[HOME] [DOWNLOAD] [DOCS] [NEWS] [SUPPORT] [TIPS] [ISSUES] [CONTRIBUTE] [DONATE]

Long Wiki Edits Thread

Software signatures is a broken system that only at least somewhat-computer-geeks will get. At the same time these chase way regular users due to added complexity. They’d rather skip installing something with signatures available if they don’t know how and install something insecure instead that doesn’t mention it feeling more secure.

Fixing this mess could be metalink with OpenPGP support automating all of this:

Looks good.

Is that a secure system? @HulaHoop

1 Like

https://www.whonix.org/wiki/Point_Release - introduced this term for an upcoming Qubes-Whonix point release Qubes-Whonix 14 (4.0.1-20181104) TemplateVMs Point Release for Qubes R4 -- Testers Wanted! and soon also Non-Qubes-Whonix 14 point release.

According to their lead dev, they do implement GPG signing (htough optional) of flatpak repos and code commits:

https://blogs.gnome.org/alexl/2017/02/10/maintaining-a-flatpak-repository/

I want to suggest they adopt TUF for their software repo code because it has defense in depth against so many other attacks than basic download poisoning.

https://theupdateframework.github.io/security.html

2 Likes

include keepassxc to the comparison

http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/wiki/Dev/Password_Manager

very important as i think now its the best one in use from high tech ppl like micahlee

But how does it link the creator of the package with the package itself? If someone replaced the package on the website and resigned it, no one would notice that?

Imagine one day of the month Whonix downloads were signed by someone other than me. Key/signatures delivered the same way. Looks like with flatpak no one would notice?

One would need to add the dev key to their keyring for this process to go thru. Much the same way as adding an outside apt repo to Whonix.

2 Likes

HulaHoop:

One would need to add the dev key to their keyring for this process to go thru. Much the same way as adding an outside apt repo to Whonix.

Then it sounds ok. I was missing that step in @torjunkie 's instructions
above or overlooked.

In any case, please proceed @torjunkie.

1 Like

Tox is also alpha software which has not been formally audited, therefore it is less trusted.

formally audited is a very high hoop to jump through. Not much software has been formally audited ever. And even formal audit isn’t a “replaced brakes” alike operation. It’s like a “medical checkup”. It can mean many things, can be superficial and cheap or it can be super throughly and cost hundreds of thousands.

2 Likes

OK - will fix that.

One question is where HexChat & RetroShare sit in the recs list. Now we have:

  1. Ricochet IM
  2. Gajim
  3. Tox

Also, the “Change the System or Tor Browser Language” page has Qubes-Whonix applicable stuff in it e.g. Tor Browser language changes, so it should also be moved up to where the Keyboard page went (and out of the Non-qubes-whonix Only section of ToC). Plus, Whonix has lots of non-English users, so it will be a Whonix 1st step for many users i.e. keyboard + language changes e.g. German in your case.

http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/wiki/Language

We can mark the System Language Changes section as Non-Qubes-Whonix only in that page (although some bits of that look like they would work in Qubes-Whonix e.g. Korean and Russian language changes i.e. if they would work in Debian-9 TemplateVM, they would work in Whonix-WS TemplateVM and propogate?)

In fact, only “System - All languages” looks non-qubes-whonix specific.

1 Like

All the (huge) Bitcoin stuff here:

http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/wiki/Money#Bitcoin

Should be moved to a stand-alone page, and out of the Money page. And also listed as a stand-alone link on the main ToC with all the other crypto-currencies.

(Will also need a nice image then too @TNT_BOM_BOM if split off).

Then, the money page is a high-level overview. Of course, particular emphasis can be given to the reader reviewing the Bitcoin page in conjunction, since it is the most popular cryptocurrency by a wide margin.

1 Like

I guess:

  1. Ricochet IM
  2. Gajim
  3. HexChat
  4. RetroShare
  5. Tox

Is proper recommended order for recs?

Actually, much is KDE-specific or non-Qubes-Whonix only.

Some bits ‘kind of’ work in Qubes-Whonix. Russian instructions have Russian language appearing in all VM apps instead of English, just not Russian keyboard input even when set to default. Ditto Korean using dpkg-locales reconfig.

(e.g. keyboard input for Korean would require ibus-hangul or similar installed in TemplateVM, which allows easy switching. Proper presentation of all characters would also require fonts-unfonts-core. That seems to work in Debian 9, so would work in whonix-ws-14 templateVM. Russian would have similar steps).

