Page MenuHomePhabricator

prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that / disable Qubes dom0 /etc/qubes-rpc/qubes.SetDateTime
Open, NormalPublic

Description

We do not want dom0 telling Qubes-Whonix VMs the time. Because in case of a compromised Whonix VM, we do not want the adversary replace/restore the /etc/qubes-rpc/qubes.SetDateTime script. To avoid time related deanoymization. We need to stop dom0's /usr/bin/qvm-sync-clock from running that hook for Qubes-Whonix VMs.

In T384#6287 @marmarek said we should use the mgmt stack for that.

mgmt should keep configuring qvm-sync-clock disabled for Qubes-Whonix VMs. For freshly downloaded templates as well as for user custom created new Whonix VMs based on Qubes-Whonix templates.

Details

Impact
High

Event Timeline

Patrick assigned this task to nrgaway.
Patrick raised the priority of this task from to Normal.
Patrick updated the task description. (Show Details)
Patrick added projects: bug, security, Qubes, Whonix.
Patrick set Impact to High.
Patrick added subscribers: marmarek, nrgaway, troubadour and 2 others.
Patrick renamed this task from prevent dom0 telling Qubes-Whonix VMs the time to prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that.Nov 25 2015, 6:21 PM
Patrick updated the task description. (Show Details)
Patrick added projects: mgmt, Whonix 13.

Waiting for Qubes 4, feature Template policy, services->features, core plugins to be implemented.

Patrick renamed this task from prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that to prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that / disable Qubes dom0 /etc/qubes-rpc/qubes.SetDateTime.Aug 7 2018, 6:43 PM