Does anyone happen to have a buidroot definition for encfs package (for Raspberrypi)?

(In case you wonder why I like encfs? Because it's the only cross platform fs-based encryption (so perfect for using over Dropbox) for which there is also an iOS app available (Boxcryptor Classic).)

Qubes Security Bulletin #31: Several Xen bugs, practical impact unclear (XSA 216-224):

t.co/l2ZjcCOGRf

Congrats to the Xen Team for finding most of the bugs and to Jann Horn of Google Project Zero for the remaining two!

No busques más, esta es toda la dulzura que necesitarás hoy

Here's my quest for a project planning & tracking software:
github.com/QubesOS/qubes-issue

Some features I want:
1. Decompose projects into sub-projects, & further down,
2. Balance incomes & expenses,
3. Dependencies which can span multiple projects,
4. Take declarative description of projects, tasks, deps, people's availability, various constrains, etc,
5. Calendar-time and resource limitations aware.

So far TaskJuggler seems best, anything better/similar?

Organizations all over the world should DEMAND from Intel ability to disable ME/AMT code. For good. There are likely many more bugs there.

Intel should provide means to disable all ME code which runs AFTER host CPU init is complete, i.e. all the UNTURSTED-input processing code.

Intel AMT drama: Show more

A book about Mind, disguised as treatise on Formal Systems and Reasoning, camouflaged as work on Beauty, ultimately talking about Mind... ❤

Qubes Security Bulletin #30 for another critical Xen bug(s) in PV memory virtualization (XSA 213-214): github.com/QubesOS/qubes-secpa

The bugs were found by the same researcher who found the previous Xen bug (XSA 212): Jann Horn of Google P0, congrats!

Also, please read our commentary in the bulletin (linked above) about the general defense approaches we've been working on for Qubes 4.x.

Infosec ethics/drama Show more

Turned out that the phrase "Plan B" has a special connotation in the US (a day-after contraception pill), which I wasn't aware before . One of the US-based devs pointed this out and we're discussing how/if to change the option name and to what alternative (needless to say some users didn't like the "paranoid" name either):
t.co/0YBigxAH0V

I guess Qubes OS is getting ever more mainstream... :)

New post: "Compromise recovery on Qubes OS":
qubes-os.org/news/2017/04/26/q

Because fuckups happen... and it's good to have a reasonable Plan B.

I really like draw.io, a free Visio alternative, which also works fine in *offline* mode as a Chrome app (I tested it in offline VM).

But it would be even cooler if there was an easy way to package Chrome Apps as RPM or DEB, as then it could be easily installed in a template VM for use in many different AppVMs. Anyone knows how to do that?

(The diagram below is for an upcoming post on Qubes Compromises Recovery, BTW)

I did a write up for the Hamburgsides keynote I did last year - 'The Mighty Superpowers of a well-established "Us"', about BlackHoodie, why XYZ-only workshops make sense, why otherness is an issue and about how-to Padawan 0x1338.blogspot.de/2017/04/the

@rootkovska @tl @micahflee @gnome @federicomena

Thanks for the kind words about GNOME!

This might be a good start: github.com/flatpak/flatpak/wik

Some major threat surface I see today is Wayland API (good), pulseaudio (bad), GL drivers (ugly).

The intention is to use portals (dbus) instead of dev access for most things. This is how you get file access despite no $HOME in the mount namespace. The file chooser, for example, is out of process then fd pass.

Have fun planting virus signatures in strange places that touch remote disks somehow/somewhere.

Example:

Change your mail sig to:
X5O!P%@ap[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

Or send it in a browser var, as a password (quickly find the sites that don't encrypt passwords), send to open syslogs, etc.

The some AV actually delete/quarantine the file (weblogs, mailspool, {u,w}tmp etc.)!

What are your ideas?

Inspired by: sec.cs.tu-bs.de/pubs/2017-asia

Show more
Mastodon

Follow friends and discover new ones. Publish anything you want: links, pictures, text, video. This server is run by the main developers of the Mastodon project. Everyone is welcome as long as you follow our code of conduct!