Split-scan setup using Salt

Split-scan setup for Qubes OS using Salt

This project provides a split-scan setup for Qubes OS, similar to the other split setups. You can apply it using Salt. If you are not familiar with Salt, the files should still be relatively easy to understand, allowing you to apply the configuration manually.

Link to the project: GitHub - PhysicsIsAwesome/qubes-split-scan: Split-scan setup for Qubes OS via Salt · GitHub

Split-scan creates a client-server architecture for scanners.

Scanners get connected, installed and set up only in the server qube. It does not matter whether usb, network or other scanner type.

Multiple clients can then connect to this server qube via qrexec to use this scanner, even offline qubes. Since only the server qube needs direct access to the scanner, clients don’t need usb, network or other access to use the scanner and also don’t need hardware-specific software installed, like hplip.

Scanner access gets mediated by qubes policy rules, respectively looks for the tag scan-client, for which a rule in above repo is already implemented.

1 Like

Could you explain what this does? Is this for network scanning? It’s really hard to tell.

2 Likes

@Another1 I have added a better description.

3 Likes

Thanks for the reply. It seems to me that it is still safer to scan files in a dedicated qube and then copy the results to other locations using qvm-copy and perhaps sanitize them. I’m saying this because other split mechanisms increased security, but here it seems lower.

A dedicated, disposable scanner qube without split-scan might indeed be more secure. The question is how much, and is it worth the additional inconvenience?

Are you sure they all do? Just a few examples:

is it safe to expose cups to other qubes like in split-print, considering the security history of cups?

Is it safe to expose keepassxc IPC in a split-keepassxc setup? Has the IPC mechanism between the browser extension and the keepassxc desktop app been designed with being a security boundary in mind? Wouldn’t it be more secure to have several small keepassxc files each in the qube where they are needed, so you don’t have to trust keepassxc IPC to keep your passwords secure? How convenient would that be with all the small databases, especially, if you want to sync your keepassxc passwords to other devices like your smartphone, so you can use it there?

2 Likes

Thanks for the explanation. I spoke too soon. You’re right that split setups may involve a tradeoff between security and convenience.

What do you mean by “scanner”? Do you mean devices like these: