Re: [qubes-users] Can't get ProxyVM based VPN working

2016-06-04 Thread Chris Laprise
On 06/04/2016 10:43 AM, ad5108...@gmail.com wrote: I've been trying to configure a ProxyVM with a VPN for a while now, and I can't seem to get it to work. I've tried both the NetworkManager instructions and the command line instructions from here: https://www.qubes-os.org/doc/vpn/. The

Re: [qubes-users] "Upgrading" to btrfs

2016-06-04 Thread Chris Laprise
On 06/04/2016 07:05 PM, Achim Patzner wrote: Hi! Did anyone ever try running btrfs-convert on a Qubes /? Successfully? Achim I installed with btrfs on top of luks. You may not want to convert if you have the standard lvm on luks, because then you'll have two volume management layers

Re: [qubes-users] No /dev/cdrom present?

2016-06-02 Thread Chris Laprise
On 06/02/2016 06:40 PM, gaikokujinkyofu...@gmail.com wrote: Hi I wanted to create a win7 HVM and was going to start off by making an iso from the CD I have but then I tried the simple dd if=/dev/cdrom of=~/win7_image.iso and I get an error: dd: failed to open '/dev/cdrom': No such file or

Re: [qubes-users] BIOS updates in qubes

2016-06-02 Thread Chris Laprise
On 06/02/2016 07:54 PM, Buck Smith wrote: With a Dell laptop running qubes, presumably no BIOS updates happen, right? One could still get attacked via BIOS is some had physical access to machine to swap out a part. But not over internet. Agree? Disagree? -- That is one of Qubes'

Re: [qubes-users] Copy / Move file within a Template VM

2016-06-12 Thread Chris Laprise
On 06/12/2016 01:09 PM, qubescr...@gmail.com wrote: Hi Chris. Thanks for your response. I hadn't realized that /etc/ was a bad place to move the .ovpn file, and was just following the instructions in 'Streisand' (which is excellent, by the way!) https://github.com/jlund/streisand I guess

Re: [qubes-users] Is there a standard procedure to reinstall whonix?

2016-06-10 Thread Chris Laprise
On 06/10/2016 02:33 PM, Patrick Schleizer wrote: Andrew David Wong: On 2016-06-06 16:02, Andrew David Wong wrote: Added: https://github.com/QubesOS/qubes-doc/commit/ ffbe63ac8c6fa3feb06ab78ac88455cc90fb746a I'm not sure if I understood the proposed two changes, but feel free to submit a pull

Re: [qubes-users] Install VPN in anon-whonix

2016-06-09 Thread Chris Laprise
On 06/09/2016 06:21 AM, asdfg...@sigaint.org wrote: On 06/08/2016 04:15 PM, asdfg...@sigaint.org wrote: Hello I read the guide on whonix site about how setup a VPN in workstation but it is old and my VPN is a little different, it has a GUI interface but also a setup for Open VPN (to work i

Re: [qubes-users] use different network configuration for each template

2016-06-09 Thread Chris Laprise
On 06/09/2016 11:00 AM, Nicola Schwendener wrote: Hello all, I'm totally new to Qubes OS and I'm really fell in love. My 2 questions is about network connectivity. 1. there's a way to connect a switch with multiple VLAN in Trunk mode and let the templates work indipentently with a single

Re: [qubes-users] Proxify VM

2016-06-09 Thread Chris Laprise
On 06/09/2016 11:45 AM, Jeremy Lator wrote: Hello To setup socks5 in network-manager openvpn do I have to go advanced-->proxies and enter all the details? Thank you Yes, but I'd ask the NM folks about any issues with that. Chris -- You received this message because you are subscribed to

Re: [qubes-users] debian 8, rc.local not running

2016-06-09 Thread Chris Laprise
On 06/09/2016 10:31 PM, Drew White wrote: Hi folks, Debian 8... On boot, the rc.local file doesn't execute after the system has booted. What could be wrong? root@***:/rw/config# ls -al total **M drwxr-xr-x 3 root root 4.0K Jun 10 12:24 . drwxr-xr-x 9 root root 4.0K Jun 8 12:11 ..

Re: [qubes-users] How to setup iptables if the connection of VPN breaks down

2016-06-11 Thread Chris Laprise
On 06/11/2016 02:08 PM, katerim...@sigaint.org wrote: Hello I read a document in qubes about the script to setup in /rw/config/qubes-firewall-user-script but there are some problem Sudo nano doesn't work (it works in debian), I try with gedit but give me an error when save the file The script

Re: [qubes-users] Proxify VM

2016-06-06 Thread Chris Laprise
On 06/06/2016 06:11 AM, Jeremy Lator wrote: Shortly I have JonDo in the first VM and a VPN in the second VM. I want that the VPN detect socks of JonDo during the connection MyISP --> JonDo --> Firewall --> VPN-->internet \/ \ / \/ \ /

Re: [qubes-users] TheBrain installation - JRE Error?

