Qubes.live Canary 1

We have published Qubes.live Canary 1. The text of this canary and its accompanying cryptographic signatures are reproduced below. For an explanation of this announcement and instructions for authenticating this canary, please see the end of this announcement.

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
Qubes.live Canary 1

The Qubes.live team members who have digitally signed this file state the following:

1. The date of issue of this canary is February 4, 2025.

2. There have been 0 Qubes.live security bulletins published so far.

3. The Qubes.live team Key fingerprint is:

994E0 B67DF 22DD4 123E9 CF94D 90394 3F63B 102DD
D9B95 91EF7 C9A60 038A7 7DEFA 11893 63543 518F6
8B746 0C32F 801CA 4E8A5 1ED41 9E108 47D2C 54BF9

4. No warrants have ever been served to us with regard to the qubes.live project (e.g. to hand out the private signing keys or to introducebackdoors).

5. We plan to publish the next of these canary statements in the first fourteen days of March 2025. Special note should be taken if no new canary is published by that time or if the list of statements changes without plausible explanation.

# Disclaimers and notes

This canary scheme is not infallible. Although signing the declaration makes it very difficult for a third party to produce arbitrary declarations, it does not prevent them from using force or other means, like blackmail or compromising the signers' laptops, to coerce us to produce false declarations.

The proof of freshness provided below serves to demonstrate that this canary could not have been created prior to the date stated. It shows that a series of canaries was not created in advance.

This declaration is merely a best effort and is provided without any guarantee or warranty. It is not legally binding in any way to anybody. None of the signers should be ever held legally responsible for any of the statements made here.

Proof of freshness

- [Trump to pause tariffs on Canada and Mexico after they agree to strengthen borders](https://www.bbc.com/news/live/c8d90v1m6qvt)

- [特朗普的关税政策会损害美国消费者吗?](https://www.bbc.com/zhongwen/articles/cn0yey2z9nzo/simp)

- [Founder of pro-Russian paramilitary group dies in explosion in Moscow](https://edition.cnn.com/2025/02/03/europe/armen-sarkisyan-bomb-death-moscow-intl-latam/index.html)

- [btc transaction](https://www.blockchain.com/explorer/transactions/btc/4a2a1f1539499bd535857ce4c07f5fd00197b275a424c94635fc15244d86753f)

Footnotes

You can get their PGP public key in https://blog.qubes.live/rule/index.html

Bar’s PGP signature

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEi3Rgwy+AHKTopR7UGeEIR9LFS/kFAmeh+dQACgkQGeEIR9LF
S/kw4g/9GAmRpnrMiU0zM1EVaVyes1HigkIbw9BOaESDm+msbZDor9LCZYfMcWyC
8/fHkf1VE7zqhUhRG+UskYa3AkPwEFD9ToJvqAUCn6p75eBUEUy41lgAgI2gIBd9
ziHv9+S1OWg1TfstMwOdpQYpHvJUb+8GHXfVmdmvbGodJskd0hlTi77ecvjGbgt9
niLIairzfNWS1tlR3tfuXkZV4KLZRky46hRucGey/sTIUfY1j2blUBZ64O3aEWqZ
dC1ttrpGcmdh7WhI1HAfTRaS6VfhKR0e9/fFtnPNpCSLlQPmXr01GwdsU0FxBtx1
rh9rDKmNwVEoJEWvIuwRMk4+diQtznpYdTpSbAv66qXl1PHw5wSgbQ5XqqkykiiK
Q3SZrEkpquaU68wBkeUP8ov+dL3nGF6tgY3lJqBbiRHNeLCrxuz+7uMaRANwdDwn
u9w2xqe1knCtPVSs4dzzPDFxLbw1s9KHmAyOJhPBFtzjIsNctCafGmq3facA4yqi
ZohJ9TXz2fuwDh5OYyGlPZ7rFP19pBUnIuepPi9oEWIo2UJ7pWlV2iWItU7zsANj
Rv7x8CvBNm6ajYQ9/iVFvd63cKYdYPuG/+4PWHAA62Pw4T6n0xKhKdv+ZgpfkboT
PclkdDA/pgeUfNeSyeyRuMD3O9/LdgA2HuKhg6ZeIOLBa/aSqzc=
=d1us
-----END PGP SIGNATURE-----

cccacaia’s PGP signature

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE2blZHvfJpgA4p33voRiTY1Q1GPYFAmeh+MMACgkQoRiTY1Q1
GPYv8A//fqDtzljSsqH74D/sdXveqAEEhOPbbY5qtkC4CqgUCZmxUqkVHoNH5Gt+
rBQwmPvcSvgh/boxfWKo7fmpCE0Q5bAYgkxQPbiEQAfoQ72q2IJOg9zAukLF8q3n
xf/pdrRgMKI+knkoO8+k+CUncbO0QXsu70IaU6SqLBVLMS0EDRBPhf0KLvpNoedk
HaixFc4qjpIUUO8i+TmORJ33kZ6qErHypeD5QGjg8tAiTJpBasEGAI5rNFpxmr0P
jZho1ZijPzQ1Ko7NyQeqHCgDuYFPscxiRSp1GjkY8OyR6iOy4O+XYbTuKzFAhorb
u/Kx6GzR4QSwTfCUse+v+spYWL/zKrd5l05Sw0ehLSO2JccsXcrKC5kYE7vsCMVo
3raWgc1IxuCsWHiCaZeLgRSuSGb2fXdXxTe5ABZyVtkqL58/zeP4wWIxVpfPeJ4F
jZhMhvCzLYd4olL2ubbKs5/0j/C7j/ZxDdCJ7FpYh1C9/5g3Rw288HN0jQN/dfWm
Xbcnx1wP9pyu4vvEK6n/xUZt0jP1Dpn9udQZMKuK0VhSL697y3UJqH/xanPYC3Ho
8sxJx2chfctTDbh3yocqou/nPYNj+0LuXwyiEBNp8bQSx4+itoyC/E+rMxnfh/lm
QwHOT+7VvJP13xVLqfbFFJAOI+NU7SVi+1sqbFn3wOikQDNffbI=
=FQ/T
-----END PGP SIGNATURE-----

