Show more

@ademalsasa both of my personal laptops run Qubes OS and have for quite a while. I’ve got other systems on Fedora and Debian, but the bulk of my development and security work is done on qubes based on the same distros.

Now my old laptop, a T460s, has a kali-rolling Qubes OS template VM with the tools I fancy for testing/investigating. At 17GB it’s the largest template I’ve ever made, but I’ll base a DispVM off it and likely a few normal qubes as well with configurations suited for specific roles. A few posts about what I do, and how, will happen eventually.

T460s running Qubes OS compiles A Rust Site Engine v0.9.0 in 3m15s. Librem 14 configured the same way does it in 1m20s. This is a full release build with flags for crt-static. Not mad about that at all. Now to wipe the T460s and prepare it for other duties.

Sometime this week I’ll be tweaking some Qubes stuff so my UI adapts between my Librem 14 being used with its onboard 1080p panel or my external 2160p.

org.Gtk.MountOperationHandler support coming to so you can open encrypted volumes with swipeable, modal dialogs

@purism

And now we’re at IAH waiting to board. Flights have many more passengers now than they did in any of the other months I’ve flown during the pandemic.

Show thread

Heading back to The Netherlands tomorrow. Enjoyed not working at all for a month and getting to see my family and friends. Slightly terrified by what my inbox may hold, but I won’t check until I’m on the clock again.

A Rust Site Engine v0.9.0 is out - adding a route for favicon.ico and redefining the roadmap. Cache is out, RSS feed is in. At this point I've been running my personal site on ARSE for a month and have been pleased with how it's working.

crates.io/crates/arse

Snagged a BatPower P120B USB-C PD charger, and a VAVA VA-UC020 8-in-1 USB-C hub for my and so far so good. I have not even looked at what might be needed to use the HDMI port in Qubes, but the power pass through and data ports all work great.

Huge news out of Washington state. King County, which includes Seattle and is home to Amazon and Microsoft, has voted to ban government use of face surveillance. twitter.com/ACLU_WA/status/139

Updated to fix a mistake in my steps: I did not include the cipher used (chacha20) to encrypt/decrypt and while that won't error out in OpenSSL it will result in you not actually encrypting/decrypting data.

Show thread

@kyle very nearly every piece of ubiquitous technology was either created or modified for increasing the efficiency with which war is waged.

That scene in The Dark Knight where Batman turns everyone's cellphones into a massive surveillance network, was supposed to be a cautionary tale, not a project roadmap.

@kyle what did you have? Eating inside!!! A distant memory.

Guest Blogger @ajmartinez has written up a great technical guide on how to use Qubes's advanced isolation features on his Librem 14 to manage and store GPG keys securely on a pair of Librem Keys. puri.sm/posts/guest-post-libre

My notes on extending the Qubes OS Split GPG feature to include SSH Agent support:

ajmartinez.com/tech/posts/2021

Now my network-attached qubes no longer have any private keys on disk, and since my subkeys are also loaded on both of my Librem Keys as mentioned in an earlier post, I can still access my remote systems as long as I have one of my physical tokens.

@randynose @kyle many likely are still waiting for the year of LoTD to arrive though some of us have been doing it for more than a decade. The set of things released and then killed by Google is impressive. Only time will tell if Fuschia makes it on that list.

As promised yesterday, here's a walkthrough on using Qubes OS disposable VMs, opensc, hybrid encryption, and USB security tokens (Librem Key) on my Librem 14 to create redundant hardware tokens from the encrypted backup of my GPG keyring:

ajmartinez.com/tech/posts/2021

None of this is groundbreaking, but these steps do not seem to exist in any one document that I could find so I wrote one.

Show more
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml