Qubes OS could be honeypot?

Until you offer a viable alternative I am pretty much compelled to accept this approach as “good enough”.

Neither do Qubes support “confidential computing” with untrusted hypervisor. Why? Because it is enormously complicated task for a desktop system and we have usability issues already, being a small bunch of geeks never accepted by mainstream dekstop community for variety of reasons. And it is ok. What do you expect? Feel free to throw in $20-30M for improvements, we certainly could find a good use for this investment.

8 Likes

Unman, I send you PM 3days ago.

At the moment:
Something going wrong with my clean installation from last 24h:

  1. Global settings change themself or not saved, for example error indicated under USB devices that any type of USB device allowed to connect dom0 while settings on “disable”.
  2. fedora-42-minimal and update qube start by themself few times without any reason (updater was inactive)
  3. fedora-42-minimal arrive from repositories with extra packages, for example samba that known for his vulnerabilities.

(should we move to “are they hack me” or PM?)

chuckles

This made me sign up and its equal part charming and disgusting what people write in response to low effort paranoia rants.

2 Likes

Numerous organizations serious about security use Qubes OS. Most security experts say good things about Qubes and recommend it. That’s more relevant.

1 Like

Is any result of your story?
Please, tell to us

1 Like

+1
I really wan’t to share my disk with public
But i can’t normally work for few years
And i can’t see another way
I check all my connections, dump traffic, check all logs, check all syscalls, check all file hashes, sometimes check libs in memory dumps. Attacks is like from air
I have no space with all bu’s and dumps

First time i think it’s after Joanna’s leave. But last time think it’s whonix repos troubles, because i no hear about any case without whonix. For one hand it’s expected correlation, but seriously, no one case

Hey,
Excuse me, disk was’t shipped to QubesOS team because Israel make me believe they take action on right direction.
Few months after, not only technical but also physical terror action continued. Also, Israel tried to use drugs against me in order to “heal” this crazy, and pass me exams where they try to figure out if I still remember and know the truth.

After that “exam” I was fired from cyber security implementer role at integration company, state honeypot…
And now days look for what to do without work, money and under pressure of state terrorism.

QubesOS feel fine, I hard few things that I know as attack vectors and PC work well. Device that was hacked, was with misconfigurations - without SELinux and apparmor on sys qubes.
Also, I believe that guides that offer save same RAM by using minimal templates without SELinux and apparmor for sys qubes are dangerous for users of our community.

Another thing,
I also targated by smartphone vector, and if we talk about Honeypot - maybe GrapheneOS became an one:


They hide and delete question from end users attacked by spyware… also there is same toxic idiots that troll for such questions.

likely no. but if you are fearful get a pfsense or wireshark configured on an old laptop between your router and the qubesos and log all connections and packets then decrypt for the https using tls keys . i don’t know where tls keys are stored though. you can also analyze the raw unencrypted data yourself if qubes uses http but it does not to my knowledge. you can also try to conduct traffic fingerprinting if you cannot decrypt data.

tl;dr ; didn’t know Q traffic was easy to notice though ; maybe OP could condense the premise or find something objective to even discuss

and security isn’t the only reason to use the excellent Q system , I no longer have to worry about reinstall OS’s because of some fail point, updates, software , etc; it’s also sort of fun

3 Likes

As a citizens we need to create a game theory that revert the honeypot against the state actors and push ordinary citizens cyber defense/attack to the limit. The expected result in criminal proceeding related to cyber should damage to the national security (backdoors), the state need to do a choice between internal security (crime) or external (war).

What do you except from them ?

2 Likes

(To support discussion about honeypot)
It mean that NSA found something more valuable to maintain.

1 Like

How many lines of source code does Xen have?

1 Like

I think Arellanos made the best post in this topic.
But I have read some posts by him and it seems he hasn’t effectively started using and appreciating the power of AI yet.
I think AI is a huge turning point to verifying source code. It’s not as simple as just say “look for vulnerabilities”, but it makes everything 100 times easier and more effective.
AI can also help to create custom software which helps detect a malware in your system.
And AI can also help to investigate what caused the malware.
This means if Qubes OS caused the malware with a malicious package in an update, then thanks to AI, it’s much easier for an average end user to detect that and then warn everyone. The AI can write an informative text which gives the important evidence.

If Qubes OS ever goes through such a scandal, then I think everyone would switch to other operating systems. Qubes OS is not big enough like Windows or Apple to be able to come back from that.

But if we take away AI, then it’s more challenging, and Arellanos dark description is fitting. Then it’s important to be able to make informed decisions if we trust their developers.
He was neutral to not comment if Qubes OS team are trust worthy. But I think the biased moderation that happens shows the potential for a slippery slope that could potentially lead to a compromise, maybe widespread or targeted.
When we’re not allowed to bring up specific evidence of things their team or moderators have done, then that’s also a bad sign.
And ITL, the company that owns Qubes OS, is also centralized. Centralized systems are more vulnerable than decentralized systems.

I think it’s hard to trust any code audits by random community members because I have seen many posts here which show a lack of ethics. I won’t point fingers because its against the rules and unlike some other users, i would get banned for breaking rules.

1 Like

At the risk of inviting more semi-inscrutable stream-of-consciousness corporate AI boosting and backhanded “the mods are feds!! (or something like that!!)” insinuation, who or what is “Arellanos”?

1 Like

It’s the developer of Wonix
:wink:

3 Likes

Define your scope, README.md, .gitignore, and other files technically count as source code.

2 Likes

Having seen how a honeypot or something like that worked in a real business scenario, I can give an example:

An Info-sec organization (probably known here), hired a person who was known to have had training in a foreign military cyber unit. He then started to ‘hire’ or recommend business dealings with other orgs related to his earlier work.

The original org was well known, had a stellar reputation, the founders had solid reputations and unshakable ethics. They were really concerned about privacy, security and open-source solutions.

Well after this new hire (who was kind of forced in there by investors actually) got into a position of relative power and could influence hiring.. Well things started to change in this org without the founders knowing about it, and, to make a long story short this org did turn into a foreign intel collection point, spyware, backdoor org. You would never have known as from the outside the backgrounds, the transparency, the ethics etc… Were unquestionable, it is just interesting how powerful a few people in a few key positions can be. Cases can be like this in a way, the CEO’s or most of the company can not know what is going on.

I would say especially in this field, trust models are extremely important, and questions such as OPs should always be allowed to be asked.

There is sometimes a stigma in this world to even broach this question, as I found out by the looks when I presented this to the board of a company I was contracting with… (It turned out I was right btw.)

4 Likes