Re: [qubes-users] How to get trusted iso?

2017-05-01 Thread Chris Laprise
On 05/01/2017 03:43 PM, cooloutac wrote: Does Qubes ever plan on selling iso sticks? I would like to know. And I've suggested this in the past, but with DVD-Rs which I think are preferable to USB sticks (even the ones with hardware write-protect switches). -- Chris Laprise,

Re: [qubes-users] Intel ME exploitable

2017-05-01 Thread Ilpo Järvinen
On Mon, 1 May 2017, 'Lolint' via qubes-users wrote: > Confirmation by Shintel: > https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Gu > ide%20-%20Rev%201.1.pdf So it requires either network connection to an ME aware NIC or, unsuprisingly, access to some local HW interface

Re: [qubes-users] Re: Opening links in your preferred AppVM

2017-05-01 Thread Ángel
On 2017-05-01 at 18:32 -0700, Gaiko wrote: > On Monday, May 1, 2017 at 6:40:40 PM UTC-4, Ángel wrote: > > On 2017-05-01 at 12:34 -0700, Gaiko wrote: > > > Thoughts? > > > > Does your desktop file validate? > > ie. run: desktop-file-validate open_work_vm.desktop > > > > If the desktop file is

Re: [qubes-users] Re: Opening links in your preferred AppVM

2017-05-01 Thread Gaiko
On Monday, May 1, 2017 at 4:37:37 PM UTC-4, u+q...@bestemt.no wrote: > Gaiko [2017-05-01 21:34 +0200]: > > On Wednesday, June 22, 2016 at 2:38:22 PM UTC-4, Micah Lee wrote: > > > I published a quick blog post explaining how I do this: > > > > > >

Re: [qubes-users] Not using firewall rules correctly?

2017-05-01 Thread Gaiko Kyofusho
On Mon, May 1, 2017 at 10:47 PM, Gaiko Kyofusho < gaikokujinkyofu...@gmail.com> wrote: > > > On Sat, Apr 29, 2017 at 6:45 PM, Unman wrote: > >> On Sat, Apr 29, 2017 at 06:13:46PM -0400, Gaiko Kyofusho wrote: >> > Thanks, I looked up about host files, and found the >> >

[qubes-users] Re: Overheat warning

2017-05-01 Thread Grzesiek Chodzicki
W dniu niedziela, 30 kwietnia 2017 20:16:56 UTC+2 użytkownik - napisał: > I have a very serious overheating problem with my Thinkpad X201t, and I'm > wondering if there's a better way of handling it in Qubes. At the moment, the > computer just suddenly starts to shut down without warning. (I can

[qubes-users] dom0 "refused to give back memory" with the yellow triangle error, Must I reboot it ?

2017-05-01 Thread Myna
I have like 10 AppVMs open I'd rather not close them all and reopen, since qvm-close -all always hangs so, does it really matter ? because it's dom0 vs. other VMs ? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group

[qubes-users] awesome wm: Focus steal hardened rc.lua

2017-05-01 Thread David Hobach
Dear users, I was annoyed by some unwanted focus changes whilst using awesome and thus created the attached config that should prevent most of them. Maybe it'll be useful to some of you (I noticed some threads on this mailing list about focus steal stuff after all). The code should be

Re: [qubes-users] Re: One of many questions: 2 displays ? how

2017-05-01 Thread Alex
On 04/30/2017 12:20 AM, foo4 wrote: > Alex, I have two computers, On both what happens is it mirrors the > primary display, but I'm wanting to expand/extend the display not > clone it :) > > They are both onboard Intel CPU graphics, I'd have to look up what > comes with skylake and kabylake. > >

[qubes-users] Checking laptop compatibility using boot from USB drive

2017-05-01 Thread Vít Šesták
I'll probably have an opportunity to verify some laptop's compatibility. My idea is to boot Qubes OS or its installer from USB and then to do some checks (most notably VT-d compatibility and USB controller topology). It should be something done in reasonable time and without installing QubesOS

[qubes-users] Re: Intel ME exploitable

2017-05-01 Thread Reg Tiangha
On 05/01/2017 12:04 PM, cooloutac wrote: > On Monday, May 1, 2017 at 1:26:52 PM UTC-4, Vít Šesták wrote: >> AFAIU, if https://ark.intel.com/ shows “Intel® vPro™ Technology: no”, then >> the particular CPU is safe. But I am not 100% confident in vPro and related >> technologies, so I might be

[qubes-users] Re: Changed resolution, now screen doesn't work?

