Likely Qubes Compromise - Advice for New Installation

Hi,
Qubes 4.3 appears compromised and I’m trying to figure out how so I don’t repeat the vulnerability.

No IT background, high threat model.

Indicators of compromise:

Documents disappeared from vault where I had stored recovery codes

Looking at bash_history saw that sha256sum was run three times against my Keepassxc passwords.kdbx file. I did not do that (nor did I at the time have any knowledge re: sha256sum use etc). Database has yubikey challenge response

Downloaded a number of apk files for upload to graphene phone. Ran sha256sum with copilot/chatbpt help and verified PGP. Subsequently, when I started seeing anomalies, saw that the modified dates for these files were earlier than the created and accessed dates.

Did deep dive on all this when I noticed that my travel router password had reverted to earlier password and that wireless had been turned on. Had been connecting via mifi to ethernet cable to travel router to ethernet cable to laptop. Laptop only used so far to access email in a separate dvm dedicated to email. Have not seen unknown devices or login in proton sentinel.

So maybe I attached to an evil twin? Could this create these issues? Or USB?

Keepass was in separate vault.

Had another document vault where folder I added from usb was moved to trash and emptied (not by me - but when I look at the folder I see it’s over 50MB but nothing is visible - restored folder maybe those documents are still there)

Have a usb analysis dvm that opens but terminal and thunar won’t load.

Before I noticed that wireless had been turned back on my travel router, firefox in my default dvm homepage changed from fedoraproject.org ot data:… And other dvm qubes firefox changed from fedora homepage ot firefox homepage. I’ve done nothing but update as indicated by the icon top right of the screen. At one point clicking to open a new default dvm nothing appeared.

USB - I have transferred documents to be backed up and at one time to be added to qubes via usb. Attached usb to releavnt qube. And yes I have attached that usb directly to vault at times so maybe that was the mistake/vector?

Use copy to qube in thunar to move documents as needed.

have relied on AI for most of my setup and learning and finally understand enough to read some of the comments here.

Plan to wipe the computer and install qubes 4.3.1. Ideally I’d like to have a heads laptop but if it will just get compromised again not worth the expense.

Any idea how this could have happened? Also I see files “expunged” without my interaction.

Long term highly targeted threat. No safe wifi so use mifi and travel router with VPN on both travel router and laptop.

New to linux so new to qubes. Willing to learn whatever I need to so I can communicate safely Basic office work - writing, reading, research and email .Nothing fancy.

One last questoin - fedora 43-xfce has been updating daily for weeks. Early on it might update every few days. Is this normal?

If you slogged through all of this - thank you!

EDIT: forgot to mention - several days last week closing a disposable qube closed firefox but the qube was still on per the list of running qubes. Then a day or days later looking at Thunar documents I had downloaded to the disposable were still there. Chatgpt, duckai thought might have been from compromised environment/rogue tower since I go online with MiFI. Now disposable qubes shut down as they should again.

Tamper detection is worth the expense, do you want to find out how you were compromised or stay in the dark every single time against your threat model?

How do I get tamper detection? What do you suggest? Thanks so much for the reply!

You already said it yourself, get a laptop supporting Heads. If you want a suggestion, take a look at the NovaCustom NV54 or NV56:

I’ve been in touch with them and read very positive things about them here. Thank you

I posted a few days ago as Qubes7957 about high threat model and potentially compromised qubes laptop and appreciate the responses I got - someone recommended Heads and Nova Custom. I went back yesterday or the day before to ask a follow up question and could not log in/credentials invalid. Plus I can’t find my post. If I somehow violated Forum rules please let me know. If not, pretty clear confirmation that my qubes laptop is compromised -since my forum credentials were in a vault in Keepassxc (prior post mentioned the sha256 commands run on my database that I did not run).

If not, here’s my follow up question.

My understanding is that Heads would alert me re: a firmware change or attempted change but does not protect the computer against compromise. If I had a Heads laptop that did get compromised, would I be able to reinstall Qubes fully and safely as a fresh start? Perplexity tells me that just reinstalling Qubes on this Thinkpad (no Heads) does not guarantee that the malware/compromise won’t persist on the new install.

Also, the forum “your topic is similar to…” is hugely helpful, especially the post about potential router compromise. Makes me wonder if I should be using Whonix/Tor (never used either) to access email rather than firefox in a dedicated disposable email dvm. Would that help with possibly compromised internet access?

Thank you for the help and if my last post violated Forum rules - I apologize!

No, not necessarily, the difference is tamper detection, not tamper prevention.

Thank you. It’s the tamper prevention I’m struggling with. Will keep reading to try to figure out how to prevent a repeat occurence. Appreciate your responses.

You start by understanding your adversary’s playbook. If you do not know the methods they they are using to compromise you, then you cannot make informed decisions to prevent them.

Inappropriate post

Honestly to the OP (and the merged post) I would buy a new laptop and copy all important files by hand since I am that paranoid

If you do not know the extend of your adversary’s skills I assume a rootkit on the ssd/m.2’s chipset or even raw access to the PSP or ME of the cpu and just smash and burn it afterwards lest a poor soul finds it and plugs it in their computer

On the other hand since you are not a techy and these are extremely weird things to happen then we can erase the possibility someone has been drugging you and you have memory

Lastly consider your position in the world at large and in your close social circle, don’t answer these following questions just think about them:

Are you someone that can affect the war in Iran or Ukraine even by a very slight margin?

Are you someone that has financial privileged access to a large company or infrastructure?

Can you turn the balance that would offset the dollar or have access to crypto, tor, i2p or any other network or currency?

Can you affect or cause an effect that would offset political landscape in Europe, Australia, USA , Canada, China, India, Russia or god have mercy on your soul Israel?

Do you have proof that could take power away from a very powerful individual?

Do any of the above apply to your spouse, significant other, a close or distant relative that you keep in touch with?

If none of the above are true then chances are you somehow got compromised by a script kiddie that either god pissed at you online, dislikes you, found you as a random target or think you have a large sum of crypto in self custody, you could be a victim that doesn’t update their computer often or otherwise

One thing to note recently we had both a xen vulnerability that affects qubes and a bunch of Linux vulnerabilities that could be used for lateral movement, if you haven’t updated for a while you might have had an infected or open router someone used for lateral movement to you, it could very well be neighborhor, someone else targeting you for a while that parked a drone in your roof etc etc

My advise is as follows: buy the most recent AMD based laptop you can find

Lastly and I know this might be taken as an offense and I am sorry but there could be a chance your family tree has the schizotype genome, try cutting out gluten completely, other brain affecting drugs like modafinil, marijuana, nicotine(it supposedly protects the brain of schitzotypes but it actually just blurs the effect so it hides the symptoms, so it could potentially make it much worse since you have less control of your mind), start fasting with no food for a few days to clear your mind from brainfog, or much worse you might have a heavy Gurdjieff type imbalance/insanity taking place if this theory stands, my highschool best friend has a schitzotype genome and 99% of people would never even guess even if he is in his 30s now, a curious mind about the world stops the degradation and reverses it to something greater really

Since I cannot edit my comment ilill make a new one to insert my edit

“”"

Edit was that really inappropriate? I am sorry it’s the questions I usually ask when someone has security problems I cannot audit myself and must keep respect the other person’s privacy

I thought me stating “dont answer the followig statements” was good enough? Mods pm me for the specific inappropriate instance

“”"

maybe the last paragraph was not needed. but otherwise great advice.