2016-06-06 Thread Chris Laprise
On 06/05/2016 09:29 AM, 0981'029438'109438'0192438'0192438'019438'0943 wrote: Hello, I like to install thebrain 7: http://www.thebrain.com/products/thebrain/download-old/ JAVA is not a high security backbone, so in the future, I would like to install all JAVA Apps in a isolated HVM. But

Re: [qubes-users] TheBrain installation - JRE Error?

2016-06-05 Thread Chris Laprise
On 06/05/2016 09:29 AM, 0981'029438'109438'0192438'0192438'019438'0943 wrote: Hello, I like to install thebrain 7: http://www.thebrain.com/products/thebrain/download-old/ JAVA is not a high security backbone, so in the future, I would like to install all JAVA Apps in a isolated HVM. But

Re: [qubes-users] Install VPN in anon-whonix

2016-06-08 Thread Chris Laprise
On 06/08/2016 04:15 PM, asdfg...@sigaint.org wrote: Hello I read the guide on whonix site about how setup a VPN in workstation but it is old and my VPN is a little different, it has a GUI interface but also a setup for Open VPN (to work i have to use GUI). Do I setup like a normal VPN in

Re: [qubes-users] Where to install wireshark?

2016-05-29 Thread Chris Laprise
On 05/29/2016 11:46 AM, qazx...@sigaint.org wrote: Hi. I just installed Qubes, and I'm doing a tor -> proxy setup with whonix (Because of CloudFlare...), and I want to make sure it's working properly by looking at the traffic after it leaves whonix gateway. On my old system I'd just install

Re: [qubes-users] Is it possible to turn a Template HVM into an HVM?

2016-05-29 Thread Chris Laprise
On 05/29/2016 10:31 AM, Achim Patzner wrote: Hi! I guess the subject said it already: If someone created a (Windows 7-based) Template HVM based on the assumption it would be a good idea to do this to derive a number of HVMs from it but had to agree that it was not one of his brightest ideas,

Re: [qubes-users] Debian 8 Template, can't install printers

2016-06-02 Thread Chris Laprise
On 06/02/2016 12:32 AM, Drew White wrote: On Thursday, 2 June 2016 14:11:32 UTC+10, Chris Laprise wrote: On 06/01/2016 10:29 PM, Drew White wrote: > > The UI he is describing is system-config-printer (Red Hat). He > could try > gnome-co

Re: [qubes-users] Web Conferencing software and QUbes

2016-05-26 Thread Chris Laprise
On 05/25/2016 05:13 PM, Franz wrote: On Wed, May 25, 2016 at 2:00 PM, > wrote: On Wednesday, May 25, 2016 at 1:24:04 AM UTC-4, J. Eppler wrote: > Hello, > > > > > If there is another web conferencing app that works

Re: [qubes-users] i2p AppVM

2016-05-26 Thread Chris Laprise
On 05/25/2016 02:24 PM, cubit wrote: Hello Are there any i2p users on the list, I would be interested in hearing how you are setting up your AppVMs to best keep this traffic as secure as possible. -- The i2p router is super simple and automatic, esp. if you're using straight i2p to

Re: [qubes-users] Debian 8 Template, can't install printers

2016-05-26 Thread Chris Laprise
On 05/25/2016 03:29 AM, Drew White wrote: I don't know what communicating with the printer has to do with anything, it's the install of the driver that isn't working. I can do it with Fedora Template, but not Debian template. The templates themselves have no such restriction that you are

Re: [qubes-users] Web Conferencing software and QUbes

2016-05-26 Thread Chris Laprise
On 05/26/2016 06:42 PM, Franz wrote: On Thu, May 26, 2016 at 6:16 PM, Chris Laprise <tas...@openmailbox.org <mailto:tas...@openmailbox.org>> wrote: On 05/25/2016 05:13 PM, Franz wrote: On Wed, May 25, 2016 at 2:00 PM, <raahe...@gmail.com <mailto:

Re: [qubes-users] btrfs vs lvm?

2016-05-30 Thread Chris Laprise
On 05/30/2016 11:35 AM, Rusty Bird wrote: Bahtiar `kalkin-` Gadimov: IMHO you should use LVM. Because btrfs is IMHO not mature enough. (Personal anecdote warning) I used it for backups until the partion become read-only and throw out of space warnings, for no obvious reason. On Qubes 3.0, I

Re: [qubes-users] Password management best practices for mid-grade tinfoil hats

2016-06-21 Thread Chris Laprise
On 06/21/2016 11:13 AM, stephen.wick...@gmail.com wrote: As I'm moving from OS X to Qubes, gradually, I wanted to get a feel for best practices for management of passwords. Qubues has KeePassX. Should I trust that over the Firefox password manager? Or pretty similar? Would it be a good idea

Re: [qubes-users] problem with running mullvad in proxyvm (DNS weirdness and autostart question)?

2016-06-21 Thread Chris Laprise
On 06/21/2016 02:09 AM, Jane Jok wrote: Hello! So, long story short, I've successfully configured a debian-based ProxyVM to run Mullvad's GUI client (I know one can use "vanilla OpenVPN" to connect to mullvad, I still prefer their GUI thing and decided to give it a try) In a word, as

Re: [qubes-users] problem with running mullvad in proxyvm (DNS weirdness and autostart question)?