2017-05-01 Thread almir . aljic1998
On Monday, May 1, 2017 at 6:51:51 PM UTC+2, almir.a...@gmail.com wrote: > I changed the resolution of my Qubes from 1920x1080 to 1600x1200 (by > accident) and now my screen doesn't show anything when I choose HDMI2 (my > desktop PC is attached to the screen with an HDMI cable). Setting the >

Re: [qubes-users] Intel ME exploitable

2017-05-01 Thread Chris Laprise
On 05/01/2017 12:38 PM, Jean-Philippe Ouellet wrote: I want my RISC-V laptop already! I would agree, but these things are still quite slow... correct? I think they are lacking in out-of-order execution and SIMD, for example. A good benchmark for performance might be something like the last

[qubes-users] Re: Changed resolution, now screen doesn't work?

2017-05-01 Thread almir . aljic1998
On Monday, May 1, 2017 at 6:51:51 PM UTC+2, almir.a...@gmail.com wrote: > I changed the resolution of my Qubes from 1920x1080 to 1600x1200 (by > accident) and now my screen doesn't show anything when I choose HDMI2 (my > desktop PC is attached to the screen with an HDMI cable). Setting the >

[qubes-users] Re: Intel ME exploitable

2017-05-01 Thread cooloutac
On Monday, May 1, 2017 at 1:26:52 PM UTC-4, Vít Šesták wrote: > AFAIU, if https://ark.intel.com/ shows “Intel® vPro™ Technology: no”, then > the particular CPU is safe. But I am not 100% confident in vPro and related > technologies, so I might be wrong. Can someone confirm/deny this claim? > >

Re: [qubes-users] say it out (loud) - Qubes OS Stickers

2017-05-01 Thread Darren Fix
On Monday, May 1, 2017 at 12:37:56 PM UTC-6, cooloutac wrote: > On Friday, April 28, 2017 at 9:59:03 PM UTC-4, Darren Fix wrote: > > On Tuesday, April 25, 2017 at 9:09:06 AM UTC-6, cooloutac wrote: > > > On Monday, April 24, 2017 at 3:32:57 AM UTC-4, lok...@gmail.com wrote: > > > > On Saturday, 22

Re: [qubes-users] How to get trusted iso?

2017-05-01 Thread Chris Laprise
On 05/01/2017 02:33 PM, cooloutac wrote: I know I can't buy one, so how do I get an a fresh iso if my machine is compromised? Obviously, someone more prudent would of kept their original iso on dedicated usb stick. But I was too cheap. I'll go out on a limb and say that Qubes is more about

[qubes-users] Re: Intel ME exploitable

2017-05-01 Thread Reg Tiangha
On 05/01/2017 10:38 AM, Jean-Philippe Ouellet wrote: > *Sigh*... Yep. We were right to be concerned (of course). And now we > have something other than our tin foil hats to point at too: > > https://semiaccurate.com/2017/05/01/remote-security-exploit-2008-intel-platforms/ > > I want my RISC-V

[qubes-users] Re: Problem installing qubes

2017-05-01 Thread cube1701 via qubes-users
I'm having the same problem. My machine is hanging onto the network setup. I disabled the card in bios but no success. Can anyone help? Thx -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving

[qubes-users] Re: Changed resolution, now screen doesn't work?

2017-05-01 Thread cooloutac
On Monday, May 1, 2017 at 2:19:29 PM UTC-4, almir.a...@gmail.com wrote: > On Monday, May 1, 2017 at 6:51:51 PM UTC+2, almir.a...@gmail.com wrote: > > I changed the resolution of my Qubes from 1920x1080 to 1600x1200 (by > > accident) and now my screen doesn't show anything when I choose HDMI2 (my

[qubes-users] Re: Intel ME exploitable

2017-05-01 Thread Reg Tiangha
On 05/01/2017 11:14 AM, Reg Tiangha wrote: > On 05/01/2017 10:38 AM, Jean-Philippe Ouellet wrote: >> *Sigh*... Yep. We were right to be concerned (of course). And now we >> have something other than our tin foil hats to point at too: >> >>

[qubes-users] Re: Intel ME exploitable

2017-05-01 Thread Vít Šesták
AFAIU, if https://ark.intel.com/ shows “Intel® vPro™ Technology: no”, then the particular CPU is safe. But I am not 100% confident in vPro and related technologies, so I might be wrong. Can someone confirm/deny this claim? Regards, Vít Šesták 'v6ak' -- You received this message because you

[qubes-users] Re: Overheat warning

2017-05-01 Thread cooloutac
On Sunday, April 30, 2017 at 2:16:56 PM UTC-4, - wrote: > I have a very serious overheating problem with my Thinkpad X201t, and I'm > wondering if there's a better way of handling it in Qubes. At the moment, the > computer just suddenly starts to shut down without warning. (I can reliably > get

[qubes-users] Re: Intel ME exploitable

2017-05-01 Thread Reg Tiangha
On 05/01/2017 12:19 PM, Reg Tiangha wrote: > On 05/01/2017 12:04 PM, cooloutac wrote: >> On Monday, May 1, 2017 at 1:26:52 PM UTC-4, Vít Šesták wrote: >>> AFAIU, if https://ark.intel.com/ shows “Intel® vPro™ Technology: no”, then >>> the particular CPU is safe. But I am not 100% confident in vPro

[qubes-users] Re: Changed resolution, now screen doesn't work?

2017-05-01 Thread cooloutac
On Monday, May 1, 2017 at 1:42:34 PM UTC-4, almir.a...@gmail.com wrote: > On Monday, May 1, 2017 at 6:51:51 PM UTC+2, almir.a...@gmail.com wrote: > > I changed the resolution of my Qubes from 1920x1080 to 1600x1200 (by > > accident) and now my screen doesn't show anything when I choose HDMI2 (my

[qubes-users] How to get trusted iso?

2017-05-01 Thread cooloutac
I know I can't buy one, so how do I get an a fresh iso if my machine is compromised? Obviously, someone more prudent would of kept their original iso on dedicated usb stick. But I was too cheap. So what happens if that was not done, or how can someone get a trusted iso for the first time in

Re: [qubes-users] say it out (loud) - Qubes OS Stickers

2017-05-01 Thread cooloutac
On Friday, April 28, 2017 at 9:59:03 PM UTC-4, Darren Fix wrote: > On Tuesday, April 25, 2017 at 9:09:06 AM UTC-6, cooloutac wrote: > > On Monday, April 24, 2017 at 3:32:57 AM UTC-4, lok...@gmail.com wrote: > > > On Saturday, 22 April 2017 07:46:28 UTC+8, Dominique St-Pierre Boucher > > > wrote:

[qubes-users] Changed resolution, now screen doesn't work?

2017-05-01 Thread almir . aljic1998
I changed the resolution of my Qubes from 1920x1080 to 1600x1200 (by accident) and now my screen doesn't show anything when I choose HDMI2 (my desktop PC is attached to the screen with an HDMI cable). Setting the resolution to 1280x1024 worked fine, but as soon as I set it to 1600x1200 and

[qubes-users] Re: Overheat warning

2017-05-01 Thread -
-- Original Message Subject: Re: Overheat warning Local Time: May 1, 2017 5:47 AM UTC Time: May 1, 2017 9:47 AM From: grzegorz.chodzi...@gmail.com To: qubes-users lo...@lorentrogers.com W dniu niedziela, 30 kwietnia 2017 20:16:56 UTC+2 użytkownik -

Re: [qubes-users] Auto update download in Linux

2017-05-01 Thread Rusty Bird
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Drew White: > On Wednesday, 26 April 2017 11:05:43 UTC+10, Rusty Bird wrote: > > Rusty Bird: > > > Drew White: > > > > On Tuesday, 25 April 2017 07:51:46 UTC+10, Unman wrote: > > > > > I think the only way to get a caching proxy is to install your

Re: [qubes-users] How to get trusted iso?

2017-05-01 Thread cooloutac
On Monday, May 1, 2017 at 3:03:05 PM UTC-4, Chris Laprise wrote: > On 05/01/2017 02:33 PM, cooloutac wrote: > > I know I can't buy one, so how do I get an a fresh iso if my machine > > is compromised? Obviously, someone more prudent would of kept their > > original iso on dedicated usb stick.

Re: [qubes-users] How does qvm-open-in-(d)vm determine which application to open a file in?

2017-05-01 Thread u+qbsu
Unman [2017-04-25 20:48 +0200]: > I'm not convinced becase my stretch works as expected without gvfs-bin, > but it is built not upgraded. gvfs-bin brings in gvfs-common, so it may > be that that's what iss required and isnt in a Jesie-upgarded system. It also works in

Re: [qubes-users] Re: Opening links in your preferred AppVM

2017-05-01 Thread u+qbsu
Gaiko [2017-05-01 21:34 +0200]: > On Wednesday, June 22, 2016 at 2:38:22 PM UTC-4, Micah Lee wrote: > > I published a quick blog post explaining how I do this: > > > > https://micahflee.com/2016/06/qubes-tip-opening-links-in-your-preferred-appvm/ > > This would be

