Re: [qubes-users] Recommended laptop?

2020-01-01 Thread Claudia
December 31, 2019 1:02 PM, "eira wahlin"  wrote:

> I use qubes on an AMD system (thinkpad with Ryzen 5 pro 2500u). While I'm 
> happy with it, I've had
> to make some sacrifices. AMD systems are tricky with hardware forwarding, so 
> I cannot (at the
> moment) use a sys-USB. There is an inherent security problem there.
> 
> Also, I've had to make my own versions of the (horribly elitistic and 
> class-hatingly named) AEM
> system. I use my machine's TPM2 to verify that my BIOS hasn't been infected, 
> but that was difficult
> as hell to set up. AEM relies on Intel's TPM module, and doesn't work with 
> AMD machines.
> 
> So while most of it all works, it's been tricky to set up, and it's not all 
> functional yet.
> 
> <3
> /panina

Hi again, processor buddy. I have the Ryzen 5 (non-Pro) 2500U. I've also had a 
lot of problems with it. The IOMMU grouping is terrible, the kernel has a lot 
of problems with the firmware and ACPI, it doesn't support USB Qube, and so on. 
I haven't dared to even try AEM on this machine. But considering the 
performance for the money, I guess I really can't complain.

I recently got suspend/resume half working. Turns out, some or all of the 
Fam15h processors including the 2500U change their cpuid feature bits when 
resuming from suspend, which causes a Xen panic. This means the fans come back 
on, but the screen doesn't power back on and it can't save any logs, so it's 
really hard to diagnose. You can patch Xen to disable the feature check.

If you don't mind patching Xen, it's very likely that this will fix it for you 
(although you may run into other post-resume problems). And it's really not as 
difficult as it sounds.

This link contains a patch and instructions for building it.
https://www.mail-archive.com/qubes-users@googlegroups.com/msg31697.html

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/7cb86fb029b7e582b13e5cf32013d7c4%40disroot.org.


Re: [qubes-users] Recommended laptop?

2019-12-31 Thread eira wahlin
I use qubes on an AMD system (thinkpad with Ryzen 5 pro 2500u). While I'm happy 
with it, I've had to make some sacrifices. AMD systems are tricky with hardware 
forwarding, so I cannot (at the moment) use a sys-USB. There is an inherent 
security problem there.

Also, I've had to make my own versions of the (horribly elitistic and 
class-hatingly named) AEM system. I use my machine's TPM2 to verify that my 
BIOS hasn't been infected, but that was difficult as hell to set up. AEM relies 
on Intel's TPM module, and doesn't work with AMD machines.

So while most of it all works, it's been tricky to set up, and it's not all 
functional yet.

<3
/panina

On 24 December 2019 13:54:50 CET, Claudia  wrote:
>December 24, 2019 12:51 PM, taschent...@posteo.de wrote:
>
>> On Tue, 2019-12-24 at 12:48 +, Claudia wrote:
>> 
>>> Personally I would try to avoid AMD systems,
>> 
>> why that?
>> 
>> --
>> You received this message because you are subscribed to the Google
>Groups "qubes-users" group.
>> To unsubscribe from this group and stop receiving emails from it,
>send an email to
>> qubes-users+unsubscr...@googlegroups.com.
>> To view this discussion on the web visit
>>
>https://groups.google.com/d/msgid/qubes-users/8137b39c393fd7d7192a72a8620706ae13f4150b.camel@posteo.
>> e.
>
>
>https://www.mail-archive.com/qubes-users@googlegroups.com/msg31520.html
>
>Not scientific evidence or anything, just my personal
>opinion/experience.
>
>-- 
>You received this message because you are subscribed to the Google
>Groups "qubes-users" group.
>To unsubscribe from this group and stop receiving emails from it, send
>an email to qubes-users+unsubscr...@googlegroups.com.
>To view this discussion on the web visit
>https://groups.google.com/d/msgid/qubes-users/dbb007537f3a3cae3b2356ea6df374b2%40disroot.org.

-- 
Sent from my Android device with K-9 Mail. Please excuse my brevity.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/958DAD3F-58A4-45E7-BE25-85E598A08534%40nonbinary.me.


Re: [qubes-users] Recommended laptop?

