Re: [qubes-users] ThinkPad W530

2023-05-04 Thread Simon Newton
l.com?utm_medium=email&utm_source=footer> > . > -- Kind Regards, Simon Newton E: simon.new...@gmail.com -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, se

Re: [qubes-users] [UPDATE] Re: NitroPad T430 passes hardware certification for Qubes 4.0!

2022-04-03 Thread Simon Newton
On Sun, 3 Apr 2022 at 16:46, Franz <169...@gmail.com> wrote: > > Many thanks Simon, > I do not have a T430, I have a W520 with coreboot, but the problem is just > the same. I was wondering why VT-d is not working and your email explained > it. So many thanks. > Now I s

Re: [qubes-users] [UPDATE] Re: NitroPad T430 passes hardware certification for Qubes 4.0!

2022-04-03 Thread Simon Newton
>Are you sure? Intel tells that i7-3632QM supports VT-d Yes. You have made the same mistake nitrokey did. There are two versions of the CPU, one is BGA which supports VT-d, but does not fit the rPGA T430 motherboard. The other is the rPGA version, which does fit the T430 but does not have VT-d htt

Re: [qubes-users] Nitropad X230 with Qubes 4.1

2022-01-19 Thread Simon Newton
uilding this yourself from source, or grabbing a prebuilt bin from the Heads CircleCI https://app.circleci.com/pipelines/github/osresearch/heads - the hardware is still an X230. However you need to consider if Nitropad would support your product were you to do this. -- Kind Regards, Simon Newton E:

Re: [qubes-users] Re: [HCL] ThinkPad T430

2021-09-11 Thread Simon Newton
ps > "qubes-users" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to qubes-users+unsubscr...@googlegroups.com. > To view this discussion on the web visit > https://groups.google.com/d/msgid/qubes-users/672ae672-3d5f-421b-90dd-cdea3c1

Re: [qubes-users] SWAPGS Side Channel Attack

2019-09-09 Thread Simon Gaiser
t.org/archives/html/xen-devel/2018-07/msg00982.html [3]: https://grsecurity.net/respectre_announce.php Simon -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEE3E8ezGzG3N1CTQ//kO9xfO/xly8FAl12ZYgACgkQkO9xfO/x ly8fVhAAytcPEKgHfchZFSx8b4q0yGijnM2PVS5z7zbYchQtZ3xkgf+6ZxGwauay buD22CE2B+ZMWhgnS3

Re: [qubes-users] SWAPGS Side Channel Attack

2019-09-09 Thread Simon Gaiser
ing like this is not in place currently. See [3] for a description of the non-public gcc plugin from grsecurity which implements this approach. [2]: https://lists.xenproject.org/archives/html/xen-devel/2018-07/msg00982.html [3]: https://grsecurity.net/respectre_announce.php Simon -- You receive

[qubes-users] Re: service VMs not auto starting

2019-05-11 Thread simon . newton
On Saturday, May 11, 2019 at 1:47:05 PM UTC+1, simon...@gmail.com wrote: > Ive not had this problem on any other machine I run qubes on, and its a bit > perplexing > > service VMs will not start automatically during the boot process. systemctl > status returns "libxenlight

[qubes-users] service VMs not auto starting

2019-05-11 Thread simon . newton
Ive not had this problem on any other machine I run qubes on, and its a bit perplexing service VMs will not start automatically during the boot process. systemctl status returns "libxenlight failed to create new domain" libxl-driver.log shows "domcreate_attached_devices: unable to add PCI devic

Re: [qubes-users] why was DNS/ICMP removed from Qubes manager/firewall in R4?

2019-02-14 Thread simon . newton
es in the foot because the interface is not intuitive (it > > says it blocks all traffic other than what is specified and then later > > modifies this saying "just kidding, we let DNS through") > > > > Feb 14, 2019, 11:59 AM by simon.new...@gmail.com: > >

Re: [qubes-users] why was DNS/ICMP removed from Qubes manager/firewall in R4?