2016-06-21 Thread Chris Laprise
On 06/21/2016 03:04 PM, Chris Laprise wrote: On 06/21/2016 02:09 AM, Jane Jok wrote: Hello! So, long story short, I've successfully configured a debian-based ProxyVM to run Mullvad's GUI client (I know one can use "vanilla OpenVPN" to connect to mullvad, I still prefer their

Re: [qubes-users] create new VM freeze screen 1

2016-06-18 Thread Chris Laprise
On 06/18/2016 02:55 PM, 109348'109438'0193284'0913284'092183'0491820439 wrote: Hi Chris, used 2777284 free 17995792 shared 338500 buffers 62024 cached 2037140 buffer/cache used 67812 free 80117772 swap 8011772 used 0 create Fedora23 AppVM = 6 Seconds, yes create Debian8 AppVM = 5 Seconds,

Re: [qubes-users] How to share data between 2 Qubes installations via USB in a sensible way?

2016-06-19 Thread Chris Laprise
On 06/19/2016 05:25 AM, David Hobach wrote: I wonder whether there's any sensible (= relatively secure) way of sharing data between 2 Qubes installations via a single USB pen drive or hard disk? What are you using or do you have any thoughts? [...] Probably I did understand what you are

Re: [qubes-users] create new VM freeze screen 1

2016-06-18 Thread Chris Laprise
On 06/18/2016 08:48 AM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2016-06-18 05:29, '098134'0194328'017834'01783'40917834209 wrote: Hallo, it is a little strange, always if I create a new VM (which takes several minutes), than the system response time for

Re: [qubes-users] How do I install packages to a template over a VPN?

2016-06-22 Thread Chris Laprise
On 06/22/2016 05:50 PM, james.e.w...@gmail.com wrote: My employer supports Fedora as a workstation OS, but it requires a lot of software be applied and that software must be obtained over their VPN. What I have tried: 1. clone fedora-23 to OCfedora-23 2. download two VPN rpms from a VM and

Re: [qubes-users] Opening links in your preferred AppVM

2016-06-23 Thread Chris Laprise
On 06/22/2016 02:38 PM, Micah Lee wrote: I published a quick blog post explaining how I do this: https://micahflee.com/2016/06/qubes-tip-opening-links-in-your-preferred-appvm/ Hi Micah, I liked your new article on messaging apps. Just wondering if you've looked at Ring.cx yet... Its open

Re: [qubes-users] How to install clean template?

2016-06-22 Thread Chris Laprise
On 06/22/2016 08:45 PM, Ward... James Ward wrote: I have even bypassed the firewall. I've got the VPN ProxyVM pointing directly at NetVM. That doesn't bypass the firewall exactly. The vpn vm is also a firewall, and it accepts the firewall settings of other vms that are pointing to it. So

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-06-23 Thread Chris Laprise
On 06/23/2016 06:53 AM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2016-06-23 03:49, Rusty Bird wrote: Hi Andrew, On 2016-06-22 21:58, Todd Lasman wrote: On 05/16/2016 11:44 PM, Andrew David Wong wrote: I seem to have this exact same problem, but only

Re: [qubes-users] How to install clean template?

2016-06-23 Thread Chris Laprise
Continuing this in James' original thread... https://groups.google.com/d/msgid/qubes-users/fbc140cc-94e4-4218-8095-3a73d346296f%40googlegroups.com Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] How do I install packages to a template over a VPN?

2016-06-23 Thread Chris Laprise
There is an issue with updating a template over a vpn: The intercepting updates proxy normally runs in sys-net, which can't see inside the encrypted vpn traffic. This may be a cause of the problem, however it should really only manifest if you are using yum/dnf; Programs like wget should be

Re: [qubes-users] [3.2rc1] Installer boot error '/dev/root' does not exist

2016-06-25 Thread Chris Laprise
On 06/25/2016 07:10 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Jun 25, 2016 at 05:21:27AM -0400, Chris Laprise wrote: On 06/24/2016 08:25 PM, Chris Laprise wrote: I've tried this on 2 USB sticks (a USB2 and USB3) and I'm not able to boot

Re: [qubes-users] [3.2rc1] Installer boot error '/dev/root' does not exist

2016-06-25 Thread Chris Laprise
Here's a prior thread with the same error message: https://groups.google.com/forum/#!topic/qubes-users/Zu4i5kUWva8 You also mentioned he didn't have Qubes media visible, which is basically my problem. Although I'm not using UEFI, I'm wondering if I should try his solution, though I'm not

Re: [qubes-users] [3.2rc1] Installer boot error '/dev/root' does not exist

2016-06-26 Thread Chris Laprise
On 06/26/2016 06:50 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Jun 26, 2016 at 06:45:50AM -0400, Chris Laprise wrote: More info, Marek... When I try to scan the /dev/sdb device with partx, it says the device is not readable or not valid

