[1] This file should be signed in two ways: (1) via detached PGP
signatures by each of the signers, distributed together with this canary
in the qubes-secpack.git repo, and (2) via digital signatures on the
corresponding qubes-secpack.git repo tags. [2]
[2] Don't just trust the contents of this file blindly! Verify the
digital signatures! Instructions for doing so are documented here:
https://www.qubes-os.org/security/pack/
--
The Qubes Security Team
https://www.qubes-os.org/security/
Source: github.com/QubesOS…2023.txt
Marek Marczykowski-Górecki (www.qubes-os.org/team…eam)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmRrV3YACgkQ1lWk8hgw
4GrB5Q/9GchNzTj7MoQqAHsYWkZTy2qB4YOXmo6HedUqr//vz6zHx+BDne4sBiuy
V8knNY+7Wm3qvMaLvU56G7J35zJN/FeLKTbXcGBRk1sOxO67l4giuuwiq7ELTFvd
WPXblm63LpwzTIoTP4lkqb3VVEaqA5Lrr4U+fe/oqiFRX7KE3ZUEwMw078b2qqTo
NmoceN6N8QwEEuP0hhR6G1SfsVzIhl/tUFlFQQz6ymcWSu5qzechXzfPzUgD90pi
yRoNu1QBTJmZ3sKSIPMfwSEn1j7ZonlN1NEfm8dYtukr8g0aWjkoY8d2X4P0PT1L
jEPmzS5hJmqw9IhJvd2EgETHSj2Q71+MpI73vRVgvU0lhjYvkYIce72sTNC0k/28
k7HOvIkyt5jzLAGnPlvOulpBkxbvyf6jLjoyYLMp84qlGznv9cGoFSABXSQyPaha
15o/THnCJU3LbBd4ZfMwT8vgzW04tO4/AP5rc0s28nlq8QU02E5I8txylOJ5srrw
8A7q3yK03CpwI0JYDrc9JOBGdCP6i+a0qjDLNGzj8WwlalIdBGupoHxVp518yjr8
+6Sun9wOhKsf7HB6hAAdVr7fp7XoTAIdEczz7h+hm1zsbhRM50mZfWJksnfPy4RE
cG1X6BqPIkXz51idqMm7l6+8K0EVZqvwGZBpC7S1CgqYKHTvbpg=
=zV7L
-----END PGP SIGNATURE-----
Source: github.com/QubesOS…marmarek
Simon Gaiser (aka HW42) (www.qubes-os.org/team…eam)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmRrWyoACgkQSsGN4REu
FJAg2A//YILj71MatgNWIL6gmgTh66TyMSwdnWSe3lJSlOZW4LWAzu2U9S6JgK92
RpURskaLFd9Jvhv+7lUtuGVGMAyPBG9QxaxRrzvz6CVt5PgZG3x8Ll2o3CBaGeZ0
NX9jW+Jmq/abbkURtWfSb4IyF1sBbT2MH1rDRUlYIL4bCpkvwFbj7CQFtYN01DZO
c98Vy9aciSwvaDhAqGrN9QdXBkNFcn/OsrKgeuCnpjKbKYUkOuhqM+WWbetXSbIU
JHFRpUrAPbzeueRNvLq9b/G57dK5PiXiXkWTUGyzcHJnuU7XnZQArUJcDmliyI6k
Y/v39T48m6aPK1oOFgRuJh5smjgHHhf/Y68F4eAmSaA234BFd2jSMezo8DEonyrv
0+pdGAerE9+/VHXP+tkD51M/gxAry5i86iNAl2tK+VPQjk88QIPpcymDhfTAD6/4
bCvu4j9eF4jUe9HFrvJLVOC/vXseJpGrg6z7O19GhhhNWTEhiE76cQY7owV/CtCR
X8FGwiAngM449puxnP0uHYMxkXlmN3Pz52zOZcHZiQaLnUcANOiLSjH1+m1PKrlU
TqQ7zO9B49XpGh3MXCwze37qT9RAqrxW7H+omH5GdoSUzpL8QqqD9RWfzlMvgqrR
UKhH3Bt+LmgwAmBGlrqHYDLs5DTe5Id849mk7JZlv9UdZbQt4KQ=
=kqLl
-----END PGP SIGNATURE-----
Source: github.com/QubesOS…ig.simon
What is the purpose of this announcement?
The purpose of this announcement is to inform the Qubes community that a new Qubes canary has been published.
What is a Qubes canary?
A Qubes canary is a security announcement periodically issued by the Qubes security team (www.qubes-os.org/securit…security) consisting of several statements to the effect that the signers of the canary have not been compromised. The idea is that, as long as signed canaries including such statements continue to be published, all is well. However, if the canaries should suddenly cease, if one or more signers begin declining to sign them, or if the included statements change significantly without plausible explanation, then this may indicate that something has gone wrong. A list of all canaries is available here (https://www.qubes-os.org/security/canary/).
The name originates from the practice in which miners would bring caged canaries into coal mines. If the level of methane gas in the mine reached a dangerous level, the canary would die, indicating to miners that they should evacuate. (See the Wikipedia article on warrant canaries (https://en.wikipedia.org/wiki/Warrant_canary) for more information, but bear in mind that Qubes Canaries are not strictly limited to legal warrants.)
Why should I care about canaries?