QubesOS

密封硬件的验证

If you have ordered the unit with the option “sealed screws and sealed bag”, please verify the sealing before unpacking. If you do not know what this means, skip this section.

安全启动程序

With the NitroPad and NitroPC, malicious changes to the BIOS, operating system, and software can be easily detected. For example, if you left your NitroPad in a hotel room, you can use your Nitrokey to check if it has been tampered with while you were away. If an attacker modifies the NitroPad’s firmware or operating system, the Nitrokey will detect this (instructions below).

Each time you start the NitroPad or the NitroPC, you should - if possible - connect your Nitrokey. If the Nitrokey is plugged in and the system has not been modified, the following screen will appear when it is turned on.

img1

The box marked in red contains the information that the BIOS has not been changed and that the shared secret of the NitroPad or the NitroPC and the Nitrokey match. But this information is not sufficient, because an attacker could have faked it. If at the same time the Nitrokey also flashes green, everything is fine. An attacker would have to have had access to the NitroPad or NitroPC and Nitrokey to achieve this result. It is therefore important that you do not leave both devices unattended.

If the information on the NitroPad or NitroPC does not match the information on the Nitrokey, the background would turn red and the message “Invalid Code” would appear. This could indicate that manipulation has taken place.

img2

如果系统被改变了(例如在更新之后),启动过程可能是什么样子的,还有可能出现什么错误信息,下面会进一步描述。

小技巧

The NitroPad and NitroPC can also be started without the Nitrokey. If you don’t have the Nitrokey with you, but are sure that the hardware has not been manipulated, you can boot your system without checking.

入门

购买后,密码被设置为默认值,必须由您来更改。

  1. 在启动系统后按回车键("默认启动"),前提是NitroPad没有显示任何错误,且Nitrokey亮起绿色(见上文)。

  2. Next, the system will prompt you to enter the passphrase to decrypt the hard disk. The passphrase is initially "12345678".

    img3
  3. 然后,系统将引导你完成创建用户账户的过程。之后,你应该已经成功启动了系统,并且已经可以正常使用。

  4. Open the pre-installed Nitrokey App and change the PINs of your Nitrokey as described here.

  5. 在 Qubes 菜单中选择 "更改磁盘密码",更改硬盘加密的密码。该密码与用户账户密码不同。

    更改密码 Qubes 图像
  6. NitroPad 随 Qubes 操作系统提供的最新安装映像,安装后需要更新,因为它不包含所有最新的安全修复。要更新,请使用`Qubes 文档<https://www.qubes-os.org/doc/how-to-update/>`__ 中描述的更新管理器。

备注

专门针对 NitroPad V54 的 Qubes 4.2.3 安装镜像包含一个错误,它限制只能使用最高屏幕分辨率。更新 dom0 并重新启动后,这一问题就会得到解决。

系统更新后的行为

The NitroPad and NitroPC firmware checks certain system files for changes. If your operating system has updated important components, you will be warned the next time you boot the NitroPad or NitroPC. This could look like this, for example:

img4

That’s why it’s important to restart your NitroPad or your NitroPC under controlled conditions after a system update. Only when the new status has been confirmed can you leave the device unattended again. Otherwise, you will not be able to distinguish a possible attack from a system update. Detailed instructions for a system update can be found here.

Failed to Start Load Kernel Modules

在系统启动时,显示错误"Failed to start Load Kernel Modules"。`这是一个已知的问题 <https://github.com/QubesOS/qubes-issues/issues/2638>`__这不是关键问题,可以忽略不计。