Re: [qubes-users] [3.2rc1] Installer boot error '/dev/root' does not exist

2016-06-26 Thread Chris Laprise
More info, Marek... When I try to scan the /dev/sdb device with partx, it says the device is not readable or not valid device. When I plug in another USB stick, the partitions are enumerated as /dev/sdc1 etc. but they cannot be mounted (devices are unreadable). From dmesg, these errors

Re: [qubes-users] [3.2rc1] Installer boot error '/dev/root' does not exist

2016-06-26 Thread Chris Laprise
On 06/26/2016 06:50 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Jun 26, 2016 at 06:45:50AM -0400, Chris Laprise wrote: More info, Marek... When I try to scan the /dev/sdb device with partx, it says the device is not readable or not valid

[qubes-users] [3.2rc1] Installer boot error '/dev/root' does not exist

2016-06-24 Thread Chris Laprise
I've tried this on 2 USB sticks (a USB2 and USB3) and I'm not able to boot the new installer from either one. Apparently it can't find the filesystem it needs to transition from the initramfs root. The iso was verified with gpg and written to the drives with plain 'dd if=isoimage of=dev/sdb'.

Re: [qubes-users] Unable to install 3.2-rc1 on Thinkpad T450s

2016-06-26 Thread Chris Laprise
On 06/26/2016 02:08 PM, 41wycb+5v6q0qb48s8dk via qubes-users wrote: Hello, I've disabled all support for UEFI in the BIOS, having enabled only support to Legacy mode. I've also disabled the secure boot having enabled the 'USB UEFI BIOS Support'. At this stage I'm able to get the grub splash

Re: [qubes-users] [3.2rc1] Installer boot error '/dev/root' does not exist

2016-06-25 Thread Chris Laprise
On 06/24/2016 08:25 PM, Chris Laprise wrote: I've tried this on 2 USB sticks (a USB2 and USB3) and I'm not able to boot the new installer from either one. Apparently it can't find the filesystem it needs to transition from the initramfs root. The iso was verified with gpg and written

Re: [qubes-users] How to log all the websites accessed by a VM

2016-07-25 Thread Chris Laprise
On 07/25/2016 02:20 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Jul 25, 2016 at 03:14:02PM -0300, Franz wrote: ok now it works, it outputted a list of addresses. But I have to paste this list on firewall rules of that VM and this is on Qubes

Re: [qubes-users] Qubes Security Bulletin #24 (Critical bug)

2016-07-26 Thread Chris Laprise
On 07/26/2016 08:45 PM, el...@tutanota.com wrote: What is best way to verify our system supports these things? I think you can also check out the processor with Intel.. ark.intel.com You can search through the different processors if you are looking to pick up a new computer. A guide I

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-07-11 Thread Chris Laprise
On 07/05/2016 02:21 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Jul 04, 2016 at 10:26:51AM -0400, Chris Laprise wrote: If I replace the kernel with 4.1 from R3.1, it can make it to the AEM target and the decrypt prompt. It chokes just after

Re: [qubes-users] Firewall rules

2016-07-14 Thread Chris Laprise
On 07/14/2016 10:39 AM, katerim...@sigaint.org wrote: Good day I'm using a VPN in sys-net and would setup firewall rules to stop internet connection if VPN crash. In sys-net isn't possible to insert ip addresses, then I did it in sys-firewall. With some tests I saw that if VPN disconnect

Re: [qubes-users] Changing swap. /etc/fstab cant be edited

2016-07-14 Thread Chris Laprise
On 07/14/2016 05:43 PM, Facundo Curti wrote: Hi list. I'm having troubles to start qubes. When I start it says that a partition is being used by a process. As I was reading: https://forums.opensuse.org/showthread.php/503587-Slow-boot-What-is-quot-A-start-job-is-running-for-dev-disk-by-quot

Re: [qubes-users] Cryptsetup LUKS Nuke Option

2016-07-22 Thread Chris Laprise
On 07/22/2016 07:03 PM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2016-07-22 08:15, TheFactory wrote: Another good use for this feature is that you can pre-program in some landmines to destroy the drive and overcome brute force. Since the LUKS password prompt

Re: [qubes-users] Qubes Security Bulletin #24 (Critical bug)

2016-07-28 Thread Chris Laprise
On 07/27/2016 04:27 PM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2016-07-26 20:01, Chris Laprise wrote: On 07/26/2016 08:45 PM, el...@tutanota.com wrote: What is best way to verify our system supports these things? I think you can also check out

Re: [qubes-users] Re: Fedora 23 template upgrade conflict

2016-07-29 Thread Chris Laprise
On 07/29/2016 02:08 PM, 45uiay+8xfsofrot5g94 via qubes-users wrote: Just did, still no luck. The update still presents the same error. I had to use 'dnf clean all' before update would work. Chris -- You received this message because you are subscribed to the Google Groups "qubes-users"

Re: [qubes-users] Yellow dot / guid crash in appvms

2016-07-31 Thread Chris Laprise
On 07/31/2016 04:32 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Jul 31, 2016 at 04:19:50PM -0400, Chris Laprise wrote: ErrorHandler: BadWindow (invalid Window parameter) Major opcode: 10 (X_UnmapWindow

Re: [qubes-users] VPN ProxyVM rc.local

2016-08-14 Thread Chris Laprise
On 08/14/2016 04:52 PM, Paf LeGeek wrote: Hello ! I am trying to follow the steps in the link below to make a ProxyVpn with VPN autostart : https://www.qubes-os.org/doc/vpn/ But my rc.local does not start on my ProxyVM. I did the commands below on my Debian 8 Template VM : sudo chmod +x

Re: [qubes-users] Re: Buying new laptop.. What check should I do in-store..?

2016-07-12 Thread Chris Laprise
On 07/12/2016 08:04 PM, neilhard...@gmail.com wrote: Is it worth checking for a BIOS compatible with coreboot or libreboot, or some kind of open source BIOS..? Is it true that if I have a Intel ME processor, but a motherboard that isn't compatible.. that at least this prevents network access

Re: [qubes-users] Unable to update templates

2016-07-20 Thread Chris Laprise
On 07/20/2016 01:20 PM, jkitt wrote: My netvm is a proxyvm that I've set up. I've just found out about the global in which the updatevm can be changed. However, i've set this to my VPN VM yet nothing - it's still trying to connect to the same IP. IRRC that IP is a non-existent node but it's

Re: [qubes-users] VPN Link Up, NetVM set to VpnVM but AppVMs still don't have net access?

2016-07-20 Thread Chris Laprise
On 07/20/2016 02:59 PM, gaikokujinkyofu...@gmail.com wrote: On Saturday, July 16, 2016 at 5:09:48 PM UTC-4, gaikokuji...@gmail.com wrote: I tried the 'sudo iptables -L -v -t nat' anyway and to be honest I am not sure I understand the output: [user@VPN ~]$ sudo iptables -L -v -t nat Chain

Re: [qubes-users] Setting up OpenVPN (Can't understand documentation)

2016-07-17 Thread Chris Laprise
On 07/17/2016 04:26 AM, ajshdas7...@sigaint.org wrote: Under "Using iptables and openvpn" @ https://www.qubes-os.org/doc/vpn/ It says to create the proxyvm, but it does not say if the following steps should be taken in the template or in the proxyvm. Does anyone know? That part should be

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-07-15 Thread Chris Laprise
On 07/13/2016 11:15 AM, Chris Laprise wrote: On 07/12/2016 11:15 AM, Chris Laprise wrote: On 07/12/2016 01:48 AM, Chris Laprise wrote: On 07/05/2016 02:21 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Jul 04, 2016 at 10:26:51AM -0400, Chris

Re: [qubes-users] Is there any debugging in the Qubes 3.2-r1 installer?

2016-07-15 Thread Chris Laprise
On 07/15/2016 01:55 PM, Achim Patzner wrote: Hi! As I'm not getting the install image to boot into the installer (it is dropping me into dracut), is there any debug version that could collect debug information in a convenient way? Alternatively: Could the installation process be launched from

Re: [qubes-users] VPN Link Up, NetVM set to VpnVM but AppVMs still don't have net access?

2016-07-15 Thread Chris Laprise
On 07/15/2016 01:26 PM, gaikokujinkyofu...@gmail.com wrote: On Thursday, July 14, 2016 at 5:50:52 PM UTC-7, Chris Laprise wrote: On 07/13/2016 12:36 PM, gaikokujinkyofu...@gmail.com wrote: Hi, with quite a bit of help (thanks again) I was able to setup a VpnVM and have it work perferctly

Re: [qubes-users] Firewall rules

2016-07-14 Thread Chris Laprise
On 07/14/2016 04:51 PM, katerim...@sigaint.org wrote: On 07/14/2016 10:39 AM, katerim...@sigaint.org wrote: Good day I'm using a VPN in sys-net and would setup firewall rules to stop internet connection if VPN crash. In sys-net isn't possible to insert ip addresses, then I did it in

Re: [qubes-users] Question on SECURITY of WHONIX VM

2016-07-12 Thread Chris Laprise
On 07/12/2016 09:23 AM, neilhard...@gmail.com wrote: I have a question about the security of Whonix, which is used as the Tor VM in QUBES 3.2. My question is... we know that the Tor Browser can be hacked, mainly based on Firefox exploits. So it's very possible that when I'm using Whonix, the

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-07-12 Thread Chris Laprise
On 07/12/2016 01:48 AM, Chris Laprise wrote: On 07/05/2016 02:21 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Jul 04, 2016 at 10:26:51AM -0400, Chris Laprise wrote: If I replace the kernel with 4.1 from R3.1, it can make it to the AEM target

Re: [qubes-users] Multi-drive computers installation

2016-07-13 Thread Chris Laprise
On 07/12/2016 08:35 PM, Drew White wrote: Has anyone been able to install Qubes on a multi-drive PC as a multi-drive PC without having all drives formed into 1 yet? Anaconda always seems to mess up when I manually setup partitions. But both LVM and Btrfs will let you expand volumes into

