• Purism Librem 14v1 w/ Qubes - First Thoughts

    From Greenlfc@1337:3/129 to All on Wed Apr 27 12:17:52 2022
    Hi folks,

    This is a repost of my recent gemlog post on the same topic. You can see it here if you're a gemini user. So far I'm fairly happy, but we'll see how it looks when the shiny wears the rest of the way off. I am a little disappointed that, for the premium this hardware has, that the preloaded software wasn't a bit more up-to-date.

    Original post: ## 2022-04-25: Librem 14v1 First Impressions at gemini://gemini.greenleader.xyz/technotes.gmi

    Finally received my Purism Librem 14v1 (not their fault on the delay). Here are my first impressions and some of my initial setup concerns.

    I ordered the 32GB / 1TB / SeaBIOS + coreboot / Qubes version. First impression at unboxing is that this is a really attaractive laptop. Nice sharp corners, matte finish, no markings on the top or inside, minimal markings on the bottom. Gives me vibes like a "murdered out" car. Screen is nice, too. I like that sticker life, but I'm go
    ing to keep the back clean until it starts getting scratched.

    On first boot, you're prompted for your LUKS password. I wasn't given one. I checked the FAQ and support site without luck. I gave up and emailed, but while I was waiting, I found a blog post from the CEO (https://puri.sm/posts/qubes-now-a-preinstall-option-for-librem-14-and-mini/)

    Or so I thought. They shipped the machine with Qubes 4.0 installed. The whonix templates included were the deprecated -15 ones. I could have reinstalled Qubes, but I wanted to get the whole "new user" experience, so I toughed it out.

    System time was *way* off. I had to fix that before updates would work (due to cert validity), and it took a reboot before it kicked in. Then I performed a distribution upgrade to get to 4.1: https://www.qubes-os.org/doc/upgrade/4.1/

    From dom0:
    ```
    sudo qubes-dom0-update -y qubes-dist-upgrade
    sudo qubes-dist-upgrade --all
    ```
    reboot
    ```
    sudo qubes-dist-upgrade --resync-appmenus-features
    ```
    The whonix installs were still on -15, so had to import the new templates:
    ```
    sudo qubes-dom0-update --enablerepo=qubes-templates-community --action=reinstall qubes-template-whonix-ws-16
    sudo qubes-dom0-update --enablerepo=qubes-templates-community --action=reinstall qubes-template-whonix-gw-16
    ```
    Re-assign the App VMs to the updated templates (don't forget to change the DispVM setting in the -ws VM) and delete -15 templates:
    ```
    qubes-dom0-update --action=remove cubes-template-whonix-ws-15
    qubes-dom0-update --action=remove cubes-template-whonix-gw-15
    ```

    I also went ahead and installed the Debian 11 template:
    ```
    sudo qubes-dom0-update --action=install qubes-template-debian-11
    ```

    That's it for now. I've got to start adding apps to my templates, setting up my app vms, and importing the Windows HVM that I need. Also need to try to see if I can get OpenConnect working (I was working on it on a tester for the past month, but could never get it to work in our environment).

    GreenLFC ║ e> greenleaderfanclub@protonmail.com
    Infosec / Ham / Retro ║ masto> GLFC@mstdn.starnix.network
    Avoids Politics on BBS ║ gem> gemini.greenleader.xyz

    --- Mystic BBS v1.12 A48 2022/04/03 (Raspberry Pi/32)
    * Origin: 2o fOr beeRS bbs>>>20ForBeers.com:1337 (1337:3/129)
  • From Greenlfc@1337:3/129 to All on Wed May 11 08:00:12 2022
    So a few weeks into it, and here are some updated thoughts.

    - If you use virtual backgrounds in Microsoft Teams, prepare to be disappointed.
    - Still haven't got the VPN set up yet, but I've also not really been working on it. For now, the VPN running in my Windows HVM is good enough for most tasks.
    - I can't get Remmina to reliably connect through work's Remote Desktop Gateway. I think it's a TLS negotiation thing, but I haven't been able to investigate.
    - It's a fail on me for not doing my due diligence, but the CPU *is* a little underwhelming for purpose. It works fine, but really we should have more than six cores in a machine built around virtualization.
    - For some reason my webcam, which I use as a microphone, will occasionally get "stuck" and I can't get it reconnected to the VM I use for video conferencing until I bounce the VM.

