[prev in list] [next in list] [prev in thread] [next in thread] 

List:       qubes-users
Subject:    Re: [qubes-users] Thinkpwn?
From:       Andrew David Wong <adw () qubes-os ! org>
Date:       2016-08-14 7:43:39
Message-ID: d7c3efc9-a97d-08cc-6a11-2a47bcdb882b () qubes-os ! org
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 2016-08-13 20:57, eliwu@tutanota.com wrote:
> Maybe this is a dumb question, but I can't seem to find any threads here on
> thinkpwn on the qubes group. Should we be turning off our thinkpwn'd
> computers off until there are bios updates to correct thinkpwn? 
> Specifically, if we have... single boot qubes? dual boot with some other os
> (windows / osx)?
> 
> Lastly, perhaps more importantly, once a computer has been thinkpwn'd, is
> there any way to check? In other words, is it no longer safe to buy a used
> computer with which to run Qubes off of (in case it has been breached by
> thinkpwn)?
> > From my understanding, even if you swap out the hard drive and change the
> > os, the malicious software survives.  That is huge, no?
> 
> There is a laymen's guide on github.. I am sure that every first-world
> nation (and at the very least the cryptolocker people--they made millions
> in two months last year) have ten to twenty people working on honing out
> the exploit.
> 
> Toss the old computers, or am I being too paranoid?
> 

Joanna tweeted about this on 2016-06-29:

"BTW, as @QubesOS isolates apps, networking, USB, etc away from UEFI
interfaces, this attack should not be a problem."

https://twitter.com/rootkovska/status/748122429235552256

- -- 
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJXsCEpAAoJENtN07w5UDAwQhwQALTnKPDrxFOAhqFoE2OWnPDW
OlUrdJEe2CeDRwIHHyXkx23U+EyXF3VcOAVDFKBD5wXOUSGH64AAG4J5uwD1Efsu
3e+YDx/Z8tw5AI1JjO+MnwdYnS+sgmQn9h1OrojBboS1bFqkftV3P/kSJ5kSdaas
x98apg4dWL+E59qZqA6KONpPjxfLc6uoQfu9wIPUX9vg1QQa/fH178gJJwsfnLbN
zvg/LAWWP3XsdRfqKm4D41Lnj2BHu/hUjSXfNZPELJAgXhTvJdQ2U/eSGxmjZ5Fy
oeEsEXbGtsyzyS7nL3qB4kHHBmGNU0oirl1v1DRc2LbiFBEVCFuShcw0XUwqrgpR
KdEgkpHfkyoxVPhZAY6Ma7yJR7vTrmNfLhCPyP8flwH02/5FG1BMkNe+VyMmfDpz
vRLgP4kg0PRub9qfQDf1NNgGTrL3cKAGbPAxEzpsvxS69lDaBXxvgUSaOXW14EnI
ufqnT3lv83eNabLUXnkl6Oz8pg6tAmBJV44gCM0LKrrKYlzu2iGL4iyKNgUZ1Cgb
4Ds9l471cbzeztCwmFYKeWo40cSrILtbRcTFXGmIAGHEvZsVUwbJIoyMLbAxPvhv
dhiZKQNH3jhYJSBWOZGlxtdXDcq3OsqCZPEhLmn2uibFVspU2JlGXTJ/H1kYSxlo
QOtEvn9Xb+JXkoLDB9Pz
=Jm16
-----END PGP SIGNATURE-----

-- 
You received this message because you are subscribed to the Google Groups \
"qubes-users" group. To unsubscribe from this group and stop receiving emails from \
it, send an email to qubes-users+unsubscribe@googlegroups.com. To post to this group, \
send email to qubes-users@googlegroups.com. To view this discussion on the web visit \
https://groups.google.com/d/msgid/qubes-users/d7c3efc9-a97d-08cc-6a11-2a47bcdb882b%40qubes-os.org.
 For more options, visit https://groups.google.com/d/optout.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic