4GoXhQ//Sz9mT1IPGqmifJnpxz9wbPrhDQQ5vb9gKQZgvPSv4L4PY2MRYb7zmGR5
bI62gFp7hgKFU7T+0pNLDUPsA3fBCJtrdfkQLn2vkkV0gE7NXY48dtYIWPQ0smSv
cd+wfG6yrVnGKc08yWRsA8Zp2zSKaHrERKi5DQZjZexBtt9PVMk3hCkmEHjFCNqs
dFey8WXJsF5nUJqTPd4FWsLRW+ktvGv3RJ8j/XtjwYsYljgX/sGtTgJUW4yrks7f
NaIQ3c+B4nEz33zgR5bAdMLGCX0xxXPyCRwNNg5FUpBOZIlV4W1vl1EMUDVoa/s6
c8KHTI5a127i+RWI9KKY6zINscqYXWEaH2ppojzN8bIZpFuB1BJu63oXpycUPGOS
TfKWaY5T7v3casxaQtf18polAxi9LS2KRYcTPUAaRUrpxfte8mTqEuvtTD7h4bIX
BRLl0TYzC/Q3/2LpSsto55JMgJBF53DyX4Gin0Ix0slTLToqIUk8gNXhjE0PB+U3
QJWuArI4uDTflEj78WregZ7S0pi7oDILO2JV1+fcgl2yGui6+77O63HXBpgvCCag
hFDDIsgxg2PwtXQpziU5GeLbEKDiAMi10ex1aXEprhdcj/VyqXIrcSvqKu4w3S5d
pkNkhKPtWpP+mFh/NuCip8IwjCSsP0IUCXhUXHvtsKdL1hIsrDQ=
=xznI
-----END PGP SIGNATURE-----
Source: github.com/QubesOS…marmarek
Simon Gaiser (aka HW42) (www.qubes-os.org/team…eam)’s PGP signature
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmS/I5gACgkQSsGN4REu
FJBs7g/+L5gs0fG0wgJppQXQBqr5FKavexsab2Qxfo8Kfh5oJUTouzJxti9PemyB
4EdjklEVJdQYoQTV3SZDOzO4ZNGplpooKVm81F9FXGfrQG4AREoAwHaIkwqLvwyk
iYmOlSQz7vS5OJGyUlczXfwplVvbJEj2lqRTiZAjEn23MQ2gu5yMqOOb8iOeUAa6
XL1+SSQSYGEZBrTBLRpp6Bea+JRzwqb6OEcKPhdp82toPUO7OH+rgSu1e8P0sCt+
aTveHV/lMdiaJmcMgNxhov7wke/sb5nlZTFU+ZFJ7uuKKgqNSgc5t/qpRUylBtu1
1SSehwhrgB9iStKPoN8WYOvR861/Gqvvgv0zaqmRxHGbaSmFn6ZgH21XHtHaOiGt
2iD4tEJZARNFdEmJSoGQ10M2JN96u/PCN4yGrUtMLxcs7ZuNlHT/mZoEp53l2ThA
TEY8hXvZxHwuB+idLWtW5sCvlFBWd1+J7FLnRU8sP11mfwPdhC2C9nZjXFVroFxl
VsQnCz1BX0Ao0tTW/lBg1FCgA4BV8w381X5jfPEFKDxraWvN2W2ISQzQwRl1bv5h
ugdWyXVDc3y517purr5QJVyivMNQKM34beNtGymPRXd54zwQlvg7dj3nR3rx3Gsw
dzuL6b9P1EaCcnkvOmKVBCgbj1j1y3ZH1/u5HkOO/GJlXKTu2uI=
=CVsz
-----END PGP SIGNATURE-----
Source: github.com/QubesOS…ig.simon
What is the purpose of this announcement?
The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published.
What is a Qubes security bulletin (QSB)?
A Qubes security bulletin (QSB) is a security announcement issued by the Qubes security team (www.qubes-os.org/securit…security). A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address them. A list of all QSBs is available here (https://www.qubes-os.org/security/qsb/).
Why should I care about QSBs?
QSBs tell you what actions you must take in order to protect yourself from recently-discovered security vulnerabilities. In most cases, security vulnerabilities are addressed by updating normally (https://www.qubes-os.org/doc/how-to-update/). However, in some cases, special user action is required. In all cases, the required actions are detailed in QSBs.
What are the PGP signatures that accompany QSBs?
A PGP (en.wikipedia.org/wiki/Pr…_Privacy) signature is a cryptographic digital signature (https://en.wikipedia.org/wiki/Digital_signature) made in accordance with the OpenPGP (en.wikipedia.org/wiki/Pr…_Privacy) standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG) (https://gnupg.org/). The Qubes security team cryptographically signs all QSBs so that Qubes users have a reliable way to check whether QSBs are genuine. The only way to be certain that a QSB is authentic is by verifying its PGP signatures.
Why should I care whether a QSB is authentic?
A forged QSB could deceive you into taking actions that adversely affect the security of your Qubes OS system, such as installing malware or making configuration changes that render your system vulnerable to attack. Falsified QSBs could sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.
How do I verify the PGP signatures on a QSB?