Re: [qubes-users] Intel ME exploitable

2017-05-01 Thread 'Lolint' via qubes-users
Confirmation by Shintel: https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide%20-%20Rev%201.1.pdfhttps://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide%20-%20Rev%201.1.pdf -- You received this message because you are subscribed to the Google

Re: [qubes-users] say it out (loud) - Qubes OS Stickers

2017-05-01 Thread cooloutac
On Monday, May 1, 2017 at 2:44:08 PM UTC-4, Darren Fix wrote: > On Monday, May 1, 2017 at 12:37:56 PM UTC-6, cooloutac wrote: > > On Friday, April 28, 2017 at 9:59:03 PM UTC-4, Darren Fix wrote: > > > On Tuesday, April 25, 2017 at 9:09:06 AM UTC-6, cooloutac wrote: > > > > On Monday, April 24,

[qubes-users] Re: Intel ME exploitable

2017-05-01 Thread Reg Tiangha
On 05/01/2017 02:48 PM, 'Lolint' via qubes-users wrote: > Confirmation by Shintel: > https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide%20-%20Rev%201.1.pdf > > -- > You

[qubes-users] Re: Can't access windows shares?

2017-05-01 Thread Gaiko
On Sunday, April 30, 2017 at 8:32:39 PM UTC-4, Drew White wrote: > On Saturday, 29 April 2017 08:25:19 UTC+10, Gaiko wrote: > > On a previous installation of qubes I was able to access my server with > > little problem by just going into nautlius and for "other locations" typing > > in the

[qubes-users] Re: Testers wanted

2017-05-01 Thread drew . qubes
On Sunday, 2 April 2017 13:17:20 UTC+10, Unman wrote: > > Hello all, > > Now that r3.1 is end of life, we need to do some work to clear the 113 > bugs that are still open. > > A first step would be to triage the bugs to see what still affects 3.2 > and what can be closed. > If you are

[qubes-users] Re: Intel ME exploitable

2017-05-01 Thread Vít Šesták
Some notes: * Applying the patch probably requires BIOS update (and MoBo vendor releasing the update), I guess. * I wonder what is the technical distinction between home and SMB/Enterprise. Is it vPro? * I am not sure how can I check the version. There are some ME/AMT-related Linux tools, but

Re: [qubes-users] How to get trusted iso?

2017-05-01 Thread cooloutac
On Monday, May 1, 2017 at 5:35:56 PM UTC-4, Chris Laprise wrote: > On 05/01/2017 03:43 PM, cooloutac wrote: > > Does Qubes ever plan on selling iso sticks? > > I would like to know. And I've suggested this in the past, but with > DVD-Rs which I think are preferable to USB sticks (even the ones

[qubes-users] Re: sys-usb issues ; yubikey, etc

2017-05-01 Thread ftb.myna
I do see https://github.com/adubois/qubes-app-linux-yubikey however, I think compiling it might be over my head. Can I just shutdown sys-usb and operate without it again ? I definitely need the yubikey to work, but my other security needs .. -- You received this message because you are

[qubes-users] Re: Can't access windows shares?

2017-05-01 Thread Gaiko
On Sunday, April 30, 2017 at 8:32:39 PM UTC-4, Drew White wrote: > On Saturday, 29 April 2017 08:25:19 UTC+10, Gaiko wrote: > > On a previous installation of qubes I was able to access my server with > > little problem by just going into nautlius and for "other locations" typing > > in the

Re: [qubes-users] Auto update download in Linux

2017-05-01 Thread Drew White
On Monday, 1 May 2017 22:55:20 UTC+10, Rusty Bird wrote: > Drew White: > > On Wednesday, 26 April 2017 11:05:43 UTC+10, Rusty Bird wrote: > > Well, if I don't give the guest access to the internet by restricting > > firewall, and I tell it to "Allow connections to Updates Proxy", why > >

Re: [qubes-users] Re: Opening links in your preferred AppVM

2017-05-01 Thread Ángel
On 2017-05-01 at 12:34 -0700, Gaiko wrote: > Thoughts? Does your desktop file validate? ie. run: desktop-file-validate open_work_vm.desktop If the desktop file is malformed, it will be bypassed silently. -- You received this message because you are subscribed to the Google Groups

[qubes-users] sys-usb issues ; yubikey, etc

2017-05-01 Thread Myna
well I just about locked myself out of the system, by doing : Enable sys-usb: qubesctl top.enable qvm.sys-usb Apply the configuration: qubesctl state.highstate It said like 3/5 successful, Having no idea how to undo this, and fearing meltdown, just rebooted, not to my