Hacker News

Favorites Setup
Comment by TacticalCoder | original | Arbitrary code execution in QubesOS via copy-to-VM error reporting backchannel
[−]TacticalCoder · 2026-08-30 Sun 11:09 UTC · link
I do really like the following in the bulletin:

> Important: At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The standard method is to obtain the QMSK fingerprint from multiple independent sources in several different ways and check to see whether they match the key you just imported. For more information, see How to import and authenticate the Qubes Master Signing Key.

It looks like Qubes is ran by people who take security seriously, which is refreshing.

[−]leonidasrup · 2026-08-30 Sun 11:29 UTC · link
How well is QMSK protected from a serious attacker?
[−]inigyou · 2026-08-30 Sun 16:00 UTC · link
I own a Qubes T-shirt which I bought in person at FOSDEM. The design on the T-shirt consists of many copies of the QMSK in hexadecimal. All of their merch is like this.