Re: [qubes-users] Re: External Fully Encrypted SSD Drive. What do you think?

2020-07-29 Thread brendan . hoar
On Wednesday, July 29, 2020 at 2:33:29 AM UTC-4, Qubes wrote: > > On 7/29/20 1:56 AM, ludwig...@gmail.com wrote: > > *What if it saves a spare set of encryption keys somewhere in its flash > for > > the "lawful investigator" to find?* > > > I am not aware of any proof to support this line of

[qubes-users] Re: HCL - Lenovo ThinkPad W520

2020-07-16 Thread brendan . hoar
On Sunday, July 12, 2020 at 2:51:25 PM UTC-4, pok...@gmail.com wrote: > > I have the W520 with CPU type i7-2630QM and Nvidia Quadro 2000M (Lenovo > 4284-E78). > > https://ark.intel.com/content/www/us/en/ark/compare.html?productIds=52219,53474 > > This laptop version doesnt have VT-d, but I

Re: [qubes-users] Accessing files on a different SSD on the same laptop...

2020-06-07 Thread brendan . hoar
On Sunday, June 7, 2020 at 12:29:28 PM UTC-4, Andrew Sullivan wrote: ... On the fedora-based VMs, the tool `gnome-disks` is a gui way of manually mounting filesystems. [I tend to forget the order of operations and/or flags for things like mount (which is the mountpoint? which is the source

Re: [qubes-users] Multiple X sessions in Dom0?

2020-05-31 Thread brendan . hoar
On Friday, May 29, 2020 at 6:15:31 AM UTC-4, donoban wrote: > > On 2020-05-29 02:34, brend...@gmail.com wrote: > > Can Qubes support multiple X sessions in dom0? > Or do you mean multiple X sessions with the same user? > Yes, exactly. On Friday, May 29, 2020 at 6:23:19 AM UTC-4, Frédéric

[qubes-users] Multiple X sessions in Dom0?

2020-05-28 Thread brendan . hoar
Can Qubes support multiple X sessions in dom0? e.g. default session on primary terminal (via ctrl-alt-f1), then start another session on the third pty (ctrl-alt-f3) after logging in as the primary qubes user in dom0? B -- You received this message because you are subscribed to the Google

[qubes-users] Re: Next update of Qubes?

2020-05-23 Thread brendan . hoar
On Saturday, May 23, 2020 at 11:32:31 AM UTC-4, Catacombs wrote: > > I see that Qubes does not announce planned new releases of Qubes, or state > what should trigger an update. > > Just seems like it would be so much easier if we had an entire new version > of Qubes, which I could install. At

Re: [qubes-users] Re: Install of the Fedora-32 templateVM failed

2020-05-18 Thread brendan . hoar
On Monday, May 18, 2020 at 6:01:13 PM UTC-4, TheGardner wrote: > > understood. > Guess I have to do some backups, which I have to move to my NAS. The new > machine will take two months longer. Have to come out with the current > space until then. > > Is it possible that you haven't invoked the

[qubes-users] Re: HCL - Dell Latitude E5470 + Docking Station

2020-05-11 Thread brendan . hoar
On Monday, May 11, 2020 at 6:13:21 PM UTC-4, Rafael Reis wrote: > My only concern right now is the decisions for the GUI of Qubes 4.1. I > wonder if the separation of the GUI and dom0 would result in > incompatibility with E5470 or even a big decrease in performance. This > thing is perfect

[qubes-users] Re: Fedora 30 approaching EOL, Fedora 31 TemplateVM available, Fedora 32 TemplateVM in testing

2020-05-01 Thread brendan . hoar
On Friday, May 1, 2020 at 12:39:54 AM UTC-4, seshu wrote: > > One question that just occured to me about upgrading the template VM's. > Many of the comments and posts in this forum are assuming Qubes is > installed on a laptop. I have it installed on a desktop, and my keyboard / > mouse uses

[qubes-users] Blanking memory for security?

2020-04-25 Thread brendan . hoar
Xen hypervisor overwrites memory before allocating it to a domU VM. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To

Re: [qubes-users] KDE Plasma in dom0 under R4.0.3

2020-04-11 Thread brendan . hoar
On Saturday, April 11, 2020 at 7:10:18 PM UTC, Sven Semmler wrote: > > On Sat, Apr 11, 2020 at 02:48:17PM -0400, Chris Laprise wrote: > > I've never had a problem with KDE in dom0 as long as the display manager > is > > switched to sddm and BIOS is set to integrated graphics. "Discrete >

Re: Antw: [EXT] [qubes-users] probable lvm thin_pool exhaustion

2020-03-10 Thread brendan . hoar
On Wednesday, March 11, 2020 at 1:34:17 AM UTC, maiski wrote: > > > Quoting brend...@gmail.com : > > > > Qubes 4.1 (in development) has added a warning (in addition to the > current > > lvm space usage warning) for lvm metadata usage above a threshold. 4.0 > > doesn't have the metadata

Re: Antw: [EXT] [qubes-users] probable lvm thin_pool exhaustion

2020-03-10 Thread brendan . hoar
On Tuesday, March 10, 2020 at 11:49:58 AM UTC, maiski wrote: > > Quoting Ulrich Windl >: > > For some reason I have a "watch -n30 lvs" running in a big terminal. > > On one of the op lines I see the usage of the thin pool. Of course > > this only helps before the problem... > > > > But I

[qubes-users] Re: SSD and safety.

