Re: [qubes-users] Recommended laptop?
December 31, 2019 1:02 PM, "eira wahlin" wrote: > I use qubes on an AMD system (thinkpad with Ryzen 5 pro 2500u). While I'm > happy with it, I've had > to make some sacrifices. AMD systems are tricky with hardware forwarding, so > I cannot (at the > moment) use a sys-USB. There is an inherent security problem there. > > Also, I've had to make my own versions of the (horribly elitistic and > class-hatingly named) AEM > system. I use my machine's TPM2 to verify that my BIOS hasn't been infected, > but that was difficult > as hell to set up. AEM relies on Intel's TPM module, and doesn't work with > AMD machines. > > So while most of it all works, it's been tricky to set up, and it's not all > functional yet. > > <3 > /panina Hi again, processor buddy. I have the Ryzen 5 (non-Pro) 2500U. I've also had a lot of problems with it. The IOMMU grouping is terrible, the kernel has a lot of problems with the firmware and ACPI, it doesn't support USB Qube, and so on. I haven't dared to even try AEM on this machine. But considering the performance for the money, I guess I really can't complain. I recently got suspend/resume half working. Turns out, some or all of the Fam15h processors including the 2500U change their cpuid feature bits when resuming from suspend, which causes a Xen panic. This means the fans come back on, but the screen doesn't power back on and it can't save any logs, so it's really hard to diagnose. You can patch Xen to disable the feature check. If you don't mind patching Xen, it's very likely that this will fix it for you (although you may run into other post-resume problems). And it's really not as difficult as it sounds. This link contains a patch and instructions for building it. https://www.mail-archive.com/qubes-users@googlegroups.com/msg31697.html -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/7cb86fb029b7e582b13e5cf32013d7c4%40disroot.org.
Re: [qubes-users] Recommended laptop?
I use qubes on an AMD system (thinkpad with Ryzen 5 pro 2500u). While I'm happy with it, I've had to make some sacrifices. AMD systems are tricky with hardware forwarding, so I cannot (at the moment) use a sys-USB. There is an inherent security problem there. Also, I've had to make my own versions of the (horribly elitistic and class-hatingly named) AEM system. I use my machine's TPM2 to verify that my BIOS hasn't been infected, but that was difficult as hell to set up. AEM relies on Intel's TPM module, and doesn't work with AMD machines. So while most of it all works, it's been tricky to set up, and it's not all functional yet. <3 /panina On 24 December 2019 13:54:50 CET, Claudia wrote: >December 24, 2019 12:51 PM, taschent...@posteo.de wrote: > >> On Tue, 2019-12-24 at 12:48 +, Claudia wrote: >> >>> Personally I would try to avoid AMD systems, >> >> why that? >> >> -- >> You received this message because you are subscribed to the Google >Groups "qubes-users" group. >> To unsubscribe from this group and stop receiving emails from it, >send an email to >> qubes-users+unsubscr...@googlegroups.com. >> To view this discussion on the web visit >> >https://groups.google.com/d/msgid/qubes-users/8137b39c393fd7d7192a72a8620706ae13f4150b.camel@posteo. >> e. > > >https://www.mail-archive.com/qubes-users@googlegroups.com/msg31520.html > >Not scientific evidence or anything, just my personal >opinion/experience. > >-- >You received this message because you are subscribed to the Google >Groups "qubes-users" group. >To unsubscribe from this group and stop receiving emails from it, send >an email to qubes-users+unsubscr...@googlegroups.com. >To view this discussion on the web visit >https://groups.google.com/d/msgid/qubes-users/dbb007537f3a3cae3b2356ea6df374b2%40disroot.org. -- Sent from my Android device with K-9 Mail. Please excuse my brevity. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/958DAD3F-58A4-45E7-BE25-85E598A08534%40nonbinary.me.
Re: [qubes-users] Recommended laptop?
