advantages being sought here. Using either snapshots or reflinks, you can create

Re: [qubes-users] Re: mounting a disk image or volume in app-vm, fast backups

2016-11-14 Thread Chris Laprise
. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@google

Re: [qubes-users] One step foerward, two steps back on Macbook 11,1 - can't boot into Qubes

2016-11-14 Thread Chris Laprise
nux is much easier to boot on a Mac from DVD. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post

Re: [qubes-users] Re: Intel TXT advice

2016-11-13 Thread Chris Laprise
a remote exploit that can also priv escalate against Xen--and from there possibly infect firmware or boot device--would benefit from using AEM. When I last shopped around, I was under the impression that TXT was tied to AMT/ME/Vpro as a package. Chris -- You received this message because

Re: [qubes-users] Re: Installing VPN in Qubes Versus VPN on a Router

2016-11-13 Thread Chris Laprise
TTPS, ZRTP, etc.) by implication. Then the only way to have reliable link encryption is to have everyone we communicate with sitting at home connecting to a single VPN server... each from their router-bound VPN clients... tethered by an ethernet cable between router and PC. Egads. Chris --

Re: [qubes-users] Leak Problems with VPN ProxyVM + AirVPN & Network lock

2016-11-12 Thread Chris Laprise
generated from the VPN VM from the packets going to/from appVMs. So accidental net access generated while using the VPN CLI, for example, will be blocked and stay out of the VPN tunnel. Its not critical but Whonix people wanted it as a precaution. Chris -- You received this message because you

Re: [qubes-users] Thoughts on Qubes OS Security... Could be improved.

2016-11-12 Thread Chris Laprise
he prompts over and over for VMs that are created, and there is no way to guarantee that 'certain' VMs have integrity to do this by default. ==== Hi Chris, Its easy to enable apparmor. See the Whonix documentation about this. I will have a look thanks. I have read that Ap

Re: [qubes-users] Thoughts on Qubes OS Security... Could be improved.

2016-11-12 Thread Chris Laprise
firewall does, the risk is very low. I don't think it really sacrifices any security to share a template with sys-net. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from

Re: [qubes-users] Leak Problems with VPN ProxyVM + AirVPN & Network lock

2016-11-12 Thread Chris Laprise
y VM & maybe the other iptables commands from the VPN doc assuming a user manually implemented them, yes. So probably only some further bugs in combination would lead to serious issues. I see. So that is similar to the scenario I described above. Chris @Sec Tester: AirVPN enables y

Re: [qubes-users] Re: Are Qubes/Xen vulnerable to new DRAMA attack?

2016-11-11 Thread Chris Laprise
On 11/11/2016 10:37 PM, Sec Tester wrote: Perhaps another reason why VM's shouldn't have default root access? "taskset 0x2 sudo ./measure -p 0.7 -s 16." This really needs root to work?! This could be important... these rowhammer vulns have become BAD. Chris -- You received th

Re: [qubes-users] Display Calibration

2016-11-11 Thread Chris Laprise
er drivers operate there. Chris For now I can configure apps (at least Darktable for sure) to use my color profile manually. (BTW: I'm about to create a "color management in Qubes" documentation soon) - -- Best Regards, Marek Marczykowski-Górecki Invisible Things Lab A: Because it

Re: [qubes-users] Leak Problems with VPN ProxyVM + AirVPN & Network lock

2016-11-11 Thread Chris Laprise
On 11/11/2016 01:24 PM, David Hobach wrote: On 11/10/2016 10:07 PM, Chris Laprise wrote: > On 11/10/2016 01:28 PM, David Hobach wrote: >> I'd recommend to avoid any tools employing iptables which were not >> written explicitly for Qubes as well. > > This. Or at least d

Re: [qubes-users] Leak Problems with VPN ProxyVM + AirVPN & Network lock

2016-11-11 Thread Chris Laprise
to 'qubes-vpn-handler.sh' and it should work. Just don't click on the 'Activate Network Lock' as that will overwrite the firewall rules. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving e

Re: [qubes-users] Re: Are Qubes/Xen vulnerable to new DRAMA attack?

