Page MenuHomePhabricator

prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that / disable Qubes dom0 /etc/qubes-rpc/qubes.SetDateTime
Open, NormalPublic

Description

We do not want dom0 telling Qubes-Whonix VMs the time. Because in case of a compromised Whonix VM, we do not want the adversary replace/restore the /etc/qubes-rpc/qubes.SetDateTime script. To avoid time related deanoymization. We need to stop dom0's /usr/bin/qvm-sync-clock from running that hook for Qubes-Whonix VMs.

In T384#6287 @marmarek said we should use the mgmt stack for that.

mgmt should keep configuring qvm-sync-clock disabled for Qubes-Whonix VMs. For freshly downloaded templates as well as for user custom created new Whonix VMs based on Qubes-Whonix templates.

Details

Impact
High

Event Timeline

Patrick created this task.Aug 16 2015, 3:55 AM
Patrick updated the task description. (Show Details)
Patrick raised the priority of this task from to Normal.
Patrick assigned this task to nrgaway.
Patrick added projects: bug, security, Qubes, Whonix.
Patrick set Impact to High.
Patrick added subscribers: marmarek, nrgaway, troubadour and 2 others.
Patrick updated the task description. (Show Details)Nov 25 2015, 6:21 PM
Patrick added projects: mgmt, Whonix 13.
Patrick renamed this task from prevent dom0 telling Qubes-Whonix VMs the time to prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that.
Patrick edited projects, added Whonix 14; removed Whonix 13.EditedMar 22 2016, 11:47 AM

Waiting for Qubes 4, feature Template policy, services->features, core plugins to be implemented.

Patrick removed nrgaway as the assignee of this task.Jan 25 2017, 10:40 PM
Patrick edited projects, added Whonix 15; removed Whonix 14.Mar 14 2017, 9:24 PM
Patrick renamed this task from prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that to prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that / disable Qubes dom0 /etc/qubes-rpc/qubes.SetDateTime.Aug 7 2018, 6:43 PM