Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-09 Thread sevas
I couldve sworn I replied to these... Well, thanks to everyone who put their 2 cents in! There is some stellar advice in here! Im going to have to go back later and read this whole thread and write down bullet points... Heres what I have so far. Templates 3 catagories. 1) original

Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-08 Thread Steve Coleman
On 03/07/18 15:05, sevas wrote: Cool. That gave me some ideas. Thanks for sharing your setup. So, another infosec question Im trying to figure out... Templates Vs AppVMs. I find that I separate my Templates based on two criteria. What I want to limit access to, and what I do or do not

Re: Qubes and Email/PIM (Was: Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-08 Thread Yuraeitha
On Thursday, March 8, 2018 at 7:49:13 PM UTC+1, steve.coleman wrote: > Glad to hear I'm not the only one paying attention to this particular > attack surface. There is nothing like a wide open 24x7 automated attack > surface to keep you up at nights wondering what web exploits will be >

Re: Qubes and Email/PIM (Was: Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-08 Thread Yuraeitha
On Thursday, March 8, 2018 at 2:55:18 AM UTC+1, [ 799 ] wrote: > Hello, > > > > Am 06.03.2018 10:04 nachm. schrieb "Steve Coleman"  > Because the SMTP infrastructure was not designed with compartmentalization in > mind, and I only get my one email account to work with, this single "email" >

Re: Qubes and Email/PIM (Was: Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-08 Thread Steve Coleman
Glad to hear I'm not the only one paying attention to this particular attack surface. There is nothing like a wide open 24x7 automated attack surface to keep you up at nights wondering what web exploits will be discovered next by the hacker community. Even with layers of security well before

Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-08 Thread Mike Keehan
On Wed, 7 Mar 2018 12:54:17 -0800 (PST) Yuraeitha wrote: > > > I would love to hear how you divide your VMs up. I was looking for > > examples online, but I couldnt find any; aside from an (ITL?) essay > > I read last year. But starting easy and growing is good advice. >

Qubes and Email/PIM (Was: Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-07 Thread 799
Hello, Am 06.03.2018 10:04 nachm. schrieb "Steve Coleman" Because the SMTP infrastructure was not designed with compartmentalization in mind, and I only get my one email account to work with, this single "email" VM is highly isolated. It gets its own software locked down configuration and is

Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-07 Thread Yuraeitha
On Wednesday, March 7, 2018 at 9:05:51 PM UTC+1, sevas wrote: > Cool. That gave me some ideas. Thanks for sharing your setup. > > So, another infosec question Im trying to figure out... > > Templates Vs AppVMs. > > I find myself with, currently, 8 templates and growing. > This is because I

Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-07 Thread Yuraeitha
On Wednesday, March 7, 2018 at 9:05:51 PM UTC+1, sevas wrote: > Cool. That gave me some ideas. Thanks for sharing your setup. > > So, another infosec question Im trying to figure out... > > Templates Vs AppVMs. > > I find myself with, currently, 8 templates and growing. > This is because I

Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-07 Thread 'awokd' via qubes-users
On Wed, March 7, 2018 8:05 pm, sevas wrote: > Of course, one solution is to install all my programs into a single > templateVM and only enable the programs I need in the AppVM. > > But it seems more secure to me if I keep different templates for > different needs and then create a AppVM to run

Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-07 Thread sevas
Cool. That gave me some ideas. Thanks for sharing your setup. So, another infosec question Im trying to figure out... Templates Vs AppVMs. I find myself with, currently, 8 templates and growing. This is because I am installing different programs in different VMs and Im not wanting to install

Re: [qubes-users] Re: Security questions (templates and kde)

2018-03-06 Thread Steve Coleman
On 03/06/18 13:42, sevas wrote: I havent quite tackled the security through compartmentalization part yet. I have put some thought into it though, and after dividing my attack surface between functions (keyring, passwords, misc files, etc) I realized that each function has only one app to