2016-11-10 Thread Chris Laprise
On 11/10/2016 12:50 PM, Chris Laprise wrote: On 11/10/2016 12:41 PM, raahe...@gmail.com wrote: On Thursday, November 10, 2016 at 12:38:58 PM UTC-5, raah...@gmail.com wrote: On Thursday, November 10, 2016 at 6:28:33 AM UTC-5, Eva Star wrote: Subj https://github.com/IAIK/drama All systems

Re: [qubes-users] Converting Win7 StandaloneHVM to TemplateHVM

2016-11-10 Thread Chris Laprise
the root.img from the standalone to the template's folder. Finally, install Qubes Tools into the template. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, sen

Re: [qubes-users] Re: Leak Problems with VPN ProxyVM + AirVPN & Network lock

2016-11-09 Thread Chris Laprise
the GUI program under the 'qvpn' group, granting it access to the net. Or you could change the policy of the OUTPUT chain to ACCEPT to bypass the group restriction, which doesn't affect leak prevention for forwarded traffic. Chris -- You received this message because you are subscribed

Re: [qubes-users] Re: Screen recorder for Qubes..?

2016-11-08 Thread Chris Laprise
On 11/07/2016 07:32 PM, Jean-Philippe Ouellet wrote: On Mon, Nov 7, 2016 at 2:29 PM, Chris Laprise <tas...@openmailbox.org> wrote: The framebuffer is being handled by the trusted dom0 graphics stack, so is actually a trusted input. Perhaps we have run into trusted != trustworthy termi

Re: [qubes-users] Re: Android-x86 on Qubes

2016-11-07 Thread Chris Laprise
have the additional drive configured for that VM. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To

Re: [qubes-users] Re: Screen recorder for Qubes..?

2016-11-07 Thread Chris Laprise
a simple matter to pipe the raw video to a codec in an appVM. For many, this may be an acceptably unlikely risk, particularly if the thing you are recording is relatively trusted already. The threat model is pretty similar to Qubes' Trusted PDF feature. Chris -- You received this mes

Re: [qubes-users] Special (Secure) Browser Frontend for Qubes?!

2016-11-02 Thread Chris Laprise
specific to web browsing. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send

Re: [qubes-users] How to rotate VPNs?

2016-10-29 Thread Chris Laprise
fig filename that is a symlink to an actual config file. You could have an rc.local script that randomly selects a config file and creates the symlink. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] How to destroy files without leaving any traces ?

2016-10-26 Thread Chris Laprise
should rely on when deleting specific files. Some SSDs and HDDs also have a "secure erase" feature which erases the entire drive. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop r

Re: [qubes-users] Update to xen-4.6.3 doesn't appear in /boot

2016-10-25 Thread Chris Laprise
On 10/25/2016 03:07 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Oct 25, 2016 at 02:27:23PM -0400, Chris Laprise wrote: I'm trying to install the xen-4.6.3 package from current-testing, but there is no xen*.gz added to /boot. This file is part

[qubes-users] Update to xen-4.6.3 doesn't appear in /boot

2016-10-25 Thread Chris Laprise
I'm trying to install the xen-4.6.3 package from current-testing, but there is no xen*.gz added to /boot. How can I get this installed properly to test on my system? Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubs

Re: [qubes-users] swappiness, caches

2016-10-20 Thread Chris Laprise
ping seemed less common. There is also vm.vfs_cache_pressure which affects cache size. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubs

Re: [qubes-users] Anonymize MAC address

2016-10-18 Thread Chris Laprise
On 10/18/2016 04:26 AM, pl1...@sigaint.org wrote: On 10/16/2016 02:02 PM, pl1...@sigaint.org wrote: On 10/15/2016 08:59 AM, pl1...@sigaint.org wrote: Anyone? Instructions for MAC anonymization have just been updated: https://www.qubes-os.org/doc/anonymizing-your-mac-address/ Chris Ok

Re: [qubes-users] Re: Unable to uptade templates affer forced all traffic trhough VPN

2016-10-17 Thread Chris Laprise
. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@google

Re: [qubes-users] Anonymize MAC address

2016-10-17 Thread Chris Laprise
On 10/16/2016 02:02 PM, pl1...@sigaint.org wrote: On 10/15/2016 08:59 AM, pl1...@sigaint.org wrote: Anyone? Instructions for MAC anonymization have just been updated: https://www.qubes-os.org/doc/anonymizing-your-mac-address/ Chris Ok, is recommend to use debian as sys-net My question

Re: [qubes-users] Re: Unable to uptade templates affer forced all traffic trhough VPN

2016-10-15 Thread Chris Laprise
On 10/15/2016 12:56 PM, 4lgaqp+cqeepdnbinsts via qubes-users wrote: Hi Chris, Thanks for the suggestion. Just to clarify, the VPN tunnel was created within the sys-firewall, and currently that's the only proxyVM that I'm using (apart from the sys-whonix), hence all traffic from the sys-net