2020-02-29 Thread brendan . hoar
The diskashur and similar projects will come under the same scrutiny as SED devices’ built-in TCG Opal: that the encryption layer is closed source and not publicly auditable (unlike LUKS w/dm-crypt under Linux which is auditable). The summary of my position is: use the hw encryption features

Re: [qubes-users] SSD and safety.

2020-02-26 Thread brendan . hoar
PS - don't experiment with erasing drives on your daily driver. the drive is going to do what you asked it to do, no matter, say, whether you booted on that drive or not. POOF! -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe

Re: [qubes-users] SSD and safety.

2020-02-26 Thread brendan . hoar
On Wednesday, February 26, 2020 at 3:37:27 PM UTC, Steve Coleman wrote: > > On 2/26/20, ggg...@gmail.com > > wrote: > > > I discovered there is no program to clear an SSD. > > If you are using an Opal 2 compliant SSD and had created an encrypted > range before formatting your partition then

[qubes-users] Re: Relative comparison of Qubes OS, and its multiple VM's versus Boxes.

2020-02-26 Thread brendan . hoar
On Wednesday, February 26, 2020 at 12:18:48 PM UTC, ggg...@gmail.com wrote: > > Boxes being the Sandboxing software available in Linux. It is my hunch, > that the VM's are taking advantage of some hardware feature that insulates > them that might be a security hole for Boxes. I dunno? >

Re: [qubes-users] Creating snapshot

2020-02-18 Thread Brendan Hoar
On Tue, Feb 18, 2020 at 8:41 PM Thierry Laurion - Insurgo Technologies Libres / Open Technologies wrote: > I'm talking on top of my head but snapshots are supposed to be taken > automatically, with 2 reverts possible, by default. This may be up to interpretation but... I assumed the original

[qubes-users] Creating snapshot

2020-02-18 Thread brendan . hoar
Assuming a standard qubes 4.0.x install, just clone the VM each time you are making risky changes...before each change of course.* The use of lvm thin pool makes clones essentially use zero storage other that the bits where they diverge from the original VM, where copy on write preserves the

[qubes-users] Using secondary storage

2020-02-12 Thread brendan . hoar
I see reference to both /dev/sdc and /dev/sbc in your post. Which is it? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

Re: [qubes-users] Re: Upgrade to 16 GB RAM for an X230

2020-02-10 Thread brendan . hoar
Two inter-related arguments for switching to Coreboot so that one can replace an Intel wireless card with another card: 1. Lenovo BIOS generally has a small whitelist of WiFi cards that work and block all others. 2. Presumably the reason for this whitelist is support for AMT “out of band and

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread brendan . hoar
On Sunday, February 9, 2020 at 5:25:56 PM UTC, brend...@gmail.com wrote: > > > Has anyone tried utilizing the xen command line options to mask bits in > the cpuid, in particular section 1.2.35 cpuid_mask_ecx)? > > The man page below says that "Settings applied here take effect globally, >

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread brendan . hoar
On Sunday, February 9, 2020 at 3:19:34 PM UTC, Claudia wrote: > > > marmarek: > > This is a very bad idea to "fix" it. Those missing/changed CPUID bits > later on will cause issues. > > And given most of the microcode updates recently are about speculative > execution, missing those > > features

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Brendan Hoar
On Sun, Feb 9, 2020 at 9:15 AM Claudia wrote: > From linuxreviews.org: > "There have been reports of RDRAND issues after resuming from suspend on > some AMD family 15h and family 16h systems. [...] RDRAND support is > indicated by CPUID Fn0001_ECX[30]. This bit can be reset by clearing > MSR

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-07 Thread brendan . hoar
On Friday, February 7, 2020 at 9:35:25 PM UTC, zach...@gmail.com wrote: > > I preemptively submitted this PR to see what the Qubes team thinks. > https://github.com/QubesOS/qubes-vmm-xen/pull/70 > > I agree it probably should be fixed upstream, although I've seen the Qubes > team make exceptions

[qubes-users] Re: How to use the USB modem HUAWEI E3372h to connect to the internet in Qubes OS 4.0.3 ?

