Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upTurn Auto File Previews off by default in Debian / Whonix templates #1108
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Aug 7, 2015
Member
I guess Qubes does not influence Debian's defaults at present. Would speculate, that Fedora has just different defaults. Just now checked, in a jessie template and dolphin, preview is not enabled by default. In nautilus however I can confirm it is enabled by default. This undermines the security benefit by the right click action "Open in DisposableVM".
|
I guess Qubes does not influence Debian's defaults at present. Would speculate, that Fedora has just different defaults. Just now checked, in a jessie template and dolphin, preview is not enabled by default. In nautilus however I can confirm it is enabled by default. This undermines the security benefit by the right click action "Open in DisposableVM". |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Aug 7, 2015
Member
Correction, it's also enabled in dolphin. Quote powerpeep.
Settings => Configure Dolphin => General => Previews
Directories: Checked
Images (GIF, PNG, BMP, ...): Checked
JPEG Images: Checked
JPEG: Rotate the image automatically: Checked
|
Correction, it's also enabled in dolphin. Quote powerpeep.
|
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Aug 7, 2015
Member
I have some experience with changing distribution defaults for KDE applications. There is a number of packages, where we at Whonix change these settings:
https://github.com/Whonix?utf8=%E2%9C%93&query=kde-
If you want, I could create a kde-dolphin-security-settings package.
Dunno about nautilus. Configuration of Gnome packages is more cumbersome. I could try this as well. Would be a more time intense task.
|
I have some experience with changing distribution defaults for KDE applications. There is a number of packages, where we at Whonix change these settings: If you want, I could create a kde-dolphin-security-settings package. Dunno about nautilus. Configuration of Gnome packages is more cumbersome. I could try this as well. Would be a more time intense task. |
marmarek
added
enhancement
C: templates
P: minor
labels
Sep 2, 2015
marmarek
added this to the Release 3.1 milestone
Sep 2, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Sep 2, 2015
Member
Generally good idea. @adrelanos if you know how to do it, feel free to take this ticket :)
|
Generally good idea. @adrelanos if you know how to do it, feel free to take this ticket :) |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Sep 2, 2015
Member
Will do. Start with configuration of dolphin. Will call that package security-misc where we can aggregate similar settings.
Are you okay with the packages implemented in the following style:
https://github.com/Whonix?utf8=%E2%9C%93&query=kde- ? As a specific example you could take for example https://github.com/Whonix/kde-sounds-off. I.e. a simple genmkfile based settings package.
|
Will do. Start with configuration of dolphin. Will call that package Are you okay with the packages implemented in the following style: |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Sep 2, 2015
Member
On Wed, Sep 02, 2015 at 02:41:30AM -0700, Patrick Schleizer wrote:
Will do. Start with configuration of dolphin. Will call that package
security-miscwhere we can aggregate similar settings.Are you okay with the packages implemented in the following style:
https://github.com/Whonix?utf8=%E2%9C%93&query=kde- ? As a specific example you could take for example https://github.com/Whonix/kde-sounds-off. I.e. a simple genmkfile based settings package.
Currently we place such things (configuration of template stuff) in
core-agent-linux package, but I'm ok with creating new one.
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
|
On Wed, Sep 02, 2015 at 02:41:30AM -0700, Patrick Schleizer wrote:
Currently we place such things (configuration of template stuff) in Best Regards, |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Tracking this under https://phabricator.whonix.org/T418. |
marmarek
modified the milestones:
Release 3.1,
Release 3.1 updates
Feb 8, 2016
andrewdavidwong
added
C: Debian
C: Whonix
labels
Apr 7, 2016
rootkovska
removed
the
C:
label
Jun 30, 2016
andrewdavidwong
added
the
C: Debian
label
Jul 1, 2016
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Nov 22, 2016
Member
I still intent another try figuring this out for nautilus... https://phabricator.whonix.org/T500
But if someone else wanted to help out, please do.
|
I still intent another try figuring this out for nautilus... https://phabricator.whonix.org/T500 But if someone else wanted to help out, please do. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Nov 27, 2016
Member
File previews in the Fedora templates have been disabled for a long time now.
Is this a Fedora or Qubes feature? Where is that implemented?
(I am asking, because then implementing this ticket would be a lot simpler.)
Is this a Fedora or Qubes feature? Where is that implemented? (I am asking, because then implementing this ticket would be a lot simpler.) |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Nov 28, 2016
Member
I figured @marmarek simply changed that setting in Nautilus before packaging the standard Fedora template.
|
I figured @marmarek simply changed that setting in Nautilus before packaging the standard Fedora template. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
It wasn't me, anyway: QubesOS/qubes-core-agent-linux@40fcbde |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Nov 28, 2016
Member
If not working on Debian, it may require to call glib-compile-schemas. From rpm spec:
%posttrans
/usr/bin/glib-compile-schemas %{_datadir}/glib-2.0/schemas &> /dev/null || :
|
If not working on Debian, it may require to call
|
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Nov 28, 2016
Member
It wasn't me, anyway: QubesOS/qubes-core-agent-linux@40fcbde
Oh, sorry!
@adrelanos: BTW, here's the issue that was closed by the above commit: #813
Oh, sorry! @adrelanos: BTW, here's the issue that was closed by the above commit: #813 |
unman
referenced this issue
in QubesOS/qubes-core-agent-linux
Feb 12, 2017
Merged
Apply gschema override preventing previews in nautilus in Debian #39
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
unman
Feb 12, 2017
Member
I believe that file previews are turned off in dolphin by default. At least in jessie and stretch it appears to be so.
|
I believe that file previews are turned off in dolphin by default. At least in jessie and stretch it appears to be so. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
unman
Feb 19, 2017
Member
@andrewdavidwong The merging of QubesOS/qubes-core-agent-linux#39 closes this in Debian.
Whonix has its own solution.
|
@andrewdavidwong The merging of QubesOS/qubes-core-agent-linux#39 closes this in Debian. |
andrewdavidwong
closed this
Feb 19, 2017
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Feb 19, 2017
Member
|
Whonix does not have a solution for nautilus yet.
Do you know, can there be multiple files like
'/usr/share/glib-2.0/schemas/org.gnome.nautilus.gschema.override' doing
the same? I am asking, because I'd like to add it to the security-misc
package. (And as per Debian packaging, a file may not be owned by two
packages at once.)
|
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
unman
Feb 19, 2017
Member
|
On Sun, Feb 19, 2017 at 09:37:44AM -0800, Patrick Schleizer wrote:
Whonix does not have a solution for nautilus yet.
Do you know, can there be multiple files like
'/usr/share/glib-2.0/schemas/org.gnome.nautilus.gschema.override' doing
the same? I am asking, because I'd like to add it to the security-misc
package. (And as per Debian packaging, a file may not be owned by two
packages at once.)
I'm sorry Patrick - I misread your earlier comment.
|
powerpeep commentedAug 7, 2015
https://www.whonix.org/forum/index.php/topic,1492.0.html
Qubes Fedora templates has auto file preview off by default in the file manager to stop random files or downloads from being able to exploit parsing vulnerabilities here.
The Debian / Whonix templates have this on by default. So it shows thumbnails of images and more in the file manager's icons.
For security, could this preview feature please be turned off by default in future releases?