Re: [qubes-users] Unable to uptade templates affer forced all traffic trhough VPN

2016-10-15 Thread Chris Laprise
)... https://www.qubes-os.org/doc/software-update-vm/#updates-proxy 3. If you have sys-whonix setup, it will already have a running update proxy 4. Reconfigure the templates to not use the update proxy Chris -- You received this message because you are subscribed to the Google Groups "

Re: [qubes-users] Anonymize MAC address

2016-10-15 Thread Chris Laprise
On 10/15/2016 08:59 AM, pl1...@sigaint.org wrote: Anyone? Instructions for MAC anonymization have just been updated: https://www.qubes-os.org/doc/anonymizing-your-mac-address/ Chris -- You received this message because you are subscribed to the Google Groups "qubes-users&q

Re: [qubes-users] ANN: Leakproof Qubes VPN

2016-10-13 Thread Chris Laprise
problem which is my overriding concern. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to

Re: [qubes-users] ANN: Leakproof Qubes VPN

2016-10-13 Thread Chris Laprise
will be fixed in a timely fashion. I am wondering what the heck "reasonably secure OS" is supposed to mean in this context. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving

Re: [qubes-users] ANN: Leakproof Qubes VPN

2016-10-13 Thread Chris Laprise
On 10/13/2016 01:08 AM, Manuel Amador (Rudd-O) wrote: On 10/13/2016 03:13 AM, Chris Laprise wrote: Here is a rundown of initial concerns... * Routing tables should not be manipulated when VPN clients will surely do this as well The program prohibits OpenVPN from manipulating routing tables

Re: [qubes-users] How to force AppVm to only use Proxy-VPN connection ?

2016-10-12 Thread Chris Laprise
On 10/12/2016 10:58 PM, entr0py wrote: Manuel Amador (Rudd-O): On 10/12/2016 07:58 PM, Chris Laprise wrote: This requirement is already satisfied in the Qubes VPN doc: https://www.qubes-os.org/doc/vpn/#set-up-a-proxyvm-as-a-vpn-gateway-using-iptables-and-cli-scripts The scripts will stop

Re: [qubes-users] ANN: Leakproof Qubes VPN

2016-10-12 Thread Chris Laprise
t agnostic and more importantly fills Patrick's requirements for Tor isolation. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubsc

Re: [qubes-users] How to force AppVm to only use Proxy-VPN connection ?

2016-10-12 Thread Chris Laprise
On 10/12/2016 05:40 PM, Manuel Amador (Rudd-O) wrote: On 10/12/2016 07:58 PM, Chris Laprise wrote: This requirement is already satisfied in the Qubes VPN doc: https://www.qubes-os.org/doc/vpn/#set-up-a-proxyvm-as-a-vpn-gateway-using-iptables-and-cli-scripts The scripts will stop non-VPN

Re: [qubes-users] How to force AppVm to only use Proxy-VPN connection ?

2016-10-12 Thread Chris Laprise
nstead of going around it. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group,

Re: [qubes-users] Random MAC addresses working in Network Manager 1.4.2

2016-10-11 Thread Chris Laprise
On 10/03/2016 03:05 PM, Chris Laprise wrote: Network Manager 1.4.2 has been testing very well for me the last few days... This new version appears to randomize MAC addresses properly, and the feature set has evolved to the point where the randomization process is managed in a more holistic

Re: [qubes-users] How to trim AppVm's data to match the correct size inside?

2016-10-10 Thread Chris Laprise
option. That is the Qubes default. You can do a one-time recovery simply with 'sudo fstrim -v /rw' . There should be no need to resort to long brute force methods like using dd and cp. Chris -- You received this message because you are subscribed to the Google Groups "qubes-u

Re: [qubes-users] Major problems with 3.2, devs must address

2016-10-05 Thread Chris Laprise
in business models from top-tier brands. If you want to depart from that (not very small) selection flying your "PC compatible" and "homemade rig" flags while carrying the burden of Qubes' additional hardware requirements, well, don't expect much. Chris -- You received

Re: [qubes-users] Can't get disposable VMs to work

2016-10-03 Thread Chris Mays
On Sunday, October 2, 2016 at 11:36:09 PM UTC-5, raah...@gmail.com wrote: > On Monday, October 3, 2016 at 12:05:43 AM UTC-4, Chris Mays wrote: > > On Sunday, October 2, 2016 at 10:53:06 PM UTC-5, Andrew David Wong wrote: > > > -BEGIN PGP SIGNED MESSAGE-