December 24, 2019 12:51 PM, taschent...@posteo.de wrote: > On Tue, 2019-12-24 at 12:48 +, Claudia wrote: > >> Personally I would try to avoid AMD systems, > > why that? > > -- > You received this message because you are subscribed to the Google Groups > "qubes-users" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to > qubes-users+unsubscr...@googlegroups.com. > To view this discussion on the web visit > https://groups.google.com/d/msgid/qubes-users/8137b39c393fd7d7192a72a8620706ae13f4150b.camel@posteo. > e. https://www.mail-archive.com/qubes-users@googlegroups.com/msg31520.html Not scientific evidence or anything, just my personal opinion/experience. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/dbb007537f3a3cae3b2356ea6df374b2%40disroot.org.
Re: [qubes-users] Recommended laptop?
On Tue, 2019-12-24 at 12:48 +, Claudia wrote: > Personally I would try to avoid AMD systems, why that? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/8137b39c393fd7d7192a72a8620706ae13f4150b.camel%40posteo.de.
Re: [qubes-users] Recommended laptop?
December 24, 2019 9:43 AM, "Ondřej Šulák" wrote: > Hello pals, > > for the last release of Qubes, what laptop would you recommend? Is there any > cheaper option which > does have HW compatibility with latest Qubes (ideally with shipping from EU), > than this one: > > https://insurgo.ca/produit/qubesos-certified-privacybeast_x230-reasonably-secured-laptop > ? > Thanks for any tips! > There are two tested, but not certified, models: Thinkpad X1 Carbon gen 5, and Thinkpad x230. https://www.qubes-os.org/doc/hardware-testing/ In general Thinkpads are usually pretty safe. Personally I would try to avoid AMD systems, as well as consumer models. Look for business class or mid-range hardware where possible, as they tend to have more solid firmware. Look for Intel 4th gen (I think) and newer, as prior generations did not have integrated chipsets. Avoid buying the latest models. Qubes is based on older versions of Fedora and LTS kernels, so look for hardware that has been on the market for at least a little while. Look for models that advertise Linux compatibility or ship with Ubuntu preinstalled, and prefer vendors that tend to have good Linux support, such as Lenovo, Dell, and HP. Other than that, check the HCL, and google around and see what other users have reported. Also search the mailing list for HCL reports, as it takes a long time for them to show up on the website. Above all, make sure you can return it for a refund in case it doesn't run Qubes! Now, all that being said, I recently took a chance on a very cheap consumer-grade Dell Inspiron with AMD, and I have to say I had pretty good luck, all things considered. USB Qube is not supported, and I still haven't gotten suspend/resume to work, but everything else works, and it was a steal for the price. So even going against all recommendations you can still get lucky, it just depends how much risk you're comfortable with and how much trial-and-error you have time for. However, even following all the best practices won't guarantee success on the first try: case in point there are Thinkpads on the HCL with more problems than my cheap Inspiron. Good luck! -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/dccf3314376502a699a313ce2fcca986%40disroot.org.
[qubes-users] Recommended laptop?
Hello pals, for the last release of Qubes, what laptop would you recommend? Is there any cheaper option which does have HW compatibility with latest Qubes (ideally with shipping from EU), than this one: https://insurgo.ca/produit/qubesos-certified-privacybeast_x230-reasonably-secured-laptop/ ? Thanks for any tips! Ondrej -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/5365a450-2aeb-49c0-9015-cb6657e063b1%40googlegroups.com.