tiananmen1989’s PGP signature

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEmU4LZ98i3UEj6c+U2QOUP2OxAt0FAmeiBFsACgkQ2QOUP2Ox
At0vcQ//ebZL61emQtC1wcUf1QMOVahdcscArLD5U68DnuZvKOJDyL8/6VJxuR73
Ad4l7jPMzZM7xgQOHsbgopx4AfLAOAd7yrB4EKCS+fdnKV0McaKxuiFtqQXbLBpi
f6n37T8wv5saJJNKyK+IrMIfyXUThD1lWYn4mxnBZkxZ0MUd/G7844xz+CN8WLoy
Jv3+TU076SmSgQTrCvSAirus0KZl5aOZVs/Awy93TCTt5C/yxAdky8UlnsLNADgN
PEJm6o7y6XXEAazxLjSyK7GLmhAOdm2ORP8DXcwKOLoD/ac095fpf7XtuQnOnIyd
PHnu5YzZV6Mcv/7kLZJ/u5bcU3C1HpQyxuYyJlIa9gqjtqyT6/efOR0bSjjuD97/
eyCIqOtZCin73WzMd1C5febH9/vKT2I8hYxbjGxaA/ggHucxOCIMA4Zf5tC17VKr
2/0n4FhMyqryIL3wgJ4Qn0YGLb5HGS6I+W6p6Ryh4PjC9OvsNkbOKkKXghGqB4iV
dTajDEZ6F35JTrK91DCyMOdTPaaH2TQBtRzmtARcq7Q4A/9e14rVhhBc7rwlSz8s
PShDsi+GABCBab2YM9ITgwKkl/6PT3LibH9T5ZtLaLEcVfpLExRwJS/UxfXCjoSL
zbGv3RbBTWGpWTfv8yRgEF4rh1BNaqJcY5T0/5oF8iHdtImc5uM=
=IxcI
-----END PGP SIGNATURE-----

What is the purpose of this announcement?

The purpose of this announcement is to inform the Qubes.live that a new Qubes.live canary has been published.

What is a Qubes.live canary?

A Qubes.live canary is a security announcement periodically issued by the Qubes.live team consisting of several statements to the effect that the signers of the canary have not been compromised. The idea is that, as long as signed canaries including such statements continue to be published, all is well. However, if the canaries should suddenly cease, if one or more signers begin declining to sign them, or if the included statements change significantly without plausible explanation, then this may indicate that something has gone wrong.

The name originates from the practice in which miners would bring caged canaries into coal mines. If the level of methane gas in the mine reached a dangerous level, the canary would die, indicating to miners that they should evacuate. (See the Wikipedia article on warrant canaries for more information, but bear in mind that Qubes.live Canaries are not strictly limited to legal warrants.)

Why should I care about canaries?

Canaries provide an important indication about the security status of the project. If the canary is healthy, it’s a strong sign that things are running normally. However, if the canary is unhealthy, it could mean that the project or its members are being coerced in some way.

What are some signs of an unhealthy canary?

Here is a non-exhaustive list of examples:

  • Dead canary. In each canary, we state a window of time during which you should expect the next canary to be published. If no canary is published within that window of time and no good explanation is provided for missing the deadline, then the canary has died.
  • Missing statement(s). Every canary contains the same set of statements (sometimes along with special announcements, which are not the same in every canary). If an important statement was present in older canaries but suddenly goes missing from new canaries with no correction or explanation, then this may be an indication that the signers can no longer truthfully make that statement.
  • Missing signature(s). Qubes.live canaries are signed by the members of the Qubes.live team (see below). If one of them has been signing all canaries but suddenly and permanently stops signing new canaries without any explanation, then this may indicate that this person is under duress or can no longer truthfully sign the statements contained in the canary.

What are the PGP signatures that accompany canaries?

A PGP signature is a cryptographic digital signature made in accordance with the OpenPGP standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG). The Qubes security team cryptographically signs all canaries so that Qubes users have a reliable way to check whether canaries are genuine. The only way to be certain that a canary is authentic is by verifying its PGP signatures.

Why should I care whether a canary is authentic?

If you fail to notice that a canary is unhealthy or has died, you may continue to trust the Qubes.live team even after they have signaled via the canary (or lack thereof) that they been compromised or coerced. Falsified canaries could include manipulated text designed to sow fear, uncertainty, and doubt about the security of Qubes.live or the status of the Qubes.live