[qubes-users] Random MAC addresses working in Network Manager 1.4.2

2016-10-03 Thread Chris Laprise
/NetworkManager.conf.html man nm-settings https://github.com/QubesOS/qubes-issues/issues/938 Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-user

Re: [qubes-users] Can't get disposable VMs to work

2016-10-02 Thread Chris Mays
On Sunday, October 2, 2016 at 10:53:06 PM UTC-5, Andrew David Wong wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > On 2016-10-02 20:45, Chris Mays wrote: > > I just installed Qubes OS for the first time today, and am having troubles > > getting a disposabl

Re: [qubes-users] Why should I verify digests, if I already checked PGP signatures?

2016-10-01 Thread Chris Laprise
mention that. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to q

Re: [qubes-users] "Carrying forward" a DMA attack..?

2016-09-25 Thread Chris Laprise
On 09/25/2016 08:12 AM, johnyju...@sigaint.org wrote: Chris wrote: Especially if you did the sharing via a separate vpn or ssh tunnel. But in general, I don't think Qubes security should be considered much if any benefit to adjacent non-Qubes systems. I'm curious as to why you would say

Re: [qubes-users] "Carrying forward" a DMA attack..?

2016-09-25 Thread Chris Laprise
I would say having the Qubes box between the laptop and the Internet generally increases the safety of the laptop. Especially if you did the sharing via a separate vpn or ssh tunnel. But in general, I don't think Qubes security should be considered much if any benefit to adjacent non-Qu

Re: [qubes-users] Setup VPN, DNS script and iptables

2016-09-25 Thread Chris Laprise
traffic except the vpn connection itself. The forwarding rules you added are great for protecting downstream vms, but they don't help protect the vpn vm in this way. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubs

Re: [qubes-users] "Carrying forward" a DMA attack..?

2016-09-25 Thread Chris Laprise
tream. Etc... Of course, non-networked VMs are the safest of all. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googl

Re: [qubes-users] 4th gen X1 Carbon graphics issues

2016-09-24 Thread Chris Laprise
Have you tried using the grub boot menu to select another kernel version? You can also adjust some kernel parameters there by pressing 'e'. Does your x1 have an option for legacy boot instead of UEFI? That may work better. Chris -- You received this message because you are subscribed

Re: [qubes-users] Why won't Google Chrome remember my Google logins?

2016-09-24 Thread Chris Laprise
reason. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to q

Re: [qubes-users] Why won't Google Chrome remember my Google logins?

2016-09-24 Thread Chris Laprise
the vm, that sounds like a Chrome bug. If the problem hinges on stopping/starting, then Chrome may be storing session data in a nonstandard location (instead of /home/user) such as /var. When you are running Chrome, look in /var/lib to see if Chrome is writing files there. Chris -- You

Re: [qubes-users] Re: Dear qubes-users

2016-09-24 Thread Chris Laprise
left; so there's a chance they could suddenly disappear, but for now, it's not a bad option.) Cheers. JJ Riseup sent out a similar message last week, saying they needed to raise funds quickly. Chris -- You received this message because you are subscribed to the Google Groups "qubes-

Re: [qubes-users] Is it possible to have 2 Net VMs - one for Ethernet, another for WiFi..?

2016-09-23 Thread Chris Laprise
vm should have only ethernet, and the other vm only wifi. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.co

Re: [qubes-users] BTRFS?

2016-09-23 Thread Chris Laprise
On 09/23/2016 08:00 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, Sep 23, 2016 at 07:42:07AM -0400, Chris Laprise wrote: On 09/22/2016 07:12 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Sep 22

Re: [qubes-users] BTRFS?

2016-09-23 Thread Chris Laprise
ule *first* to emulate the current architecture? That way, people can continue to have the same storage choices and backup procedures they already do. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and s

Re: [qubes-users] BTRFS?

2016-09-22 Thread Chris Laprise
On 09/22/2016 02:08 PM, se...@redhat.com wrote: On Thursday, September 22, 2016 at 1:39:20 PM UTC-4, Chris Laprise wrote: On 09/22/2016 01:05 PM, johnyju...@sigaint.org wrote: Has the Qubes team ever considered the use of btrfs? Qubes tools will even utilize btrfs reflinks where possible, so

Re: [qubes-users] BTRFS?

