PS/2 keyboards are considered secure and natively suitable to operate on Qubes OS. However, PS/2-enabled keyboards are seldomly used on native household computers, given the lack of PS/2 ports. Therefore the USB keyboard is enabled and plugged into Dom0 by default, as an alternative. Given the potential USB-induced security risk, can we say that the security has been de-facto broken by this? What are Qubes OS experts’ and developers’ opinions on this?
The logic like this topic’s is completely wrong and reversed.
You are not buying hardware then deciding to install Qubes OS. It’s completely the opposite: you are deciding to install Qubes OS and only then you are going to buy the hardware.
You are not buying hardware then deciding to install Qubes OS. It’s completely the opposite: you are deciding to install Qubes OS and only then you are going to buy the hardware.
Unless you are switching to Qubes. If you have Qubes before, and want to upgrade your hardware (and half way know what you’re doing) then yes. Otherwise, and this should be true for most newcomers to Qubes, no.
Your argument is completely unrelated to my point. We were all newcomers at some point, and were switching to Qubes at another.
What you are suggesting might be, actually, quite dangerous: I am reading you are saying it is completely OK to switch from Windows to Qubes OS on the same hardware. Wow!
This is how I did it, when I was a newcomer: Studied Qubes. Decided to install it. Looked for a specific hardware. Sold my Windows machine. Added what was needed to be added to by new hardware. Switched to Qubes OS.
Any other approach then this should come with huge, flashy DISCLAIMER stickers.
Regarding USB keyboard and mouse - reduce your surface of what to trust in. Buy simple as old as possible PS/2 to USB adapter, buy PS/2 mouse and keyboard and you don’t have to worry anymore on them, by putting your trust to no-one-ever-messed-with-that adapter, hoping that since it is so old, back in the days most probably those weren’t still interesting enough to hack. Now you have the luxury to break mouse and keyboard each week if you want with your mind on ease. Just buy new ones, all PS/2.
My intention was to imply that I think this is the most common path for qubes newcomers. They do not understand Qubes / security, google “super secure desktop OS” and then “try it”. Which is far better than not trying it.
Also if you are implying that if windows was compromised before switching, then the only viable approach to continue using qubes after a compromise is to buy new hardware (which actually would be the correct approach, but it is unlikely most people can afford it). I’d also like to add that compromises, be it with windows or Qubes or whatever, commonly are not noticed. Although with windows you may notice if the box gets slow due to crypto miners x)
This is how I did it, when I was a
newcomer: Studied Qubes. Decided to install it. Looked for a specific hardware. Sold my Windows machine. Added what was needed to be added to by new hardware.Switchedto Qubes OS.
That is admirable, and an excellent way of switching, but I highly doubt it is the most commonly chosen way.
Any other approach then this should come with huge, flashy DISCLAIMER stickers.
Correct, but that doesn’t change the way an enduser will approach switching. And installing Qubes on a previous windows machine is still better than windows.
I am sad to read doubling down, although your points were perfectly clear in your previous post, already,
Deciding and trying are different things.
What is there to try in Qubes at all?
About common thing. It is also common way people crossing the street out of zebra crossings. Saying “it is still better to (try to) cross the street than not to (try to) cross it” is completely unrelated to the question of safety of crossing the street.
You either need/decide to cross the street or not. You are not trying to cross the street. Nothing to try there.
This all screams the lack of a threat model. I won’t flood the topic anymore.
Is having a malicious PS/2 firmware (keyboard or mouse) possible? I don’t see why not.
Given the potential USB-induced security risk, can we say that the security has been de-facto broken by this?
Only if the firmware/driver is malicious.
There are FOSS things you may be interested to have a look at:
What are Qubes OS experts’ and developers’ opinions on this?
If they allowed USB keyboards on dom0, they obviously don’t consider it a game-over thing.
You should probably be more concerned about USB network adapters.
Also if it was tampered with by, e.g., another malicious USB device.
See also: Device handling security — Qubes OS Documentation
Obviously, if you have a USB keyboard, you have no choice except to trust it. It doesn’t automatically protect you from the game over though.
PS/2 firmware cannot be reprogrammed.
PS/2 device cannot pretend it’s something else.
PS/2 device has limited functionality,
PS/2 device has much, much smaller attack surface.
PS/2 can be bought with a safe firmware,
You can buy safe USB device. Plug it in to a poisoned controller, it’s not safe anymore.
That cannot happen with PS/2 device.
Once you are sure it’s safe, it will be safe forever while in your possession only.
That’s why it is considered as a safe option.
I will not continue this discussion to fulfill curiosity, or to reply on doubling down.
The problem is that there are few computers in the market with PS/2 ports. Typical users can only choose to buy PCs with USB ports.
Is it possible to, say, register my keyboard’s MAC or unique identifier into the machine, so that QubesOS can recognize it in the first place and give access to it (no access for any other devices otherwise)?
Identifiers can be spoofed.