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-07-13 Thread Chris Laprise
On 07/12/2016 11:15 AM, Chris Laprise wrote: On 07/12/2016 01:48 AM, Chris Laprise wrote: On 07/05/2016 02:21 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Jul 04, 2016 at 10:26:51AM -0400, Chris Laprise wrote: If I replace the kernel with 4.1

Re: [qubes-users] AEM with Linux 4.4 causes hard reboot (cont... Trying to resolve issue)

2016-07-15 Thread Chris Laprise
On 07/15/2016 10:09 PM, Todd Lasman wrote: On 07/15/2016 04:38 PM, Chris Laprise wrote: On 07/15/2016 09:33 AM, Chris Laprise wrote: On 07/13/2016 11:15 AM, Chris Laprise wrote: I am able to get 4.4.* to boot now! The trick was to add 'min_ram=0x200' to the tboot options like I used

Re: [qubes-users] Question on DMA attacks

2016-07-15 Thread Chris Laprise
On 07/15/2016 02:43 PM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2016-07-15 01:46, Marek Marczykowski-Górecki wrote: On Thu, Jul 14, 2016 at 07:22:28PM -0700, neilhard...@gmail.com wrote: From the user FAQ:

[qubes-users] AEM with Linux 4.4 causes hard reboot (cont... Trying to resolve issue)

2016-07-15 Thread Chris Laprise
On 07/15/2016 09:33 AM, Chris Laprise wrote: On 07/13/2016 11:15 AM, Chris Laprise wrote: I am able to get 4.4.* to boot now! The trick was to add 'min_ram=0x200' to the tboot options like I used to do--the AEM README describes how. But now I cannot get AEM to seal the secret. Nothing

Re: [qubes-users] Tradeoffs between btrfs, lvm, and lvm thin provisioning.

2016-06-28 Thread Chris Laprise
On 06/27/2016 09:47 PM, indoler...@gmail.com wrote: What are the tradeoffs between btfs, lvm, and lvm with thin provisioning WRT speed and space efficiency? Both btrfs and (thin) lvm do similar things with copy-on-write, though I have not seen direct comparisons of speed between them. Btrfs

Re: [qubes-users] Opengl, passwords, crypt, vpn and docs

2016-06-28 Thread Chris Laprise
On 06/27/2016 09:18 PM, Eva Star wrote: 1) VPN doc say at the first part that need to add "network-manager" and enable it. At the second part it's without "network-manager". When/On what situations I need I enable? When using a proxy vm to run the vpn client, you can either enable network

Re: [qubes-users] Re: Qubes 3.2 rc1 has been released!

2016-06-28 Thread Chris Laprise
On 06/28/2016 02:23 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Tue, Jun 28, 2016 at 10:36:42AM -0700, raahe...@gmail.com wrote: Will we be able to upgrade to 3.2 from dom0 update eventually? Or if we choose not to reinstall is there security

Re: [qubes-users] Re: Creating a VPN VM using openvpn issues? (starting with no /rw/config/openvpn ?)

2016-07-05 Thread Chris Laprise
On 07/04/2016 08:42 PM, gaikokujinkyofu...@gmail.com wrote: No worries, honestly I should have thought of the sudo myself. Well, running it with sudo and it went swimmingly, it connected so that is good, another hurdle cleared. I am now back to one of your earlier posts in this thread,

Re: [qubes-users] Qubes top priorities suggestions for me as an user.

2016-07-05 Thread Chris Laprise
On 07/05/2016 04:43 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, Jul 04, 2016 at 10:46:52PM -0700, juris...@gmail.com wrote: 1) qubes is a system for security and isolation. But when you install, you have no encryption options. Full disk

Re: [qubes-users] Qubes 3.1 crashing, no warning, no error message (Lenovo X230)

2016-07-07 Thread Chris Laprise
On 07/07/2016 06:49 AM, Andreas Rasmussen wrote: On 07/07/2016 05:32 AM, Chris Laprise wrote: On 07/06/2016 01:28 PM, Andreas Rasmussen wrote: Hi! I bought a Lenovo x230 and installed Qubes 3.1 early may. It has worked like a charm, but in the last two or three weeks the computer has been

Re: [qubes-users] Qubes top priorities suggestions for me as an user.

2016-07-07 Thread Chris Laprise
On 07/07/2016 10:40 AM, Duncan Guthrie wrote: On 7 July 2016 03:28:48 BST, Chris Laprise <tas...@openmailbox.org> wrote: On 07/06/2016 09:42 PM, raahe...@gmail.com wrote: I'm not so adamant about wanting gpu passthrough on qubes, cause imo, gaming online usually means all security

Re: [qubes-users] Qubes top priorities suggestions for me as an user.

2016-07-07 Thread Chris Laprise
On 07/07/2016 12:45 PM, Duncan Guthrie wrote: On 7 July 2016 16:53:35 BST, Chris Laprise <tas...@openmailbox.org> wrote: On 07/07/2016 10:40 AM, Duncan Guthrie wrote: On 7 July 2016 03:28:48 BST, Chris Laprise <tas...@openmailbox.org> wrote: On 07/06/2016 09:42 PM, raahe.