2016-09-22 Thread Chris Laprise
On 09/22/2016 01:05 PM, johnyju...@sigaint.org wrote: Has the Qubes team ever considered the use of btrfs? Qubes tools will even utilize btrfs reflinks where possible, so hardly any extra space is used when you clone a template or other vm. Chris -- You received this message because you

Re: [qubes-users] Usability: "Firewall rules" setting will likely be missunderstood often

2016-09-22 Thread Chris Laprise
On 09/21/2016 06:24 AM, Robert Mittendorf wrote: Am 09/20/2016 um 10:29 PM schrieb Chris Laprise: This is a good candidate for filing an issue, but mainly for this situation -- "A warning if an upstream VM does not implement the firewall rules", which should include connecting

Re: [qubes-users] Usability: "Firewall rules" setting will likely be missunderstood often

2016-09-20 Thread Chris Laprise
ee with that. Chained proxyvms are probably more common than you think. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...

Re: [qubes-users] Booting Cubes, Migration

2016-09-19 Thread Chris Laprise
into the current system. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group,

Re: [qubes-users] VPN in proxyVM

2016-09-19 Thread Chris Laprise
vpn's address when browsing to a site like whatismyip.com. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegro

Re: [qubes-users] Encfs + Dropbox: How to keep your cloud files secure?!

2016-09-16 Thread Chris Laprise
a try because its more secure and probably less complex than what you're suggesting. Of course, with Qubes its up to the user to weigh the risks and make the decicions. Good luck... Chris -- You received this message because you are subscribed to the Google Groups "qubes-users&q

Re: [qubes-users] Problems attampting to test/install on a Lenovo 11e Yoga - 3.2 rc3

2016-09-16 Thread Chris Laprise
ify the iso with gpg? And is the DVD or USB stick big enough (should be at least 7GB)? Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-user

Re: [qubes-users] Encfs + Dropbox: How to keep your cloud files secure?!

2016-09-15 Thread Chris Laprise
ient vm to make this truly secure. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this gro

Re: [qubes-users] Trying to create IP tables rules on vpn ProxyVM to only allow access to LAN and VPN IPs

2016-09-12 Thread Chris Laprise
setup also re-routes all DNS over the vpn tunnel, so that is something to keep in mind for this option. Chris 1. https://www.qubes-os.org/doc/vpn/ -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] Installation problems?

2016-09-10 Thread Chris Laprise
with another Linux distro like fedora, and examine the boot/install media and the rpm that its complaining about. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, sen

Re: [qubes-users] Re: Does anyone use a dedicated Tor router box..?

2016-09-10 Thread Chris Laprise
ulnerabilities" when said bugs are discovered. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To

Re: [qubes-users] Can't connect a VPN before Tor

2016-09-09 Thread Chris Laprise
to start is trying create the whole setup in Whonix-Qubes using the Whonix doc you referenced. The Whonix forum should be able to help you with any specific issues when following their directions. Chris -- You received this message because you are subscribed to the Google Groups "qubes-us

Re: [qubes-users] problem of using PPTP

2016-09-09 Thread Chris Laprise
-- Hi, You could try openvpn instead of PPTP if your VPN service supports it. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-user

Re: [qubes-users] Newbie Qubes questions.. please help!

2016-09-07 Thread Chris Laprise
at the anti-evil-maid feature. For 2-factor, take a look at https://www.qubes-os.org/doc/yubi-key/ Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to q

Re: [qubes-users] Qubes 3.2 rc3 has been released!

2016-08-31 Thread Chris Laprise
or rc2 can just install updates, no need for full reinstall. For older releases check above page for upgrade instructions. - -- Qubes Manager systray icon is gone now... Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To u

Re: [qubes-users] PIA (privateinternetaccess.com) + Qubes OS

2016-08-30 Thread Chris Laprise
, like using 'ping' with both IP addresses and domain names, and checking 'iptables'. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-user

Re: [qubes-users] Qubes VM compromised?

2016-08-23 Thread Chris Laprise
cookie right after you created the account (also with a new/different cookie), etc. One thing that seems missing from your description is whether you stuck to https for security... Tor exit nodes are really frightful. Chris -- You received this message because you are subscribed to the Google

Re: [qubes-users] Need advice on PC

2016-08-23 Thread Chris Laprise
--especially IOMMU/ VT-d. A pretty good indicator for TPM in a laptop is whether the unit has a fingerprint scanner. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails fro

<    6   7   8   9   10   11   12   >