So I guess leave it where it is and don’t bother with instructions for Qubes-Whonix i.e. user’s / Qubes OS documentation problem (“not our bug”). The Tor Browser page already has a link to changing Tor Browser language bit (which covers off Qubes-Whonix), so that’s fine.

I’m not sure there is actually a full language presentation change that is possible system-wide for Qubes i.e. every menu, every dropdown, dom0, Qubes Manager etc appearing in Japanese, or Russian or whatever? Probably they haven’t implemented full language features yet since it would be a huge task?

I don’t see any instructions for that on their wiki or docs - so maybe users are stuck with English, system-wide presentation at least.

1 Like
Gajim
HexChat
Ricochet IM
Tox
RetroShare

Gajim: better usability, more jabber users, offline messages.
Ricochet IM: lengthy setup
Tox: not packaged for Debian
RetroShare: Outdated keys.
HexChat: not really a messenger but I guess it is ok to be left there since it’s Chat.

2 Likes

https://www.whonix.org/wiki/Whonix_Live instructions are still a bit “wild”. These are correct by the letter, technical, “method focused” but these are not unified blocks to be consumed by less-technical users who just want step by step instructions that just work.

Once that is fixed I agree, Whonix Live deserves to be promoted in much more popular places on our website.

1 Like

The formatting now should help.

HexChat, ZeroNet & IM messenger overview page -> all fixed.

Just RetroShare, MixMaster and Signal to fix in that section.

1. I gather RetroShare works in (Qubes-)Whonix, but that just some of the security issues could be tighter? e.g.

https://github.com/RetroShare/RetroShare/issues/356

&

https://phabricator.whonix.org/T560

On the wiki page, it says:

“INCOMPLETE - Depends on unimplemented features for Whonix”

That makes it sound like it doesn’t work, instead of (the probable intended meaning) “It works, but not with the best possible anonymity/security settings”.

2. Signal stuff says “Incomplete”. If it doesn’t work with those steps and it is just a basic skeleton, then I think we remove it from the main ToC i.e. because it is non-functional and not up to wiki standard for users.

3. That MixMaster page needs major reworking the way all the content is across 2 pages (Nym Server stuff can stay separate). Right now the main page is less useful than some of the Dev stuff.

Could someone please write a call for testers news for https://www.whonix.org/wiki/Whonix_Live?

3 Likes
  1. Unclear. If I am not mistaken, @HulaHoop wrote that. It’s been years since I tested RetroShare and lost interest since due to ceased development.

Nit: says unfinished rather than incomplete.
To answer your question: The instructions work as is but they are not elaborate / not pretty, not referencing usual disclaimers from https://www.whonix.org/wiki/Install_Software.
Sometimes I am using the wiki as a scratch pad. I don’t mind about the ToC entry but I would like to keep the page even if noindexed.

https://www.whonix.org/wiki/Dev/Mixmaster is a scratch pad with all the setup that was initially required. Most of it has been applied by default to Whonix to improve usability. So instructions on https://www.whonix.org/wiki/Mixmaster alone should be enough. That page was created during an earlier period of Whonix development where I wanted to show that almost anything can be combined with Whonix. (Kinda unlikely being an actual user of ZeroNet, Jondonym, i2p, mixmaster, remailers, proxy, ssh, VPN, bitmessage, various chat, voip and crypto currency clients, ftp, ssh, vnc, usenet, yacy, rss, freenet, gnunet, and whatnot. Some things were interesting for a time but then dropped.)
Haven’t used in years and unclear user interest. That might explain the “rotten” state of some things. Luckily many applications change little over time so things remain useful. Appreciate all efforts of upkeep!

1 Like

i suggest being hesitant with gajim. for vanilla use over tor, it worked well enough. however, once i started trying to use omemo effectively, there were a lot of pitfalls. in some instances, it failed open (ie. unencrypted message sent). also, i was running into a bug here and there which i could not isolate. basically, a number of the tick boxes in the “privacy” section of “preferences -> advanced” would re-enable after i disabled them for some reason. additionally, unless there has been a sea change, there is no functional otr plugin for gajim at the moment.

2 Likes

Reinstalling Qubes-Whonix TemplateVMs page created and finished. Mistakenly added all content using admin privileges so I deleted page and started over. Also I’m not sure about the page title. Know it needs to be a redirect from Qubes/ ?

https://whonix.org/w/index.php?title=Reinstall_Qubes-Whonix_TemplateVMs&oldid=39242&diff=cur

2 Likes
[Imprint] [Privacy Policy] [Cookie Policy] [Terms of Use] [E-Sign Consent] [DMCA] [Contributors] [Investors] [Priority Support] [Professional Support]