Re: [qubes-users] Recommended laptop
On 03/07/2018 03:03 PM, '我' via qubes-users wrote: I decided to buy Lenovo G505s. Thank you very much. The hardware selection tree has become a big help I've decided. Ah you have made a good choice, I hope you have gotten the one with the A10 and the dedicated graphics as it is much faster. It is the freest best relatively modern laptop out there, the novena is freer but it has no IOMMU. In terms of freedom hardware with desktops/workstations/servers you have real options, let me know if you want to get one and I will help you :D -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/e37de087-767f-03ff-5c07-83e6868fad45%40gmx.com. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Recommended laptop
I decided to buy Lenovo G505s. Thank you very much. The hardware selection tree has become a big help I've decided. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/7ROFAgePwqfCsWnQm7uD2zNNDQFFpXCPQ4fcJP-0wk22iFUfs_K19DEGI3nuk_eBAJ4tiH36KgNTR3WxaaPgbUYDlyGGyTri1dy6515oEME%3D%40protonmail.com. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Recommended laptop
On Wednesday, March 7, 2018 at 1:31:11 PM UTC+1, awokd wrote: > On Wed, March 7, 2018 7:46 am, awokd wrote: > > > There's https://www.qubes-os.org/doc/#choosing-your-hardware in the docs > > and FAQ links to same but maybe some type of decision tree? > > Here's my first attempt at one. Links don't work in its current location, > but it should be easy to follow. I'm not entirely sure this belongs on > Qubes' site so I threw in a disclaimer. > > https://github.com/awokd/qubes-doc/blob/hardwaretree/hardware/hardware-tree.md That is pretty awesome project awokd! It'd be amazing if you can finish and polish it, it's definitely very useful work. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/a54f5695-49eb-4543-97c0-f3b20c929e57%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Recommended laptop
On Wed, March 7, 2018 7:46 am, awokd wrote: > There's https://www.qubes-os.org/doc/#choosing-your-hardware in the docs > and FAQ links to same but maybe some type of decision tree? Here's my first attempt at one. Links don't work in its current location, but it should be easy to follow. I'm not entirely sure this belongs on Qubes' site so I threw in a disclaimer. https://github.com/awokd/qubes-doc/blob/hardwaretree/hardware/hardware-tree.md -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/455b28b4f92e2914b3ab9e93b0963c65.squirrel%40tt3j2x4k5ycaa5zt.onion. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Recommended laptop
On Wed, March 7, 2018 7:30 am, 799 wrote: > Am 07.03.2018 8:21 vorm. schrieb "'awokd' via qubes-users" < > qubes-users@googlegroups.com>: > > If using Coreboot instead of Libreboot aren't their better options than > the G505s which seems to be a consumer device. Libreboot is different than Coreboot because it insists on no Intel ME/AMD PSP and no blobs. A corebooted G505s is the only R4.0 capable laptop I've been able to find that still contains no form of ME/PSP, although it does need a couple blobs. The chiclet keyboard and glossy screen are pretty unpleasant, though. > As the question "what should I buy?" seems to be common, is this in the > FAQ? Maybe also with some more details regarding Stock ROM vs. Coreboot vs > Coreboot + ME_cleaner vs. Libreboot? There's https://www.qubes-os.org/doc/#choosing-your-hardware in the docs and FAQ links to same but maybe some type of decision tree? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/3a2a2fead515d79e150a8bc03faa7a7a.squirrel%40tt3j2x4k5ycaa5zt.onion. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Recommended laptop
Am 07.03.2018 8:21 vorm. schrieb "'awokd' via qubes-users" < qubes-users@googlegroups.com>: > If you aren't concerned about owner control, check > https://www.qubes-os.org/hcl/ for other laptops reported to work with 4.0. Should add that if you go with a G505s, please be prepared to flash it with Coreboot yourself. It will need an external SPI programmer. If using Coreboot instead of Libreboot aren't their better options than the G505s which seems to be a consumer device. As the question "what should I buy?" seems to be common, is this in the FAQ? Maybe also with some more details regarding Stock ROM vs. Coreboot vs Coreboot + ME_cleaner vs. Libreboot? [799] -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/CAJ3yz2vx7WC3jxM2zbC6-0nQgEO_co8dx3343JF3zKpYAHZuEg%40mail.gmail.com. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Recommended laptop
