Live data from Hacker News

Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

qubes-os.org

11–20 of 104 posts

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#11
I do really like the following in the bulletin:

> Important: At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The standard method is to obtain the QMSK fingerprint from multiple independent sources in several different ways and check to see whether they match the key you just imported. For more information, see How to import and authenticate the Qubes Master Signing Key.

It looks like Qubes is ran by people who take security seriously, which is refreshing.

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#12
post #6

I am still impressed by QubesOS track and I use it for my dedicated 'financials' laptop. IMHO the thing that is holding back QubesOS is the lack of hardware acceleration for graphics - maybe now when dual monitor setups are getting popular this could be a workaround for the security considerations?

Problem is not that nobody wants to do it, it is that GPU stack is exactly the kind of enormous driver surface Qubes exists to keep away from dom0. Second monitor does not really change that, somebody still has to trust the driver.

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#13

I do really like the following in the bulletin: > Important: At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The standard method is to obtain the QMSK fingerprint from multiple independent sources in several different way…

How well is QMSK protected from a serious attacker?

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#16
post #14

Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582

Theo is a very insightful guy, but also very opinionated. I think the truth is somewhere in between.

Especially as more and more virtualization functions move into hardware, not using them as a second security barrier seems foolish.

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#19
post #14

Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582

Brutal

I hope when people read this though they understand this is a communication style; they're clearly trying to strongly discourage people from thinking they are suddenly protected. Effective? Maybe at one time, where "macho dev energy" was a thing. Today, not so much. You can tell they mean well because the intro sentence is actually pretty cheeky!

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#20
That is sphincter tightening to read. Have to point out how amazingly well their bulletins handle communication. Clearly describes the issues, how users are to act, etc. in, what I feel, is an easy to grasp language, even if one’s not in the weeds that much. In fairness though, I do still have some past memories concerning Qubes architecture from way back, so maybe my assessment is wrong and this is still not that straight forward to grasp for most.
Post reply on HN