2019-02-14 Thread simon . newton
On Thursday, February 14, 2019 at 11:54:28 AM UTC, simon@gmail.com wrote: > On Thursday, February 14, 2019 at 3:54:04 AM UTC, Marek Marczykowski-Górecki > wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > > On Wed, Feb 13, 2019 at 08:42:10AM

Re: [qubes-users] why was DNS/ICMP removed from Qubes manager/firewall in R4?

2019-02-14 Thread simon . newton
On Thursday, February 14, 2019 at 3:54:04 AM UTC, Marek Marczykowski-Górecki wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Wed, Feb 13, 2019 at 08:42:10AM -0800, simon.new...@gmail.com wrote: > > In 3, if i clicked on "block connections" in the Qubes manager firewall > > sect

[qubes-users] why was DNS/ICMP removed from Qubes manager/firewall in R4?

2019-02-13 Thread simon . newton
In 3, if i clicked on "block connections" in the Qubes manager firewall section, there was (if memory serves me) an option to block DNS and ICMP. That is not present in R4 (though docs say you can disable DNS and ICMP manually) I'm just wondering what the logic behind the removal was? I would

Re: [qubes-users] Does anyone use any integrity checking in Dom0

2019-01-08 Thread simon . newton
Chris Laprise wrote: > Of course, I should mention anti evil maid: AEM essentially protects the > /boot partition (and your firmware!). That is nothing to sneeze at and > gives you a decent basis for investigating the dom0 root volume if > something does crop up. AEM wont work with one of my m

[qubes-users] Does anyone use any integrity checking in Dom0

2019-01-08 Thread simon . newton
As per subject, does anyone use things such as AIDE (or other file integrity IDS) ? I understand the security model is "if dom0 is compromised, you are fscked" but it would be at least nice to have something that gave me a heads up if such an event happens. -- You received this message becaus

Re: [qubes-users] Re: Qube max storage size

2019-01-08 Thread simon . newton
On Monday, January 7, 2019 at 3:03:00 PM UTC, unman wrote: > On Mon, Jan 07, 2019 at 07:52:25AM -0600, Stuart Perkins wrote: > > > > > > On Sun, 6 Jan 2019 07:41:35 -0800 (PST) > > Plex wrote: > > > > >On Sunday, January 6, 2019 at 3:20:08 PM UTC, Plex wrote: > > >> Is there a technical limitat

[qubes-users] Re: my dom0 is not updating since before 4.01

2019-01-06 Thread simon . newton
On Sunday, January 6, 2019 at 1:32:45 PM UTC, Sergio Matta wrote: > I think I have a problem with yum file configuration. Fedora 25 looks like ok > but Qubes never finds data: > > Fedora 25 - x86_64 - Updates 1.0 MB/s | 24 MB 00:24 > Fedora 25 - x86_64

Re: [qubes-users] PCI passthrough working in Qubes R4.0?

2018-01-18 Thread Simon Gaiser
Marek Marczykowski-Górecki: [...] > I don't see anything else related to this device. So until Simon gets > permissive mode sorted out, it look like you have to use that usb > ethernet. FYI: https://github.com/QubesOS/qubes-core-admin/pull/184 -- You received this message b

Re: [qubes-users] PCI passthrough working in Qubes R4.0?

2018-01-18 Thread Simon Gaiser
Marek Marczykowski-Górecki:> On Thu, Jan 18, 2018 at 03:06:00PM +0000, Simon Gaiser wrote: >> awokd: >>> On Thu, January 18, 2018 2:26 pm, "Marek Marczykowski-Górecki" wrote: >>> >>>> >>>> According to logs provided by mossy-nw permiss

Re: [qubes-users] PCI passthrough working in Qubes R4.0?