    Outside of the videoconferencing challenges it's been great, though. I'll probably keep a lightweight "insecure" machine around for VC.

    GreenLFC ║ e> greenleaderfanclub@protonmail.com
    Infosec / Ham / Retro ║ masto> GLFC@mstdn.starnix.network
    Avoids Politics on BBS ║ gem> gemini.greenleader.xyz

    --- Mystic BBS v1.12 A48 2022/04/03 (Raspberry Pi/32)
    * Origin: 2o fOr beeRS bbs>>>20ForBeers.com:1337 (1337:3/129)
  • From MeaTLoTioN@1337:1/101 to Greenlfc on Mon May 16 07:05:44 2022
    On 11 May 2022, Greenlfc said the following...

    So a few weeks into it, and here are some updated thoughts.

    - If you use virtual backgrounds in Microsoft Teams, prepare to be disappointed.
    - Still haven't got the VPN set up yet, but I've also not really been working on it. For now, the VPN running in my Windows HVM is good
    enough for most tasks.
    - I can't get Remmina to reliably connect through work's Remote Desktop Gateway. I think it's a TLS negotiation thing, but I haven't been able
    to investigate.
    - It's a fail on me for not doing my due diligence, but the CPU *is* a little underwhelming for purpose. It works fine, but really we should have more than six cores in a machine built around virtualization.
    - For some reason my webcam, which I use as a microphone, will occasionally get "stuck" and I can't get it reconnected to the VM I use for video conferencing until I bounce the VM.

    Outside of the videoconferencing challenges it's been great, though.
    I'll probably keep a lightweight "insecure" machine around for VC.


    Nice review Greenlfc; will any of the issues you've found that aren't hardware issues planned for a software fix anytime soon? Has anyone else reported similar problems?

    ---
    |14Best regards,
    |11Ch|03rist|11ia|15n |11a|03ka |11Me|03aTLoT|11io|15N

    |07── |08[|10eml|08] |15ml@erb.pw |07── |08[|10web|08] |15www.erb.pw |07───┐ |07── |08[|09fsx|08] |1521:1/158 |07── |08[|11tqw|08] |151337:1/101 |07┬──┘ |07── |08[|12rtn|08] |1580:774/81 |07─┬ |08[|14fdn|08] |152:250/5 |07───┘
    |07── |08[|10ark|08] |1510:104/2 |07─┘

    --- Mystic BBS v1.12 A47 2021/12/13 (Linux/64)
    * Origin: thE qUAntUm wOrmhOlE, rAmsgAtE, uK. bbs.erb.pw (1337:1/101)
  • From Greenlfc@1337:3/129 to MeaTLoTioN on Mon May 16 07:24:50 2022
    On 16 May 2022, MeaTLoTioN said the following...

    Nice review Greenlfc; will any of the issues you've found that aren't hardware issues planned for a software fix anytime soon? Has anyone else reported similar problems?


    The USB passthrough *can* be a little wonky sometimes, hence the webcam getting stuck issue. I know that's an area they continue to work on.

    Teams Virtual Backgrounds is likely a resource issue since I'm hitting high resource usage, combined with being *required* to use Edge to turn them on. The Linux desktop client doesn't even let you try, and Teams on Chromium doesn't have the option either.

    The Remmina and VPN stuff are organizational configuration issues, not the fault of the device or QubesOS.

    GreenLFC ║ e> greenleaderfanclub@protonmail.com
    Infosec / Ham / Retro ║ masto> GLFC@mstdn.starnix.network
    Avoids Politics on BBS ║ gem> gemini.greenleader.xyz

    --- Mystic BBS v1.12 A48 2022/04/03 (Raspberry Pi/32)
    * Origin: 2o fOr beeRS bbs>>>20ForBeers.com:1337 (1337:3/129)
  • From MeaTLoTioN@1337:1/101 to Greenlfc on Mon May 16 15:51:44 2022
    Teams Virtual Backgrounds is likely a resource issue since I'm hitting high resource usage, combined with being *required* to use Edge to turn them on. The Linux desktop client doesn't even let you try, and Teams
    on Chromium doesn't have the option either.

