[qubes-users] Re: qubes wallpaper

2017-03-04 Thread Grzesiek Chodzicki
W dniu sobota, 4 marca 2017 16:15:22 UTC+1 użytkownik haaber napisał:
> Hello,
> 
> I understand that importing a custom wallpaper may open a security
> breach for exploits against the image decoder inside dom0. On the other
> hand side, people (me inclusive) like to customize a little bit their
> system.
> 
> Nothing would be more natural as to 'sanitize' pictures that should go
> to dom0. Since qubes trusts rgb format (at least to secure pdf's), this
> seems a natural starting point. Helas!  xfce wallpaper management cannot
> read rgb files ...
> 
> Did someone already think about a possible solution? Bernhard

You know you could just view the picture in fullscreen and then take a 
screenshot of it right?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/4a37017f-c8d9-4f09-9f94-c335bb10ed12%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Re: qubes wallpaper

2017-03-04 Thread Unman
On Sat, Mar 04, 2017 at 07:37:49AM -0800, loke...@gmail.com wrote:
> On Saturday, 4 March 2017 23:15:22 UTC+8, haaber  wrote:
> 
> > Nothing would be more natural as to 'sanitize' pictures that should go
> > to dom0. Since qubes trusts rgb format (at least to secure pdf's), this
> > seems a natural starting point. Helas!  xfce wallpaper management cannot
> > read rgb files ...
> 
> You can always convert the image from its original source into PNM (or some 
> equally simple format) and then convert it to something that Xfce can read 
> (like PNG).
> 
> If you want to be as safe as possible, you should do the initial conversion 
> in a dispvm, and then use a different VM to convert to PNG. This is because 
> you should assume that the dispvm has been compromised after the conversion.
> 

Have you looked at the qvm-convert-img tool? I think it is what you're
looking for.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/20170304161452.GA9328%40thirdeyesecurity.org.
For more options, visit https://groups.google.com/d/optout.