2020-02-05 Thread brendan . hoar
On Sunday, February 2, 2020 at 1:06:45 PM UTC, M wrote: > > I can’t figure out how I can use the USB modem HUAWEI E3372h to connect to > the internet in Qubes OS 4.0.3. > So having watched these threads over the past week, I have some comments: First, you have a very finicky device. The mode

Re: [qubes-users] Re: AppVms being killed on resume due to clock skew too large

2020-02-01 Thread brendan . hoar
Perhaps due to memory balancing being temporarily unable to service all AppVMs upon dom0 wake? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

[qubes-users] Re: Anyone using remmina for RDP? (AND able to alt+tab in the RDP session w/o xfce stealing the keystroke)

2020-01-28 Thread brendan . hoar
On Monday, January 27, 2020 at 8:34:33 PM UTC, Stumpy wrote: > > I am using remmina (1.3.10) on a debian (10) appvm to rdp into a win10 > box and it works fairly well, but there is some sort of issue with > remmina grabbing the keystrokes? > When i try to alt+tab in my rdp session xfce/qubes

[qubes-users] feature request

2020-01-25 Thread brendan . hoar
I think some window managers allow one to pin certain applications to particular virtual desktops. But those aren’t really security features, more just window manager tricks to help users organize windows. My preference would be something along the lines of support for allowing multiple local

Re: [qubes-users] Re: qvm-create-windows-qube 2.0

2020-01-20 Thread brendan . hoar
Try running qvm-start-gui when the window doesn’t appear. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this

Re: [qubes-users] Re: qvm-create-windows-qube 2.0

2020-01-19 Thread brendan . hoar
On Friday, January 17, 2020 at 11:01:05 PM UTC, Elliot Killick wrote: > > On 2020-01-15 01:36, shiftedreality wrote: > > > You pointed me in the right direction. I was using Debian 10 as my > default > > Qubes template. > Debian 10 is supposed to be supported as a template. I didn't realize >

[qubes-users] Re: LibreOffice presentation mode with QubesOS

2020-01-16 Thread brendan . hoar
Alt-space fullscreen doesn’t work? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web

[qubes-users] Re: qvm-create-windows-qube 2.0

2020-01-14 Thread brendan . hoar
Which template are you using? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web visit

[qubes-users] qvm-create-windows-qube 2.0

2020-01-13 Thread brendan . hoar
Having manually set up windows VMs in in the pst, I can say that Elliot’s work here is quite the time saver. Just invoke the script, go off and do something for a bit, come back later with some windows VM installs completed, including the add on software you wanted. Haven’t tried the newer

[qubes-users] Re: Does qubes block usb on thunderbolt port?

2020-01-08 Thread brendan . hoar
On Wednesday, January 8, 2020 at 4:29:57 PM UTC-5, Ryan Tate wrote: > (The one thing that I do wonder is if is neccesary for sys-usb to bail > out on boot when an assigned device is not present, maybe there could be > a system for transient but assigned devices to be allowed to come online >

[qubes-users] Re: Does qubes block usb on thunderbolt port?

2020-01-08 Thread brendan . hoar
On Wednesday, January 8, 2020 at 6:19:54 AM UTC-5, Ryan Tate wrote: > > Does qubes block USB data on Thunderbolt ports? > So a few things: 1. Qubes has pcie hotplug disabled in the dom0 kernel, which TB uses for PCIe-based thunderbolt devices. This is disabled for security reasons. 2. The TB

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-03 Thread brendan . hoar
On Friday, January 3, 2020 at 3:48:33 PM UTC-5, Claudia wrote: > > January 3, 2020 7:17 PM, brend...@gmail.com wrote: > > > Since it appears the old made-for-purpose USB 2.0 EHCI Debug port > dongles are impossible to find > > these days, I've been looking around for alternatives and stumbled

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2020-01-03 Thread brendan . hoar
On Friday, January 3, 2020 at 12:53:31 PM UTC-5, Claudia wrote: > > January 1, 2020 5:09 PM, "Claudia" > > wrote: > > I'll see if I can figure out how to apply the patch to the latest 4.1 > (F31-based) and try it from there. In the mean time, if anyone has any > ideas please share. > Maybe

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-30 Thread brendan . hoar
On Monday, December 30, 2019 at 1:44:13 PM UTC-5, qubes123 wrote: > > Answering to your earlier question, my CPU capability information bits > change like this after suspend: > > (XEN) Entering ACPI S3 state. > (XEN) AMD-Vi: Applying erratum 746 workaround for IOMMU at :00:00.2 > (XEN)

Re: [qubes-users] Qubes Structure

2019-12-30 Thread brendan . hoar
On Monday, December 30, 2019 at 6:25:03 AM UTC-5, xao wrote: > > Don't know how I missed this link before, but after reading it, things got > much clear. Thank you! > One important tenet of Qubes is that the security focus is primarily protecting you from cross-domain (cross-VM) disclosure or

[qubes-users] Re: Recommended laptop?