    I use Teams in the Brave Browser, and use the backgrounds thing ok in Ubuntu 20.04 and Arch... I guess it's not the same for Qubes. I don't use the Linux desktop client for Teams, tried it once but doesn't work well if at all with pulse, at least I couldn't get it to.

    ---
    |14Best regards,
    |11Ch|03rist|11ia|15n |11a|03ka |11Me|03aTLoT|11io|15N

    |07── |08[|10eml|08] |15ml@erb.pw |07── |08[|10web|08] |15www.erb.pw |07───┐ |07── |08[|09fsx|08] |1521:1/158 |07── |08[|11tqw|08] |151337:1/101 |07┬──┘ |07── |08[|12rtn|08] |1580:774/81 |07─┬ |08[|14fdn|08] |152:250/5 |07───┘
    |07── |08[|10ark|08] |1510:104/2 |07─┘

    --- Mystic BBS v1.12 A47 2021/12/13 (Linux/64)
    * Origin: thE qUAntUm wOrmhOlE, rAmsgAtE, uK. bbs.erb.pw (1337:1/101)
  • From Greenlfc@1337:3/129 to MeaTLoTioN on Tue May 17 04:51:06 2022
    On 16 May 2022, MeaTLoTioN said the following...

    I use Teams in the Brave Browser, and use the backgrounds thing ok in Ubuntu 20.04 and Arch... I guess it's not the same for Qubes. I don't
    use the Linux desktop client for Teams, tried it once but doesn't work well if at all with pulse, at least I couldn't get it to.

    Hm, I haven't tried Brave yet, it's not a browser that's no my normal rotation. I think ultimately my issue will be resource consumption, but it's worth a shot.

    GreenLFC ║ e> greenleaderfanclub@protonmail.com
    Infosec / Ham / Retro ║ masto> GLFC@mstdn.starnix.network
    Avoids Politics on BBS ║ gem> gemini.greenleader.xyz

    --- Mystic BBS v1.12 A48 2022/04/03 (Raspberry Pi/32)
    * Origin: 2o fOr beeRS bbs>>>20ForBeers.com:1337 (1337:3/129)
  • From MeaTLoTioN@1337:1/101 to Greenlfc on Tue May 17 13:27:58 2022
    Hm, I haven't tried Brave yet, it's not a browser that's no my normal rotation. I think ultimately my issue will be resource consumption, but it's worth a shot.

    I've only been using Brave a month or two, I used chrome before, chromium before that but chromium stopped managing my passwords correctly so went to chrome until I found something decent.

    chrome, chromium and brave worked with Teams for me, with the virtual background, but as I say I am on Ubuntu 20.04 and Arch on a PC, YMMV with Qubes. Good luck =)

    ---
    |14Best regards,
    |11Ch|03rist|11ia|15n |11a|03ka |11Me|03aTLoT|11io|15N

    |07── |08[|10eml|08] |15ml@erb.pw |07── |08[|10web|08] |15www.erb.pw |07───┐ |07── |08[|09fsx|08] |1521:1/158 |07── |08[|11tqw|08] |151337:1/101 |07┬──┘ |07── |08[|12rtn|08] |1580:774/81 |07─┬ |08[|14fdn|08] |152:250/5 |07───┘
    |07── |08[|10ark|08] |1510:104/2 |07─┘

    --- Mystic BBS v1.12 A47 2021/12/13 (Linux/64)
    * Origin: thE qUAntUm wOrmhOlE, rAmsgAtE, uK. bbs.erb.pw (1337:1/101)
  • From paulie420@1337:3/129 to MeaTLoTioN on Tue May 17 15:13:16 2022
    I've only been using Brave a month or two, I used chrome before, chromium before that but chromium stopped managing my passwords correctly so went to chrome until I found something decent.

    chrome, chromium and brave worked with Teams for me, with the virtual background, but as I say I am on Ubuntu 20.04 and Arch on a PC, YMMV with Qubes. Good luck =)

    I've come up with a combo that really works for me... I use BRAVE for when I need a full-fledged browser and I use LIBREWOLF when I want to be a bit more secture. LW doesn't have all the bells and whistles, tho - so when a website needs that web 3.0 tools I switch over to B.



    |07p|15AULIE|1142|07o
    |08.........