2019-12-24 Thread Claudia
December 24, 2019 12:51 PM, taschent...@posteo.de wrote:

> On Tue, 2019-12-24 at 12:48 +, Claudia wrote:
> 
>> Personally I would try to avoid AMD systems,
> 
> why that?
> 
> --
> You received this message because you are subscribed to the Google Groups 
> "qubes-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to
> qubes-users+unsubscr...@googlegroups.com.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/qubes-users/8137b39c393fd7d7192a72a8620706ae13f4150b.camel@posteo.
> e.


https://www.mail-archive.com/qubes-users@googlegroups.com/msg31520.html

Not scientific evidence or anything, just my personal opinion/experience.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/dbb007537f3a3cae3b2356ea6df374b2%40disroot.org.


Re: [qubes-users] Recommended laptop?

2019-12-24 Thread taschentuch
On Tue, 2019-12-24 at 12:48 +, Claudia wrote:
> Personally I would try to avoid AMD systems, 
why that?


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/8137b39c393fd7d7192a72a8620706ae13f4150b.camel%40posteo.de.


Re: [qubes-users] Recommended laptop?

2019-12-24 Thread Claudia
December 24, 2019 9:43 AM, "Ondřej Šulák"  wrote:

> Hello pals,
> 
> for the last release of Qubes, what laptop would you recommend? Is there any 
> cheaper option which
> does have HW compatibility with latest Qubes (ideally with shipping from EU), 
> than this one:
> 
> https://insurgo.ca/produit/qubesos-certified-privacybeast_x230-reasonably-secured-laptop
>  ?
> Thanks for any tips!
> 

There are two tested, but not certified, models: Thinkpad X1 Carbon gen 5, and 
Thinkpad x230. https://www.qubes-os.org/doc/hardware-testing/

In general Thinkpads are usually pretty safe. Personally I would try to avoid 
AMD systems, as well as consumer models. Look for business class or mid-range 
hardware where possible, as they tend to have more solid firmware. Look for 
Intel 4th gen (I think) and newer, as prior generations did not have integrated 
chipsets. Avoid buying the latest models. Qubes is based on older versions of 
Fedora and LTS kernels, so look for hardware that has been on the market for at 
least a little while. Look for models that advertise Linux compatibility or 
ship with Ubuntu preinstalled, and prefer vendors that tend to have good Linux 
support, such as Lenovo, Dell, and HP. 

Other than that, check the HCL, and google around and see what other users have 
reported. Also search the mailing list for HCL reports, as it takes a long time 
for them to show up on the website.

Above all, make sure you can return it for a refund in case it doesn't run 
Qubes!

Now, all that being said, I recently took a chance on a very cheap 
consumer-grade Dell Inspiron with AMD, and I have to say I had pretty good 
luck, all things considered. USB Qube is not supported, and I still haven't 
gotten suspend/resume to work, but everything else works, and it was a steal 
for the price. 

So even going against all recommendations you can still get lucky, it just 
depends how much risk you're comfortable with and how much trial-and-error you 
have time for. However, even following all the best practices won't guarantee 
success on the first try: case in point there are Thinkpads on the HCL with 
more problems than my cheap Inspiron.

Good luck!

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/dccf3314376502a699a313ce2fcca986%40disroot.org.


[qubes-users] Recommended laptop?

2019-12-24 Thread Ondřej Šulák
Hello pals,
for the last release of Qubes, what laptop would you recommend? Is there 
any cheaper option which does have HW compatibility with latest Qubes 
(ideally with shipping from EU), than this one:
https://insurgo.ca/produit/qubesos-certified-privacybeast_x230-reasonably-secured-laptop/
 
?

Thanks for any tips!

Ondrej

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5365a450-2aeb-49c0-9015-cb6657e063b1%40googlegroups.com.


Re: [qubes-users] Recommended laptop

2018-03-07 Thread taii...@gmx.com

On 03/07/2018 03:03 PM, '我' via qubes-users wrote:


I decided to buy Lenovo G505s.
Thank you very much.

The hardware selection tree has become a big help I've decided.

Ah you have made a good choice, I hope you have gotten the one with the 
A10 and the dedicated graphics as it is much faster.
It is the freest best relatively modern laptop out there, the novena is 
freer but it has no IOMMU.