2019-12-29 Thread brendan . hoar
On Sunday, December 29, 2019 at 5:35:52 PM UTC-5, Blake S wrote: > > On Wednesday, December 25, 2019 at 10:09:24 PM UTC-6, brend...@gmail.com > wrote: >> >> My own longterm Qubes primary has been a used W520 quad core with four >> 8GB DIMMs for 32GB of RAM. Not bad for 2012 era laptop. [Avoid

Re: [qubes-users] Qubes/Xen doesn't comply with IOMMU grouping rules for PCI passthru

2019-12-29 Thread brendan . hoar
On Sunday, December 29, 2019 at 7:25:49 PM UTC-5, Claudia wrote: > > Ha. Now that you mention it, I do remember laptops used to have PCIe > slots. But I think those days are pretty much over. > > On a side note, I remembered I saw some error about the IOMMU in the > kernel logs at some point. I

[qubes-users] Notebook with Nvidia Quadro graphics card

2019-12-28 Thread brendan . hoar
Older laptops w/ Optimus allowed choosing Integrated-only video (vs hybrid or vs Discrete). I set up my W520 w/ the Integrated intel cpu and it has been a workhorse. Contemporary laptops w/ Optimus only allow Hybrid or Discrete. No way to choose just Integrated. Qubes 4.0 and lower don’t

[qubes-users] Re: Recommended laptop?

2019-12-25 Thread brendan . hoar
My own longterm Qubes primary has been a used W520 quad core with four 8GB DIMMs for 32GB of RAM. Not bad for 2012 era laptop. [Avoid the dual core versions: they only have two memory slots and can only support 16GB Max.] Storage: 1 x mSATA (300MB/s) slot; 1 x SATA (600MB/s) main bay; 1 x SATA

Re: [qubes-users] upgrade: latest stable -> latest testing RC

2019-12-25 Thread brendan . hoar
One additional thing: certain install-related, VM-creation or volume-creation “fixes” across versions won’t be applied after an upgrade. E.g. there were volume mis-alignment fixes, that lead to better SSD and LVM performance, made after 4.0, that aren’t auto-fixed for existing VMs or

[qubes-users] Re: One of the configured repositories failed (Fedora 20 - x86_64)

2019-12-23 Thread brendan . hoar
On Monday, December 23, 2019 at 9:06:09 AM UTC-5, Spleen Productions wrote: > > I've setup a machine running R2 since i need audio working on Windows HVM. > > I would like to install QWT but when i run sudo-qubes-dom0-update i get > the following error: > > One of the configured repositories

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-23 Thread Brendan Hoar
On Mon, Dec 23, 2019 at 9:46 AM Claudia wrote: > Awesome, in time for Christmas even! Downloading it now. Looks like it > failed a few tests, so I don't know if it'll be usable enough to really > test suspend/resume on it but we'll see. Not sure if I'll get a chance to > install it today but

Re: [qubes-users] Re: HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-23 Thread Brendan Hoar
On Mon, Dec 23, 2019 at 6:45 AM Claudia wrote: > > I'm not sure this is the problem, though, because I get the same symptoms > when suspending in a Fedora 25 livecd. Which makes me think it's a Fedora > problem not a Xen problem, at least for R4.0. In Fedora 29 I think the > symptoms were

[qubes-users] Startup/Shutdown thin pool trim - where to insert with systemd?

2019-12-21 Thread brendan . hoar
Hi folks [ calling @tasket !] I'd like to have the system perform a thin_trim command across the primary thin pool on Qubes startup and shutdown. The purpose would be opportunistic erasure of deleted volumes in the pool (say, if they were removed without blkdiscard being run against them

Re: [qubes-users] HCL - Dell Inspiron 15 5000 (5575) AMD Ryzen 5 2500U w/ Vega 8 Graphics

2019-12-20 Thread brendan . hoar
On Friday, December 20, 2019 at 9:29:55 AM UTC-5, Claudia wrote: > > December 19, 2019 12:13 AM, "Claudia" > > wrote: > > > This is R4.1 build 20191013 > > > > It works pretty well, definitely better than 4.0, but there are some > weird boot issues. If I let it > > boot with everything as

Re: [qubes-users] wipe released diskspace of a disposable VM's

2019-12-19 Thread brendan . hoar
Use this one instead, previous one had a missing newline: https://pastebin.com/JMtuns8g Brendan -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

Re: [qubes-users] wipe released diskspace of a disposable VM's

2019-12-19 Thread brendan . hoar
On Thursday, December 19, 2019 at 12:09:26 PM UTC-5, Brendan Hoar wrote: > > This script shows the approach I take for an ephemerally keyed lvm pool: > > https://pastebin.com/LDKKwsWW > > And of course, since I was in a hurry, I see typos and better possible edits in th

Re: [qubes-users] wipe released diskspace of a disposable VM's

2019-12-19 Thread brendan . hoar
This script shows the approach I take for an ephemerally keyed lvm pool: https://pastebin.com/LDKKwsWW Assuming you want a windows standalone work VM and one or more whonix disposable VMs, you just need to change the two variables in the script and launch it in dom0. Be sure you know what

Re: [qubes-users] wipe released diskspace of a disposable VM's

2019-12-18 Thread brendan . hoar
On Wednesday, December 18, 2019 at 10:04:40 AM UTC-5, steve.coleman wrote: > > On 2019-12-15 22:04, brend...@gmail.com wrote: > My suggestion is, rather than the time consuming wiping of bits after > the fact would be to instead create an encrypted volume/partiton/pool > when launching a

Re: [qubes-users] wipe released diskspace of a disposable VM's

2019-12-17 Thread brendan . hoar
On Monday, December 16, 2019 at 5:33:52 PM UTC-5, Claudia wrote: > > brend...@gmail.com : > > Disposable VMs were not developed with anti-forensics in mind (e.g. no > protection in jurisdictions where you can be forced to hand over your drive > password > Never thought about it, but that makes

Re: [qubes-users] wipe released diskspace of a disposable VM's

2019-12-15 Thread brendan . hoar
As to the first question: with qubes 4.0 it is a bit difficult to effectively wipe free space in the default thin pool. One can create a thin volume and write to it until the thin pool reaches some saturation level (99.5%), then hit that volume with blkdiscard before invoking lvremove. Because

Re: [qubes-users] wipe released diskspace of a disposable VM's

2019-12-15 Thread brendan . hoar
Disposable VMs were not developed with anti-forensics in mind (e.g. no protection in jurisdictions where you can be forced to hand over your drive password). That being said... In 4.0 (updated) qubes now calls blkdiscard on volumes being removed before invoking lvremove. If you happen to use

Re: [qubes-users] Making a DispVM permanent

2019-09-23 Thread brendan . hoar
On Monday, September 23, 2019 at 11:57:22 AM UTC-4, steve.coleman wrote: > > On 2019-09-21 07:27, tetrahedra via qubes-users wrote: > > Is there a way to turn currently-running DispVM instance into a regular > > permanent AppVM, which I can delete later? > > I'm not sure it this helps or not,

[qubes-users] Bad/expired certs in qubes repo mirror dgplug.org

2019-09-23 Thread brendan . hoar
Report below: [MIRROR] qubes-template-fedora-30-minimal-4.0.1-201907160147.noarch.rpm: > Curl error (60): SSL peer certificate or SSH remote key was not OK for > https://mirrors.dgplug.org/qubes/repo/yum/r4.0/templates-itl/rpm/qubes-template-fedora-30-minimal-4.0.1-201907160147.noarch.rpm > >

Re: [qubes-users] Making a DispVM permanent

2019-09-22 Thread brendan . hoar
On Sunday, September 22, 2019 at 7:37:40 AM UTC-4, one7...@gmail.com wrote: > > Hello, > > *Von:* tetrahedra via qubes-users > *Betreff:* [qubes-users] Making a DispVM permanent > > Is there a way to turn currently-running DispVM instance into a regular > permanent AppVM, which I can delete

Re: [qubes-users] "Root File out of memory warning"?

2019-09-18 Thread brendan . hoar
On Tuesday, September 17, 2019 at 6:15:12 PM UTC-4, awokd wrote: > > On a side note, anyone know why "sudo fstrim -av" in dom0 now says 0 > bytes trimmed for root? I double-checked and have discard specified > everywhere it should be. Only thing I don't remember seeing before is > stripe=64 in

Re: [qubes-users] Re: whonix tor browser customization

2019-09-10 Thread Brendan Hoar
On Tue, Sep 10, 2019 at 2:40 PM 'awokd' via qubes-users < qubes-users@googlegroups.com> wrote: > brendan.h...@gmail.com: > > > Under whonix-15, the whonix developers have inserted a presetting > question > > on startup allowing you to choose what you want the default on startup > to > > be, and

Re: [qubes-users] Re: whonix tor browser customization

2019-09-10 Thread brendan . hoar
On Tuesday, September 10, 2019 at 2:13:46 PM UTC-4, tetra...@danwin1210.me wrote: > Did upstream (Tor) also change the NoScript settings to block all > javascript on all sites by default, even at the lowest Tor Browser > security level? > Not exactly. Upstream intended the security slider to

Re: [qubes-users] Reminder: Please help test new updates and provide feedback!