2018-01-18 Thread Simon Gaiser
awokd: > On Thu, January 18, 2018 2:26 pm, "Marek Marczykowski-Górecki" wrote: > >> >> According to logs provided by mossy-nw permissive mode is correctly >> enabled in xen-pciback in dom0 for this device. The question here is what >> else is needed for HVM (using qemu in stubdomain). > > My dom0

Re: [qubes-users] How to rollback Dom0 updates?

2016-12-12 Thread Simon
p on a more positive note I find it great that the template VM now shut down themselves automatically once the update is done :) ! Have a nice day, Simon. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and

Re: [qubes-users] Re: How to enable permanent full screen mode in appvm ?

2016-12-11 Thread Simon
check notes while watching the video). Regards, Simon. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post

Re: [qubes-users] How to rollback Dom0 updates?

2016-12-11 Thread Simon
st probably an issue around the proxy feature (there is no such issue with the templates, updating Dom0 takes twice as much time as updating the templates). - I regularly have ghost updates (the icon announcing that updates are available while there are none) but I think this is a known issue.

[qubes-users] How to rollback Dom0 updates?

2016-12-10 Thread Simon
--- 8< -- Is there any equivalent feature allowing update rollback in Qubes-OS for the Dom0 domain? Thanks by advance, Simon. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe

[qubes-users] It's winter, my laptop is freezing (again!)

2016-12-09 Thread Simon
t the screen stays black when the X server should start, setting the Grub option i915.enable_rc6=0 does not help). Here is my previous message on the topic: https://groups.google.com/forum/#!topic/qubes-users/O4UO9CjO4TM Is there anything I can do or try? I hope someone has some good news fo

Re: [qubes-users] Special (Secure) Browser Frontend for Qubes?!

2016-11-04 Thread Simon
Hi Alex, Alex wrote : On 11/03/2016 11:37 AM, Simon wrote: If you use keepassx you may want to use its auto-type feature, which is designed exactly to prevent password theft by keylogger-only or clipboard-monitor-only malware. Auto type works by typing random parts of the password via simulated

Re: [qubes-users] Special (Secure) Browser Frontend for Qubes?!

2016-11-03 Thread Simon
Depending on your actual threat this may be something you may want to take into consideration. Yes but also dead slow :P. I was more thinking of... Yes, security is always a matter of compromise :). Regards, Simon. -- You received this message because you are subscribed to the Google Groups

Re: [qubes-users] Special (Secure) Browser Frontend for Qubes?!

2016-11-02 Thread Simon
ne) with just a right-click option instead of the current "Right-Click, A, Ctrl-Shift-C, Alt-Tab, Ctrl-T, Ctrl-Shift-C, Ctrl-C, Enter" sequence... Best regards, Simon. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubs

Re: [qubes-users] How to turn Windows HVM into Fullscreen ?

2016-10-29 Thread Simon
creen mode, otherwise if you do not remember this shortcut the Alt+Tab still works (and is not catchable by the VM, as described in the linked document) and allows you to safely escape from the full screen window. Regards, Simon. -- You received this message because you are subscribed to the Goo

Re: [qubes-users] System still freezes, still no resolution.

2016-09-23 Thread Simon
t Qubes has now switched to XFCE, the freezes came back and I do not know any equivalent setting on XFCE. I recently tried to completely disable compositing and am now crossing my fingers. Regards, Simon. -- You received this message because you are subscribed to the Google Groups "qu

Re: [qubes-users] R3.2-rc2: random reboots on Lenovo T520 (workaround)

2016-09-23 Thread Simon
cific issue. Moreover, if you check the issue list, you will find yet another issue still related to i915 handling, "Graphic woes / i915 - Intel Graphics 5500 on T450s": https://github.com/QubesOS/qubes-issues/issues/2232 Good luck... Simon. -- You received this message because you ar

[qubes-users] Qubes desktop random freezes on Thinkpad T500

2016-09-21 Thread Simon
months with the XRender workaround in KDE, so if anybody knows any equivalent in the XFCE world or any other way to fix this he will have all my gratitude :) ! Best regards, Simon. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To un