Re: [qubes-users] Qubes top priorities suggestions for me as an user.

2016-07-08 Thread Chris Laprise
On 07/08/2016 12:27 AM, raahe...@gmail.com wrote: I'm also confused, you say gpus are so insecure and that qubes is not doing enough to isolate them? I don't think that's what I implied. But trying to be concise on a complex subject can leave some people with the wrong impression, so I

Re: [qubes-users] Qubes top priorities suggestions for me as an user.

2016-07-06 Thread Chris Laprise
On 07/06/2016 09:42 PM, raahe...@gmail.com wrote: I'm not so adamant about wanting gpu passthrough on qubes, cause imo, gaming online usually means all security is out the window. Plus I feel as though gpu is much bigger attack surface for side channel attacks then net card. I could be

Re: [qubes-users] Qubes 3.1 crashing, no warning, no error message (Lenovo X230)

2016-07-06 Thread Chris Laprise
On 07/06/2016 01:28 PM, Andreas Rasmussen wrote: Hi! I bought a Lenovo x230 and installed Qubes 3.1 early may. It has worked like a charm, but in the last two or three weeks the computer has been shutting down without warning or error message. It has happened five times with no apparent

Re: [qubes-users] Template installation not being reflected on AppVMs

2016-07-08 Thread Chris Laprise
On 07/08/2016 07:27 PM, danmichaels8...@gmail.com wrote: I am using QUBES 3.0 Fedora-21 When I install certain programs in the template VM for fedora, they do not show up in the AppVMs, even after restarting each of the AppVMs. I installed google-chrome-stable, and yet, it's not reflected in

Re: [qubes-users] Qubes-users forum - Please, moderate this guy

2016-07-09 Thread Chris Laprise
On 07/09/2016 08:17 AM, Gorka Alonso wrote: https://groups.google.com/d/msg/qubes-users/V8_SvMk0yx0/P4VNTpFnBQAJ "Achim. Don't forget YOU are the homosexual, NOT ME. That's a mental disease, doesn't matter if for political reasons was removed or not from disease list." Even me, being

Re: [qubes-users] Application Firewall AppArmor

2016-07-09 Thread Chris Laprise
On 07/09/2016 08:43 AM, '093148'0193248'109438'0193284'09318 wrote: Hello, where I can install the AppArmor application firewall, inside the TVM, the Template VM, correct? Is their something Qubes specific to take into account or best practices how to isolate apps inside a VM? Kind Regards

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-07-05 Thread Chris Laprise
Is there an issue open for this yet? Chris -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send

Re: [qubes-users] Re: Creating a VPN VM using openvpn issues? (starting with no /rw/config/openvpn ?)

2016-07-05 Thread Chris Laprise
On 07/05/2016 10:17 AM, gaikokujinkyofu...@gmail.com wrote: On Tuesday, July 5, 2016 at 5:52:08 AM UTC-4, Chris Laprise wrote: On 07/04/2016 08:42 PM, gaikokujinkyofu...@gmail.com wrote: No worries, honestly I should have thought of the sudo myself. Well, running it with sudo and it went

Re: [qubes-users] Re: Creating a VPN VM using openvpn issues? (starting with no /rw/config/openvpn ?)

2016-07-04 Thread Chris Laprise
On 07/04/2016 11:33 AM, gaikokujinkyofu...@gmail.com wrote: On Sunday, July 3, 2016 at 11:32:53 PM UTC-3:30, Chris Laprise wrote: On 07/03/2016 10:10 PM, gaikokujinkyofu...@gmail.com wrote: On Sunday, July 3, 2016 at 9:56:15 PM UTC+3, Chris Laprise wrote: On 07/03/2016 09:14 PM

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-07-04 Thread Chris Laprise
If I replace the kernel with 4.1 from R3.1, it can make it to the AEM target and the decrypt prompt. It chokes just after decrypting the volumes, but that's to be expected. The 4.4 kernel appears to introduce some factor that causes the crash. Swapping xen 4.6.1 with 4.6.0 has no visible

Re: [qubes-users] newbie question about port forwarding and remote connection

2016-07-04 Thread Chris Laprise
On 07/04/2016 09:29 AM, Nicola Schwendener wrote: Hello all, I'm totally new in Qubes OS. I'm moving from Windows and a "single" OS doing all... I'm posing some (stupid) questions that maybe I understand better how to migate it: Right now I've NoMachine running on my windows pc, allowing

Re: [qubes-users] Re: Creating a VPN VM using openvpn issues? (starting with no /rw/config/openvpn ?)

2016-07-05 Thread Chris Laprise
On 07/05/2016 11:03 AM, gaikokujinkyofu...@gmail.com wrote: On Tuesday, July 5, 2016 at 10:44:03 AM UTC-4, Chris Laprise wrote: On 07/05/2016 10:17 AM, gaikokujinkyofu...@gmail.com wrote: On Tuesday, July 5, 2016 at 5:52:08 AM UTC-4, Chris Laprise wrote: On 07/04/2016 08:42 PM

Re: [qubes-users] Re: Creating a VPN VM using openvpn issues? (starting with no /rw/config/openvpn ?)