2019-09-10 Thread brendan . hoar
FYI, running Thinkpad W520 running R4 w/ current-testing & kernel-latest, updated to current-testing's bevy of updates this morning. Everything is smooth so far. Brendan -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this

Re: [qubes-users] Cant connect hard drive to appvms?

2019-09-07 Thread Brendan Hoar
On Sat, Sep 7, 2019 at 3:04 PM Stumpy wrote: > ... Does the template for the VM have the ntfs-3g package installed? B > -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send

Re: [qubes-users] Re: Cant connect hard drive to appvms?

2019-09-05 Thread brendan . hoar
On Thursday, September 5, 2019 at 4:33:31 AM UTC-4, awokd wrote: > b@gmail.com: > > > USB: I generally have not attached USB drives (utilizing the USB IP support > > via `qvm-usb` aka `qvm-device usb`) to VMs as I find it slow and sometimes > > buggy. > > I don't do that either, but using

[qubes-users] Re: Cant connect hard drive to appvms?

2019-09-04 Thread brendan . hoar
On Wednesday, September 4, 2019 at 8:12:41 PM UTC-4, Stumpy wrote: > > I have a hard drive that i cant seem to connect to any of the appvms yet > I can see and access it via dom0 (not good i know). > I can attach a usb flash drive to my appvms but not the hard drive? > > This is on my laptop

Re: [qubes-users] Moving Qubes+VMs to Larger SSD - How to Handle Storage Pools on Other Disks?

2019-09-01 Thread brendan . hoar
I would advise against wiping any disks until you are sure the full set of restores are complete and tested. I’ve learned the hard way to never put myself into a situation where I cannot revert to my original configuration. Brendan -- You received this message because you are subscribed to

Re: [qubes-users] qvm-create-windows-qube Automatically creates

2019-08-30 Thread Brendan Hoar
On Fri, Aug 30, 2019 at 2:14 AM 799 wrote: > Hello Brendan, > > Thanks for the improvement list. Some questions: > > schrieb am Do., 29. Aug. 2019, 15:27: > >> - Increasing the device-stub VM priority from 256 to 1000 during install >> utilizing xl sched-credit. This dramatically increases the

Re: [qubes-users] qvm-create-windows-qube Automatically creates

2019-08-29 Thread Brendan Hoar
Couple more: - As windows 7 does not support SCSI unmap, and C and E are on virtual SCSI devices: install sdelete by default and schedule sdelete.exe -z C:\ and sdelete -z E:\ ... largish zero writes are caught at the lvm later and unallocated from storage - plus passed on as discards to physical

Re: [qubes-users] qvm-create-windows-qube Automatically creates

2019-08-29 Thread brendan . hoar
Hi crazyqube, I've used this to generate 20-30 VMs. I've noticed some incomplete installs (50/50). There do seem to be come timing dependencies that sometimes cause failures. I'll be investigating these further next week. I have some thoughts on changes I'll work on, if you're not planning

Re: [qubes-users] Re: Device showing up in Qubes sys-usb terminal but not devices icon, and attach error in dom0

2019-08-29 Thread Brendan Hoar
On Thu, Aug 29, 2019 at 3:02 AM rec wins wrote: > > OTP won't , if the key does more than U2F you may need to get a > configuration application for the key and make sure it's U2F only > slot 1 , 2 etc > Yubikey OTP works through a keyboard-like HID, which are blacklisted by default

Re: [qubes-users] qvm-create-windows-qube Automatically creates

2019-08-24 Thread brendan . hoar
On Tuesday, August 20, 2019 at 6:54:02 PM UTC-4, 799 wrote: > > Hello, > On Tue, 20 Aug 2019 at 21:34, 'awokd' via qubes-users < > qubes...@googlegroups.com > wrote: > >> 'crazyqube' via qubes-users: >> > I just made my solution for fully automatically creating and installing >> new Windows qubes

Re: [qubes-users] KDE problems

2019-08-20 Thread brendan . hoar
On Tuesday, August 20, 2019 at 9:57:51 AM UTC-4, Chris Laprise wrote: > > On 8/20/19 8:58 AM, unman wrote: > > Otherwise seems fine to me, but I don't think I'm representative user. > > Custom mens, Activities, Kwin stuff works fine. > > > > Can any other KDE users chip in with problems that

Re: [qubes-users] Data recovery - data loss during cut and paste

2019-08-15 Thread brendan . hoar
On Monday, August 12, 2019 at 12:25:02 PM UTC-4, Chris Laprise wrote: > > On 8/12/19 10:50 AM, ger...@riseup.net wrote: > > Chris Laprise: > >> On 8/12/19 9:37 AM, ger...@riseup.net wrote: > >>> Is there a possibility, to recover data after moving it with cut and > >>> paste? > >>> > >>>

