←back to thread

441 points ploggingdev | 8 comments | | HN request time: 0.001s | source | bottom
1. notfed ◴[] No.15735828[source]
Note that while Qubes OS uses full-disk encryption, it runs on Xen, which does not support hibernate.

This means that, if you use this OS on a laptop, you'll be vulnerable to cold-boot attacks, even after you close your lid, unless you configure it to shutdown on lid close. (I.e., if a highly skilled adversary steals your laptop then, even if your laptop lid is closed, they will be able to read your RAM and therefore decrypt your entire hard drive.)

Despite the major security implications, it doesn't sound like a fix will be implemented any time soon. [1]

[1] https://github.com/QubesOS/qubes-issues/issues/2414

replies(2): >>15736066 #>>15736180 #
2. bearbearbear ◴[] No.15736066[source]
If a highly skilled thief wants to break into my house they could jimmy the latch on the window and let themselves in.

I don't have any bars on my windows to prevent that.

You need to draw the line somewhere.

replies(2): >>15736166 #>>15738307 #
3. carlmr ◴[] No.15736166[source]
Yeah, I'd say it depend on if you're a normal user or Edward Snowden. Do you have really sensitive data that could cost you your life? Then you have to worry about these edge cases. Are you a normal guy who wants to browse for porn safely, then this is already pretty good privacy.
replies(1): >>15738369 #
4. freeloop3 ◴[] No.15736180[source]
Silly. If you did fully shutdown, you're now much more vulnerable to an evil maid attack, which that same advisory could employ. And now you haven't been tipped off there was an attack to begin with.
replies(1): >>15738272 #
5. notfed ◴[] No.15738272[source]
Hmm, I commend your point, however I think there is room for debate on both sides.

To defend hibernation/shutdown: if I lose my laptop or it is stolen, and I realize I will never see it again, then at least I will have peace of mind that no one can ever recover the data, assuming I had a strong password.

An evil maid attack assumes I will have the laptop in my possession again. This is a different problem, and requires different measures to defend against. I'm interested in hearing why you think leaving a laptop in sleep mode protects it from an evil maid attack.

6. notfed ◴[] No.15738307[source]
I agree that bars on my windows are a lot to ask for, and lack elegance and convenience.

My Linux OS can hibernate, and I've not found it to be noticeably inelegant or inconvenient. I suppose others' opinions may differ.

7. notfed ◴[] No.15738369{3}[source]
Do you consider your credit card number sensitive? Your username and passwords to all of your, bank accounts, social media accounts, and email accounts? Your personal photos? Your personal notes with personal information about your family? Your track record of your interests and hobbies?

I do. And, if I have a choice, I'd rather not have to wonder if this data is in the hands of a stranger after my laptop is stolen.

replies(1): >>15739518 #
8. carlmr ◴[] No.15739518{4}[source]
It has to be stolen a) while it's on, and b) by someone who immediately knows what to do.

I'm quite sure if you look at your average thief and multiply these to chances together that's less than one in a million chance to happen. Assuming you're not some high profile person where the right person is out to get you and knows which OS you use, and knows how to steal from you.