In terms of freedom hardware with desktops/workstations/servers you have 
real options, let me know if you want to get one and I will help you :D


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/e37de087-767f-03ff-5c07-83e6868fad45%40gmx.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Recommended laptop

2018-03-07 Thread '我' via qubes-users
I decided to buy Lenovo G505s.
Thank you very much.

The hardware selection tree has become a big help I've decided.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/7ROFAgePwqfCsWnQm7uD2zNNDQFFpXCPQ4fcJP-0wk22iFUfs_K19DEGI3nuk_eBAJ4tiH36KgNTR3WxaaPgbUYDlyGGyTri1dy6515oEME%3D%40protonmail.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Recommended laptop

2018-03-07 Thread Yuraeitha
On Wednesday, March 7, 2018 at 1:31:11 PM UTC+1, awokd wrote:
> On Wed, March 7, 2018 7:46 am, awokd wrote:
> 
> > There's https://www.qubes-os.org/doc/#choosing-your-hardware in the docs
> > and FAQ links to same but maybe some type of decision tree?
> 
> Here's my first attempt at one. Links don't work in its current location,
> but it should be easy to follow. I'm not entirely sure this belongs on
> Qubes' site so I threw in a disclaimer.
> 
> https://github.com/awokd/qubes-doc/blob/hardwaretree/hardware/hardware-tree.md

That is pretty awesome project awokd! It'd be amazing if you can finish and 
polish it, it's definitely very useful work.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/a54f5695-49eb-4543-97c0-f3b20c929e57%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Recommended laptop

2018-03-07 Thread 'awokd' via qubes-users
On Wed, March 7, 2018 7:46 am, awokd wrote:

> There's https://www.qubes-os.org/doc/#choosing-your-hardware in the docs
> and FAQ links to same but maybe some type of decision tree?

Here's my first attempt at one. Links don't work in its current location,
but it should be easy to follow. I'm not entirely sure this belongs on
Qubes' site so I threw in a disclaimer.

https://github.com/awokd/qubes-doc/blob/hardwaretree/hardware/hardware-tree.md


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/455b28b4f92e2914b3ab9e93b0963c65.squirrel%40tt3j2x4k5ycaa5zt.onion.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Recommended laptop

2018-03-06 Thread 'awokd' via qubes-users
On Wed, March 7, 2018 7:30 am, 799 wrote:
> Am 07.03.2018 8:21 vorm. schrieb "'awokd' via qubes-users" <
> qubes-users@googlegroups.com>:

>
> If using Coreboot instead of Libreboot aren't their better options than
> the G505s which seems to be a consumer device.

Libreboot is different than Coreboot because it insists on no Intel ME/AMD
PSP and no blobs. A corebooted G505s is the only R4.0 capable laptop I've
been able to find that still contains no form of ME/PSP, although it does
need a couple blobs. The chiclet keyboard and glossy screen are pretty
unpleasant, though.

> As the question "what should I buy?" seems to be common, is this in the
> FAQ? Maybe also with some more details regarding Stock ROM vs. Coreboot vs
>  Coreboot + ME_cleaner vs. Libreboot?

There's https://www.qubes-os.org/doc/#choosing-your-hardware in the docs
and FAQ links to same but maybe some type of decision tree?

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/3a2a2fead515d79e150a8bc03faa7a7a.squirrel%40tt3j2x4k5ycaa5zt.onion.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Recommended laptop

2018-03-06 Thread 799
Am 07.03.2018 8:21 vorm. schrieb "'awokd' via qubes-users" <
qubes-users@googlegroups.com>:


> If you aren't concerned about owner control, check
> https://www.qubes-os.org/hcl/ for other laptops reported to work with 4.0.

Should add that if you go with a G505s, please be prepared to flash it
with Coreboot yourself. It will need an external SPI programmer.


If using Coreboot instead of Libreboot aren't their better options than the
G505s which seems to be a consumer device.

As the question "what should I buy?" seems to be common, is this in the
FAQ? Maybe also with some more details regarding Stock ROM vs. Coreboot vs
Coreboot + ME_cleaner vs. Libreboot?