2016-07-06 Thread Chris Laprise
On 07/05/2016 03:05 PM, gaikokujinkyofu...@gmail.com wrote: I renamed the file, and that seems to have gotten it, in that I am now prompted to login to the vpn but now I noticed that my VpnVM does not have network access? I don't know at what point this happened but perhaps this is related

Re: [qubes-users] howto add untrusted repository to appVM (without using seperate template)

2016-08-07 Thread Chris Laprise
On 08/07/2016 07:22 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sat, Aug 06, 2016 at 06:36:10PM -0700, Andrew David Wong wrote: On 2016-08-06 18:05, emilcronja...@gmail.com wrote: Hi there, How do I add an outside/untrusted repository to an app-vm

Re: [qubes-users] Qubes Manager issues

2016-06-30 Thread Chris Laprise
On 06/29/2016 10:12 PM, Drew White wrote: Hi folks, I've just had Qubes Manager go haywire on me. Freezes up because it's using 597 MB RAM with 38 MB shared. That's just rhediculous. I had to kill the process to get out of it. And as usual, it won't start again and I have to reboot the

[qubes-users] [3.2rc1] Bug: Windows disappear, VMs go from green to yellow

2016-06-30 Thread Chris Laprise
The gui daemon connection for debian 8 VMs is disappearing in two different scenarios: 1. When starting the VM, the status goes from yellow to green then back to yellow within about 3 seconds. 2. When exiting the vlc player, all windows for that vm will disappear. I can recover from this

Re: [qubes-users] Networking

2016-06-30 Thread Chris Laprise
On 06/30/2016 09:37 PM, Drew White wrote: Hi folks, Just wondering why my Win7 has only 100 Mbit networking instead of Gigabit? Is there any way to make it gigabit in the vm? When I only have 1 or 2 VMs running, to use only 100 Mbit out of a 1000 Mbit NIC is just wasteful. Please help.

[qubes-users] Re: [3.2rc1] Bug: Windows disappear, VMs go from green to yellow

2016-06-30 Thread Chris Laprise
On 06/30/2016 09:56 PM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Thu, Jun 30, 2016 at 09:35:59PM -0400, Chris Laprise wrote: The gui daemon connection for debian 8 VMs is disappearing in two different scenarios: 1. When starting the VM, the status

Re: [qubes-users] Networking

2016-06-30 Thread Chris Laprise
On 06/30/2016 09:50 PM, Drew White wrote: On Friday, 1 July 2016 11:42:05 UTC+10, Chris Laprise wrote: That's just a description of the emulated adapter. No, it's the physical speed of throughput of data actually. I'm not talking about a descriptor, I'm talking about the actual speed

Re: [qubes-users] Q wipe files

2016-07-01 Thread Chris Laprise
On 07/01/2016 01:14 AM, Andrew David Wong wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2016-06-30 13:47, 109384'109438'0194328'0914328'098 wrote: Hello, Q security policy don't protect against app-exploits, but give the tools to protect your data. Protect data, but not apps!

Re: [qubes-users] Re: Video in Qubes 3.2

2016-06-29 Thread Chris Laprise
On 06/29/2016 03:44 AM, Drew White wrote: On Wednesday, 29 June 2016 17:41:49 UTC+10, ghbouc...@gmail.com wrote: Hi. I'm talking about the VM "virutal" CPU. hint: 1 vCPU = 1 thread of the real CPU. > How many threads do you have assigned to the VM? 8 Well, without

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-07-03 Thread Chris Laprise
On 05/30/2016 03:39 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, May 29, 2016 at 11:10:45PM -0700, Andrew David Wong wrote: On 2016-05-29 16:34, Marek Marczykowski-Górecki wrote: On Fri, May 27, 2016 at 03:27:50AM -0700, Andrew David Wong

Re: [qubes-users] Re: Creating a VPN VM using openvpn issues? (starting with no /rw/config/openvpn ?)

2016-07-03 Thread Chris Laprise
On 07/03/2016 09:14 PM, gaikokujinkyofu...@gmail.com wrote: On Wednesday, June 22, 2016 at 1:48:33 PM UTC-3:30, gaikokuji...@gmail.com wrote: On Monday, June 20, 2016 at 5:19:27 AM UTC+5:45, Chris Laprise wrote: On 06/19/2016 10:13 PM, gaikokujinkyofu...@gmail.com wrote: On Thursday, June

Re: [qubes-users] AEM boot option causes hard reboot/partial shutdown (Lenovo T450s)

2016-07-04 Thread Chris Laprise
On 07/04/2016 07:26 AM, Marek Marczykowski-Górecki wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Jul 03, 2016 at 09:20:47PM -0400, Chris Laprise wrote: AEM is now causing reboots for me as well, after installing it under R3.2rc1. Has there been any progress on this? I don't

  1   2   3   4   5   6   7   8   9   >