Re: [qubes-users] best and less expensive Lenovo think pad

2019-08-15 Thread brendan . hoar
On Thursday, August 15, 2019 at 8:24:58 AM UTC-4, unman wrote: > > On Wed, Aug 14, 2019 at 04:26:18PM -0700, brend...@gmail.com > wrote: > > 1. That first USB device, which does not state where it can be used is > > either: > > a) The USB 2.0 interface "available" via the expresscard

Re: [qubes-users] best and less expensive Lenovo think pad

2019-08-14 Thread brendan . hoar
On Wednesday, August 14, 2019 at 7:53:38 PM UTC-4, 799 wrote: > > Hello Brendan, > > schrieb am Do., 15. Aug. 2019, 01:26: > >> (...) >> >> 1. That first USB device, which does not state where it can be used is >> either: >> a) The USB 2.0 interface "available" via the expresscard interface (some

Re: [qubes-users] best and less expensive Lenovo think pad

2019-08-14 Thread brendan . hoar
On Tuesday, August 13, 2019 at 3:54:58 PM UTC-4, 799 wrote: > I have documented the Layout of the USB controllers here: > > https://github.com/one7two99/my-qubes/blob/master/docs/qubes-x230.md > > It shows which USB Controllers connects to which external USB Port and > which internal USB Devices

Re: [qubes-users] Disk usage warning

2019-08-13 Thread Brendan Hoar
On Tue, Aug 13, 2019 at 4:52 AM Franz <169...@gmail.com> wrote: > @brendan, @Chris Many thanks > > >> Also: dom0 VM usage as well as all combined domU VMs usage is allocated >> from the same shared thinpool pool00 in a default setup. >> > > Now I understand. Considering that Qubes-settings on

Re: [qubes-users] Disk usage warning

2019-08-12 Thread brendan . hoar
On Monday, August 12, 2019 at 7:41:47 PM UTC-4, Francesco wrote: > > @Chris > On Mon, Aug 12, 2019 at 1:22 PM Chris Laprise > wrote: > >> On 8/12/19 12:03 PM, Franz wrote: >> > On the upper right corner of the screen a black message alert: >> > >> > Disk usage warning! >> > You are running out

[qubes-users] M.2 to PCIe Adapter play nice with qubes?

2019-08-11 Thread brendan . hoar
M.2 NVME SSD devices are just PCIe devices with a special connector. If your main board supports PCIe 3.0 then the adapter should work just like it was an onboard M.2 slot, with one possible exception: depending on the BIOS, it might not be a bootable device. B -- You received this message

[qubes-users] Re: Qubes-OS compatible SSD SAMSUNG.

2019-08-01 Thread brendan . hoar
On Thursday, August 1, 2019 at 7:28:09 AM UTC-4, gerard ribas vicente wrote: > > The qubes-os operating system is compatible with the following SSD disk > models: > > SAMSUNG 860 EVO? > SAMSUNG860 QVO? > SAMSUNG860 PRO? > Generally all contemporary SSDs are compatible. I have used the 860 EVO

Re: [qubes-users] R4 system requirements; AMD compatibility?

2019-07-26 Thread brendan . hoar
On Friday, July 26, 2019 at 1:24:57 PM UTC-4, Claudia wrote: > Just to humor myself, I was going to try testing if I could hear sound > from Qubes after resume, but it seems audio isn't working at all. Which > is a whole 'nother problem. Aplay says "... unable to open slave; audio > open

Re: [qubes-users] Creating and running VMs on a RAM DISK?

2019-07-26 Thread Brendan Hoar
On Fri, Jul 26, 2019 at 11:31 AM unman wrote: > On Fri, Jul 26, 2019 at 05:57:02AM -0700, brendan wrote: > > Or, should I just utilize the straightforward approach of adding the > amount > > of RAM I wish to use as a RAM disk to the baseline dom0 RAM > configuration, > > and then set up the RAM

[qubes-users] Creating and running VMs on a RAM DISK?

2019-07-26 Thread brendan . hoar
Hi, Does XEN expose any sort of configuration-controlled feature or interface that would sets aside XEN-owned memory in a way that can be exposed as a block device within dom0, for use as a RAM disk? Or, should I just utilize the straightforward approach of adding the amount of RAM I wish to

Re: [qubes-users] R4 system requirements; AMD compatibility?

2019-07-26 Thread brendan . hoar
On Thursday, July 25, 2019 at 12:16:00 PM UTC-4, Chris Laprise wrote: > > On 7/25/19 11:04 AM, brend...@gmail.com wrote: > > I was able to install that particular test build on a Thinkpad X230 for > > testing: https://openqa.qubes-os.org/tests/3021 > > > > (note: click on assets tab for

[qubes-users] Re: is it possible to have two sys-net for one firewall vm?

