Show more

Huge news out of Washington state. King County, which includes Seattle and is home to Amazon and Microsoft, has voted to ban government use of face surveillance. twitter.com/ACLU_WA/status/139

Updated to fix a mistake in my steps: I did not include the cipher used (chacha20) to encrypt/decrypt and while that won't error out in OpenSSL it will result in you not actually encrypting/decrypting data.

Show thread

That scene in The Dark Knight where Batman turns everyone's cellphones into a massive surveillance network, was supposed to be a cautionary tale, not a project roadmap.

Guest Blogger @ajmartinez has written up a great technical guide on how to use Qubes's advanced isolation features on his Librem 14 to manage and store GPG keys securely on a pair of Librem Keys. puri.sm/posts/guest-post-libre

My notes on extending the Qubes OS Split GPG feature to include SSH Agent support:

ajmartinez.com/tech/posts/2021

Now my network-attached qubes no longer have any private keys on disk, and since my subkeys are also loaded on both of my Librem Keys as mentioned in an earlier post, I can still access my remote systems as long as I have one of my physical tokens.

As promised yesterday, here's a walkthrough on using Qubes OS disposable VMs, opensc, hybrid encryption, and USB security tokens (Librem Key) on my Librem 14 to create redundant hardware tokens from the encrypted backup of my GPG keyring:

ajmartinez.com/tech/posts/2021

None of this is groundbreaking, but these steps do not seem to exist in any one document that I could find so I wrote one.

My second (backup) Librem Key has arrived. Tomorrow, I’ll write up how I’m using network-isolated qubes for GnuPG related tasks and how that feeds into making a backup key so the loss of my primary isn’t a major show stopping event.

Building a 4TB RAID1 array over USB2 on slow spinning rust is *hilariously* slow.

Anyone have a USB-C dock recommendation? Needs DP or HDMI 2.0 and some USB3.1 ports. Ethernet would be nice.

Now that cars have become rolling smartphones, it's been pretty disappointing to see them copy some of the worst practices from the smartphone world. I wrote an article that talks about some of those problems. [CW: Tesla negativity] puri.sm/posts/locked-in-a-remo

Another look at my @purism Librem 14 - this time on the battery life front in Qubes OS doing basic tasks:

ajmartinez.com/tech/posts/2021

Managed to hurt my shoulder somehow (being old I guess is enough) but that’s not stopping me from enjoying my vacation.

Somehow, despite many years of international travel and expat assignments, I never noticed that indeed everyone else’s periodic tables do say Aluminium. It’s we Americans doing it wrong, and the hard line I drew in the sand about this manipulation of the name of an ELEMENT was based on a web of lies. This may be as close to an existential crisis as I ever get. I am shook.

First impressions of my new Librem 14 from @purism. In just before I take a vacation inside my vacation!

ajmartinez.com/tech/posts/2021

More to follow in a few weeks once I've had more time on the machine.

The Librem 14 has great battery life and in this post we put it through its paces from low-power idle tests all the way to a torture test that pegs all 12 threads at 100%. Check out this post and video for all of our tests and results: puri.sm/posts/librem-14-runtim

Ran into some trouble with my initial Qubes install on the Librem 14, as apparently changing any options in the disk partitioning unchecks the encryption box and renders it uncheckable. This is clearly a Qubes problem, and not a Purism problem, but it led me down a fun path of reinstalling a dozen times or so. That said, now I’m very well acquainted with PureBoot, my TPM, and my Librem Key.

I’ll work on A Rust Site Engine a bit on the Librem 14 today and see how I like it for Rust development.

Finally got my new Librem 14 with PureBoot setup with Qubes 4.0.4, and restored my qubes from backup. Going from an i5-6300U to an i7-10710U has been great!

Got my first vaccine today courtesy of VA Medical. Shockingly efficient process. Not what I’m used to from VA Med.

Show more
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml