RSSAmplifier

Blog

The Invisible Things Blog

My personal blog and website (see http://blog.invisiblethings.org/)

blog.invisiblethings.orgRSS feed ↗10 posts

Latest posts

I have a new blog: Traces of Humanity!

Hello! Welcome back! After all those years of silence, I’ve felt like writing a blog again :-) But these days I no longer do computer security – other topics interest me more now. Thus, I have spun up a new blog titled: Traces of Humanity . It is mainly intended to be a reportage of my struggles between Rationality and Humanism. Plus a place to discuss some of my new projects :-) I discuss this…

Announcing Wildland Client v0.1

On behalf of the whole team , I’m proud to announce the first public release of Wildland client ! This is a reference implementation of the Wildland protocol, which we have described in our “Why, What and How” (aka W2H) paper . Leaving aside all the usual disclaimers about how early-beta and for-power-users-only this version really is, I’d like to focus on what’s already working and possible :)…

The Next Chapter: From the Endpoint to the Cloud

Earlier this year, I decided to take a sabbatical. I wanted to reflect on my infosec work and decide what I would like to focus on in the coming years. As you probably know, I’ve spent the last nine years mostly fighting the battle to secure the endpoint, more specifically creating, developing, architecting, and promoting Qubes OS , as well as the more general concept of “Security through…

Introducing graphene-ng: running arbitrary payloads in SGX enclaves

A few months ago, during my keynote at Black Hat Europe, I was discussing how we should be limiting the amount of trust when building computer systems. Recently, a new technology from Intel has been gaining popularity among both developers and researchers, a technology which promises a big step towards such trust-minimizing systems. I’m talking about Intel SGX , of course. Intel SGX caught my…

Qubes Air: Generalizing the Qubes Architecture

The Qubes OS project has been around for nearly 8 years now, since its original announcement back in April 2010 (and the actual origin date can be traced back to November 11th, 2009, when an initial email introducing this project was sent within ITL internally). Over these years Qubes has achieved reasonable success: according to our estimates, it has nearly 30k regular users. This could even be…

Introducing the Next Generation Qubes Core Stack

This is the 2nd post from the “cool things coming in Qubes 4.0” series, and it discusses the next generation Qubes Core Stack version 3, which is the heart of the new Qubes 4.x releases. The previous part discussed the Admin API which we also introduced in Qubes 4.0 and which heavily relies on this new Qubes Core Stack. Qubes Core Stack vs. Qubes OS Qubes Core Stack is, as the name implies, the…

Qubes OS 4.0-rc1 has been released!

Finally, after years of work, we’re releasing the first release candidate for Qubes 4.0! Next Generation Qubes Core Stack for better integration No doubt this release marks a major milestone in Qubes OS development. The single most import undertaking which sets this release apart, is the complete rewrite of the Qubes Core Stack . We have a separate set of posts detailing the changes…

Introducing the Qubes Admin API

This post starts the “cool things coming in Qubes 4.0” series and focuses on what we call the “Qubes Admin API.” This should not be confused with Qubes Salt Stack integration , which we have already introduced in Qubes 3.2. High-level overview Let’s start with a high-level architecture picture of how the Admin API fits into the Qubes OS architecture: As we can see, the main concept behind the…

Compromise recovery on Qubes OS: individual VMs & full system cases

Occasionally fuckups happen, even with Qubes (although not as often as some think). What should we – users or admins – do in such a situation? Patch, obviously. But is that really enough? What good is patching your system if it might have already been compromised a week earlier, before the patch was released, when an adversary may have learned of the bug and exploited it? That’s an inconvenient…

Qubes OS 3.2 has been released

I’m happy to announce that today we’re releasing Qubes OS 3.2! This is an incremental improvement over the 3.1 version that we released earlier this year. A lot of work went into making this release more polished, more stable and easier to use than our previous releases. One major feature that we’ve improved upon in this release is our integrated management infrastructure, which was introduced in…