2019-07-26 Thread brendan . hoar
Use xentop -f to show full names. Those are likely the stub domains used for device handling, etc. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

Re: [qubes-users] R4 system requirements; AMD compatibility?

2019-07-25 Thread Brendan Hoar
On Thu, Jul 25, 2019 at 12:15 PM Chris Laprise wrote: > If it doesn't work, then the problem is probably entirely in dom0 and > Fedora 25. Assuming you already have the testing 4.19 kernel, have you > thought of upgrading it to the even newer 5.x one as 'latest'? The > latest kernel is installed

Re: [qubes-users] R4 system requirements; AMD compatibility?

2019-07-25 Thread brendan . hoar
On Thursday, July 25, 2019 at 10:18:29 AM UTC-4, awokd wrote: > > > Are there any other Xen-based distros out there I could test? > > You can add Xen to your stock Fedora install. That takes it roughly to > where Qubes begins, but you might want to use the same version of Fedora > dom0 uses. >

Re: [qubes-users] Using Salt to update TemplateVMs

2019-07-16 Thread brendan . hoar
On Tuesday, July 16, 2019 at 10:35:11 AM UTC-4, unman wrote: > I really do recommend using qubesctl for almost all system > configuration. If only because it makes recovery so much easier. > I see people saying "keep a list of packages you've installed" - if you > keep state and use salt you can

Re: [qubes-users] qvm-ls --fields name,madmen,memory

2019-07-14 Thread brendan . hoar
On Sunday, July 14, 2019 at 8:04:27 AM UTC-4, unman wrote: > On Sun, Jul 14, 2019 at 04:34:04AM -0700, bxx...@gmail.com wrote: > > When I run the above command, the memory column is always set to ???-??? in > > the output. Am I using the wrong field name? > No, right name but doesnt output.

[qubes-users] qvm-ls --fields name,madmen,memory

2019-07-14 Thread brendan . hoar
Madmen=maxmem, thank you autocorrect. :/ -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send

[qubes-users] qvm-ls --fields name,madmen,memory

2019-07-14 Thread brendan . hoar
When I run the above command, the memory column is always set to “-“ in the output. Am I using the wrong field name? B -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an

Re: [qubes-users] VPN before sys-firewall ?

2019-07-10 Thread brendan . hoar
I’m currently using: VMs -> sys-mirage-fw-int -> sys-vpn-tasket-> sys-mirage-fw-ext -> sys-net Benefit of mirage in this situation is that each one consumes only 32MB of RAM. B -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe

[qubes-users] Re: whonix workstation 15 browser dropped both noscript and https

2019-07-09 Thread brendan . hoar
I believe this is an upstream torbrowser decision. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this

Re: [qubes-users] Re: What is the path to the usb drive in sys-usb?

2019-07-09 Thread brendan . hoar
On my machine I have a sys-usb for only the usb 2.0 controller and a separately set up sys-usb-3 for the usb 3.0 controller. I found the I/O performance of using qvm-usb ok for moving small amounts of data on and off the system. For heavier I/O, I ensure the sys-usb-3 VM is shut down and

[qubes-users] Re: What is the path to the usb drive in sys-usb?

2019-07-08 Thread brendan . hoar
On Monday, July 8, 2019 at 3:55:08 PM UTC-4, brend...@gmail.com wrote: > On Monday, July 8, 2019 at 11:14:41 AM UTC-4, oak...@gmail.com wrote: > > Easy question, but I'm a noob: What is the path to the usb drive that is > > connecting through sys-usb? I am trying to get the usb to startup with

[qubes-users] Re: What is the path to the usb drive in sys-usb?

2019-07-08 Thread brendan . hoar
On Monday, July 8, 2019 at 11:14:41 AM UTC-4, oak...@gmail.com wrote: > Easy question, but I'm a noob: What is the path to the usb drive that is > connecting through sys-usb? I am trying to get the usb to startup with a > certain vm. Thanks. Since the VMs use /dev/xvd[a-d] as the operational

Re: [qubes-users] sys-net fails to load ath10k_pci after fedora-29 update

2019-06-23 Thread Brendan Hoar
I think it was the kernel-latest-qubes-vm package from the -testing repo. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to

Re: [qubes-users] Security concern while checking FLR (Function Level Reset) for PCI passthrough to Xen HVM guest

2019-06-22 Thread brendan . hoar
On Saturday, June 22, 2019 at 3:07:25 AM UTC-4, awokd wrote: > 'npdflr' via qubes-users: > > while the section: Preparing a device for passthrough > > (https://wiki.xenproject.org/wiki/Xen_PCI_Passthrough#Preparing_a_device_for_passthrough) > > states that: > > "First, determine the BDF of the

  1   2   3   >