On Wed, March 7, 2018 7:11 am, awokd wrote: > On Wed, March 7, 2018 6:27 am, '我' via qubes-users wrote: > >> Hello. >> >> >> >> I installed Qubes3.2 on my MacBook 2009 late. But I could not use WiFi. >> So I want to buy a new laptop for qubes4. What laptop is recommended? >> >> >> >> How about libreboot T400? >> https://minifree.org/product/libreboot-t400/ >> > > Libreboots are nice but Qubes 4.0 can't run on them. It needs newer CPU > features: > https://www.qubes-os.org/doc/system-requirements/#qubes-release-4x. The > only laptop that comes close to the Libreboot level of owner control and > still has the capability to run Qubes 4.0 is a Lenovo G505s. There are > other A10-5750M laptops out there but they haven't been tested with > Qubes. > > > If you aren't concerned about owner control, check > https://www.qubes-os.org/hcl/ for other laptops reported to work with 4.0. Should add that if you go with a G505s, please be prepared to flash it with Coreboot yourself. It will need an external SPI programmer. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/b9242154a37fb7ba0885532644ac996e.squirrel%40tt3j2x4k5ycaa5zt.onion. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Recommended laptop
On Wed, March 7, 2018 6:27 am, '我' via qubes-users wrote: > Hello. > > > I installed Qubes3.2 on my MacBook 2009 late. But I could not use WiFi. > So I want to buy a new laptop for qubes4. What laptop is recommended? > > > How about libreboot T400? > https://minifree.org/product/libreboot-t400/ Libreboots are nice but Qubes 4.0 can't run on them. It needs newer CPU features: https://www.qubes-os.org/doc/system-requirements/#qubes-release-4x. The only laptop that comes close to the Libreboot level of owner control and still has the capability to run Qubes 4.0 is a Lenovo G505s. There are other A10-5750M laptops out there but they haven't been tested with Qubes. If you aren't concerned about owner control, check https://www.qubes-os.org/hcl/ for other laptops reported to work with 4.0. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/eca7ee5bc26b743bc4841db47ff1c48a.squirrel%40tt3j2x4k5ycaa5zt.onion. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Recommended laptop
Hello, Am 07.03.2018 7:28 vorm. schrieb "'我' via qubes-users" < qubes-users@googlegroups.com>: Hello. I installed Qubes3.2 on my MacBook 2009 late. But I could not use WiFi. So I want to buy a new laptop for qubes4. What laptop is recommended? How about libreboot T400? https://minifree.org/product/libreboot-t400/ My suggestion would be get a Thinkpad, which is on both "compatibility lists" (HCL - Hardware Compatibility List) 1) Coreboot HCL https://www.coreboot.org/Supported_Motherboards 2) Qubes OS https://www.qubes-os.org/hcl/ As you haven't provided any information what you want to do on your Laptop and which form factor and battery runtime is right for you, nobody can give an advice. What are your requirements? As always in live it's about finding the right trade-off. I have two Laptops, one 12" with Core i5 and 16GB RAM, working WWAN and a very long battery runtime and a 15" with Core i7 / 32 GB RAM and a 3K-Display. Using the 12" much more and haven't run into any performance issues. Only recommendation: if possible grab 16 GB RAM, feels right. [799] -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/CAJ3yz2vXQLCV-Hj82%3DKskTQ14QNGK3OinU%2BcbXpv_6b93WTGiQ%40mail.gmail.com. For more options, visit https://groups.google.com/d/optout.
[qubes-users] Recommended laptop
Hello. I installed Qubes3.2 on my MacBook 2009 late. But I could not use WiFi. So I want to buy a new laptop for qubes4. What laptop is recommended? How about libreboot T400? https://minifree.org/product/libreboot-t400/ -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/vsdsXaDLVvPcY8fFeehie2jhAx-44KqKgYv3rzKp2aXVYtnF5O-XdvkgB9DYIvmgW1nQvLhVOZQvNZFfrrOie_v9eS5TvSBSY4VPoZ_YcmY%3D%40protonmail.com. For more options, visit https://groups.google.com/d/optout.