Live data from Hacker News

Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

qubes-os.org

31–40 of 104 posts

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#31

Another example for why system() is so dangerous to use. I also don't understand why it needs to show the dialog in dom0. If you have the option to handle attacker controlled input on the unprivileged side, you should do that instead of putting a lot of logic on the privileged side.

> why it needs to show the dialog in dom0 I think it's the "secure screen" that cannot be manipulated by the malware in a VM. I'd expect a password entry dialog to also be handled like that.

If you're going to put the graphics and NIC into separate VMs, surely the secure screen can be another of those semi-privileged VMs rather than part of dom0

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#32
post #14

Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582

[flagged]

It has? News to me. Go on any major thread on this page, you’ll witness similarly strong pushback visa-vi buying into corporate backed hype, akin to the overconfidence in virt security he pointed at back then.

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#33
post #21
post #14

Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582

All I see is rudeness, insults, and arrogance sparkled with inklings of technical arguments. Worthless.

But, and this is the important part, is he wrong?

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#35
post #21

Earlier quoted context omitted.

All I see is rudeness, insults, and arrogance sparkled with inklings of technical arguments. Worthless.

But, and this is the important part, is he wrong?

I don't really know as the argument is mainly about how stupid people are... The technical argument is one paragraph ended with an insult, not much to make an educated and civilized opinion.

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#36
post #21

Earlier quoted context omitted.

All I see is rudeness, insults, and arrogance sparkled with inklings of technical arguments. Worthless.

But, and this is the important part, is he wrong?

What if that isn’t the most important part

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#37
post #10

Wow, this is serious. Makes you think, that even though QubesOS attack surface is so tiny (well-designed to be secure) there are still vulnerabilities to be found. Worth noting that (as I understand) this vulnerability occurs only when doing copy-to-VM from Dom0: >Note that the VM variant of `qvm-copy-to-vm` is not affected, as its version of the error reporting function does not use `system()`: Since you should not…

You are right, copying to dom0 is not best practices and warned against since anno dazumal, but given the user groups I remember not always being technically minded (journalists, dissidents, etc.) and ensuring qubeses isolation holds even when users do things they are discouraged from has always been part of the philosophy. Don’t trust users, don’t trust userland, don’t trust software and all that yazz.

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#38
post #26
post #14

Reminds me of Theo DeRaadt again: https://marc.info/?l=openbsd-misc&m=119318909016582

I feel that, in fairness, one should at least read Adam’s response, though ideally all subsequent mails: https://marc.info/?l=openbsd-misc&m=119320496730314&w=2 Theos is a very opinionated and not necessarily wrong position, but I feel also a bit too reductive given we are eternally having to deal with compromises of some form. Also, lest we forget, it has been two decades in the interim and oh so much has changed. I…

That's an impressive amount of maturity and composure Adam demonstrates there after receiving a response like that.

Re: Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel

#39
post #32

Earlier quoted context omitted.

[flagged]

It has? News to me. Go on any major thread on this page, you’ll witness similarly strong pushback visa-vi buying into corporate backed hype, akin to the overconfidence in virt security he pointed at back then.

Vi doesn't require a visa but the trip is one way only. (Vis-a-vis)
Post reply on HN