    --- Mystic BBS v1.12 A48 2022/04/03 (Raspberry Pi/32)
    * Origin: 2o fOr beeRS bbs>>>20ForBeers.com:1337 (1337:3/129)
  • From Zylone@1337:3/154 to paulie420 on Tue May 17 22:48:36 2022
    On 17 May 2022, paulie420 said the following...

    I've only been using Brave a month or two, I used chrome before, chro before that but chromium stopped managing my passwords correctly so w to chrome until I found something decent.

    chrome, chromium and brave worked with Teams for me, with the virtual background, but as I say I am on Ubuntu 20.04 and Arch on a PC, YMMV Qubes. Good luck =)

    I've come up with a combo that really works for me... I use BRAVE for
    when I need a full-fledged browser and I use LIBREWOLF when I want to be
    a bit more secture. LW doesn't have all the bells and whistles, tho - so when a website needs that web 3.0 tools I switch over to B.

    I still have not checked out librewolf.. but if you want SUPER DUPER basic/lightweight browser... check out 'surf' and 'qutebrowser'

    I been using these for basic stuff like my security camera's, work email, youtube music, etc.. stuff that stays open all the time.. and is super minimalist!

    |15Z|07ylone

    --- Mystic BBS v1.12 A48 2022/01/28 (Linux/64)
    * Origin: bbs.pLANETcARAVAN.org:23 ssh:1337 (1337:3/154)
  • From paulie420@1337:3/129 to Zylone on Wed May 18 09:21:44 2022
    I still have not checked out librewolf.. but if you want SUPER DUPER basic/lightweight browser... check out 'surf' and 'qutebrowser'

    So I use Wayland and Surf doesn't load easily for me - seems like you might use it w/ a tiled WM but Qutebrowser is super light. Thanks, I hadn't heard of these.

    (I have used some suckless.org tools w/ WMs tho.)



    |07p|15AULIE|1142|07o
    |08.........

    --- Mystic BBS v1.12 A48 2022/04/03 (Raspberry Pi/32)
    * Origin: 2o fOr beeRS bbs>>>20ForBeers.com:1337 (1337:3/129)
  • From Zylone@1337:3/154 to paulie420 on Thu May 19 18:40:16 2022
    I still have not checked out librewolf.. but if you want SUPER DUPER basic/lightweight browser... check out 'surf' and 'qutebrowser'

    So I use Wayland and Surf doesn't load easily for me - seems like you might use it w/ a tiled WM but Qutebrowser is super light. Thanks, I hadn't heard of these.

    (I have used some suckless.org tools w/ WMs tho.)


    Ah yeah.. I didn't think about the WM thing.. but yeah using i3wm.. Very welcome =)

    |15Z|07ylone

    --- Mystic BBS v1.12 A48 2022/01/28 (Linux/64)
    * Origin: bbs.pLANETcARAVAN.org:23 ssh:1337 (1337:3/154)
  • From MeaTLoTioN@1337:1/101 to Zylone on Fri May 20 16:48:22 2022
    On 19 May 2022, Zylone said the following...

    Ah yeah.. I didn't think about the WM thing.. but yeah using i3wm.. Very welcome =)

    I do love me some i3 action! =)

    ---
    |14Best regards,
    |11Ch|03rist|11ia|15n |11a|03ka |11Me|03aTLoT|11io|15N

    |07── |08[|10eml|08] |15ml@erb.pw |07── |08[|10web|08] |15www.erb.pw |07───┐ |07── |08[|09fsx|08] |1521:1/158 |07── |08[|11tqw|08] |151337:1/101 |07┬──┘ |07── |08[|12rtn|08] |1580:774/81 |07─┬ |08[|14fdn|08] |152:250/5 |07───┘
    |07── |08[|10ark|08] |1510:104/2 |07─┘

    --- Mystic BBS v1.12 A47 2021/12/13 (Linux/64)
    * Origin: thE qUAntUm wOrmhOlE, rAmsgAtE, uK. bbs.erb.pw (1337:1/101)