[799]

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAJ3yz2vx7WC3jxM2zbC6-0nQgEO_co8dx3343JF3zKpYAHZuEg%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Recommended laptop

2018-03-06 Thread 'awokd' via qubes-users
On Wed, March 7, 2018 7:11 am, awokd wrote:
> On Wed, March 7, 2018 6:27 am, '我' via qubes-users wrote:
>
>> Hello.
>>
>>
>>
>> I installed Qubes3.2 on my MacBook 2009 late. But I could not use WiFi.
>>  So I want to buy a new laptop for qubes4. What laptop is recommended?
>>
>>
>>
>> How about libreboot T400?
>> https://minifree.org/product/libreboot-t400/
>>
>
> Libreboots are nice but Qubes 4.0 can't run on them. It needs newer CPU
> features:
> https://www.qubes-os.org/doc/system-requirements/#qubes-release-4x. The
> only laptop that comes close to the Libreboot level of owner control and
> still has the capability to run Qubes 4.0 is a Lenovo G505s. There are
> other A10-5750M laptops out there but they haven't been tested with
> Qubes.
>
>
> If you aren't concerned about owner control, check
> https://www.qubes-os.org/hcl/ for other laptops reported to work with 4.0.

Should add that if you go with a G505s, please be prepared to flash it
with Coreboot yourself. It will need an external SPI programmer.


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/b9242154a37fb7ba0885532644ac996e.squirrel%40tt3j2x4k5ycaa5zt.onion.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Recommended laptop

2018-03-06 Thread 'awokd' via qubes-users
On Wed, March 7, 2018 6:27 am, '我' via qubes-users wrote:
> Hello.
>
>
> I installed Qubes3.2 on my MacBook 2009 late. But I could not use WiFi.
> So I want to buy a new laptop for qubes4. What laptop is recommended?
>
>
> How about libreboot T400?
> https://minifree.org/product/libreboot-t400/

Libreboots are nice but Qubes 4.0 can't run on them. It needs newer CPU
features:
https://www.qubes-os.org/doc/system-requirements/#qubes-release-4x. The
only laptop that comes close to the Libreboot level of owner control and
still has the capability to run Qubes 4.0 is a Lenovo G505s. There are
other A10-5750M laptops out there but they haven't been tested with Qubes.

If you aren't concerned about owner control, check
https://www.qubes-os.org/hcl/ for other laptops reported to work with 4.0.




-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/eca7ee5bc26b743bc4841db47ff1c48a.squirrel%40tt3j2x4k5ycaa5zt.onion.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Recommended laptop

2018-03-06 Thread 799
Hello,


Am 07.03.2018 7:28 vorm. schrieb "'我' via qubes-users" <
qubes-users@googlegroups.com>:

Hello.

I installed Qubes3.2 on my MacBook 2009 late. But I could not use WiFi.
So I want to buy a new laptop for qubes4. What laptop is recommended?

How about libreboot T400?
https://minifree.org/product/libreboot-t400/


My suggestion would be get a Thinkpad, which is on both "compatibility
lists" (HCL - Hardware Compatibility List)

1) Coreboot HCL
https://www.coreboot.org/Supported_Motherboards

2) Qubes OS
https://www.qubes-os.org/hcl/

As you haven't provided any information what you want to do on your Laptop
and which form factor and battery runtime is right for you, nobody can give
an advice.
What are your requirements?

As always in live it's about finding the right trade-off.

I have two Laptops, one 12" with Core i5 and 16GB RAM, working WWAN and a
very long battery runtime and a 15" with Core i7 / 32 GB RAM and a
3K-Display.
Using the 12" much more and haven't run into any performance issues.
Only recommendation: if possible grab 16 GB RAM, feels right.

[799]

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/CAJ3yz2vXQLCV-Hj82%3DKskTQ14QNGK3OinU%2BcbXpv_6b93WTGiQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.


[qubes-users] Recommended laptop

2018-03-06 Thread '我' via qubes-users
Hello.

I installed Qubes3.2 on my MacBook 2009 late. But I could not use WiFi.
So I want to buy a new laptop for qubes4. What laptop is recommended?

How about libreboot T400?
https://minifree.org/product/libreboot-t400/

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/vsdsXaDLVvPcY8fFeehie2jhAx-44KqKgYv3rzKp2aXVYtnF5O-XdvkgB9DYIvmgW1nQvLhVOZQvNZFfrrOie_v9eS5TvSBSY4VPoZ_YcmY%3D%40protonmail.com.
For more options, visit https://groups.google.com/d/optout.