[HOME] [DOWNLOAD] [DOCS] [NEWS] [SUPPORT] [TIPS] [ISSUES] [CONTRIBUTE] [DONATE]

Long Wiki Edits Thread

https://www.whonix.org/w/index.php?title=Wickr&oldid=56181&diff=cur - not sure it’s fully Open Source.

https://github.com/WickrInc/wickr-crypto-c is only crypto core. Wikipedia says it’s proprietary. Possibly only partial source code release.

1 Like

I don’t think AMD’s SP should be mentioned on https://www.whonix.org/wiki/Out-of-band_Management_Technology

It’s not similar to the ME and isn’t a security risk. It’s the opposite. The SP is a security feature used for TEEs.

None of those arguments make sense. Obviously the CPU is privileged. The SP is no different from the rest of the CPU. The SP specifically is not an issue. TEEs are important. Why are Intel SGX, ARM TrustZone, RISC-V MultiZone etc. not mentioned there too if you think it’s such an issue?

Everything has vulnerabilities. You cannot expect the SP to be any different.

Arguably too cumbersome for me to personally do/take interest in. I like the software tool better. However @torjunkie seems to have done a great job formatting the process from the paper in:

http://dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/w/index.php?title=One_Time_Pad&stable=0&redirect=no

Do you need permission from the paper author to quote him to release the edit or what’s the problem?

1 Like

HulaHoop via Whonix Forum:

Do you need permission from the paper author to quote him to release the edit or what’s the problem?

I didn’t notice yet it was based on a paper. Now I did.

Yes, requires permission for sure. Paper doesn’t say it’s under any
libre license. Therefore defaults to copyrighted. Severity: blocker.

Links to website http://users.telenet.be/d.rijmenants/ quote:

This website is created for educational purposes and its content and
images are protected by international copyright laws. If you would like
to use the content of this website, please ask first and permission will
usually be granted under the condition that full credits and a link to
this website are given.

Another problem is that I would need to learn a lot more about the
subject or verification of authority.

Could you please remove the copyrighted content? @torjunkie

I’d remove it but I don’t want the formatting to be lost. Therefore feel
free to backup for own use.

Contacted

Name: Whonix Dev
E-mail address: whonix-devel@whonix.org
Subject: Use of text from paper on OTP
Your message: Hi Dirk, I am contacting you for permission to quote from your paper on our wiki for manually encoding OTP messages. The Whonix project is an online anonymity distro based on Tor and Debian.
3 Likes

Thanks @HulaHoop - really appreciated :slight_smile:

1 Like

Issues with hardware recommendations for other operating systems maintained by others, i.e. Qubes. Related documentation:

Issue specifically:

https://www.whonix.org/w/index.php?title=Qubes-Whonix_Security&type=revision&diff=57179&oldid=56933

Qubes (used to? still has) issues with other graphic cards. Best would be to stay out of hardware recommendations for Qubes and leave that to Qubes.

Issue generally:

  • the information might get outdated
  • the information might get contested (such as above). Time consuming to reason about, providing references.
  • it’s overextending the scope of Whonix project

The best place for Qubes hardware recommendations should be Qubes places, i.e. probably mostly Qubes website. If information on that website is bad, contribute to it. And if that’s not an option, well, bad luck but still not good to do that task for Whonix to maintain.

1 Like

A post was merged into an existing topic: [feature request] onionshare support

https://www.whonix.org/wiki/Kicksecure#iPhone_and_Android_Level_Security_for_Linux_Desktop_Distributions needs a rewrite/removal.

It’s dishonest to claim Kicksecure (even when all the hardening work is complete) is as secure as mobile platforms. Those have decades of work gone into hardening the security model.

Security is not just a checklist of features. Kicksecure’s sandboxing/MAC/verified boot/etc. isn’t even near iPhone/Android and there are numerous security enhancements in phones such as modern exploit mitigations or widespread memory safe languages that are not achievable with Kicksecure.

The claim that most Android devices have locked bootloaders is also dubious. Unlocking the bootloader and even using custom keys is part of the reference implementation.

And again, GNU/FSF are not good sources.

1 Like

A post was split to a new topic: Wickr Me vs Qubes-Whonix Persistence

OpenBazaar many users using it inside whonix , i get many questions about it. It would be nice if someone can contribute to fill the instructions about it.

But firstly can we have please wiki section for it? So that outside contributors can fill it as well.

I see here OpenBazaar in the wiki “Deprecated” section (dont know why):

http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/wiki/Deprecated#OpenBazaar

Hmm… ZeroNet various websites always results in this error: “Content.JSON Download Failed”. JS allowed on 127.0.0.1 and can see a number of peers so not sure what the problem is. Maybe like I2P you have to let it run for a long time beforehand?

Logs also show for various website attempts: “ContentDb not initialized, load files from filesystem…”

Have you succeeded in Qubes-Whonix @Patrick. Does about:config need some more tweaking perhaps? The home page works okay.

PS @madaidan Don’t waste all your talents & time on those reddit trolls. It’s like screaming into the void.

Spend more time over here doing your great development work! :slight_smile:

2 Likes

torjunkie via Whonix Forum:

Maybe like I2P you have to let it run for a long time beforehand?

Dunno. Conceivable.

Logs also show for various website attempts: “ContentDb not initialized, load files from filesystem…”

Have you succeeded in Qubes-Whonix @Patrick. Does about:config need some more tweaking perhaps? The home page works okay.

Last time I tested no such changes were required. I’ve tested very
little actual ZeroNet websites. Official links only. That worked for me
at that time.

Then why mention the full system MAC policy, hardened kernel, verified boot etc. at all?

Because that chapter illustrates Kicksecure development goals (new name
of chapter).

Whonix on USB search term has very poor results on search engines. No wiki page is suggested Related information https://www.whonix.org/wiki/System_Configuration_and_Access#Whonix_.E2.84.A2_on_External_Media is really hard to find.

Therefore moved that chapter to https://www.whonix.org/wiki/Template:Whonix_on_USB, and rewrote.

Created a dedicated wiki page for it:
https://www.whonix.org/wiki/Whonix_on_USB

Then why mention Android/iPhone?

I think the comparison table should be removed and a few more descriptive paragraphs written instead.

Because it shows that others managed to implement these features and it’s realistic to re-implement in Kicksecure - without adding any privacy issues or user freedom restrictions. It’s to tease and encourage other developers to catch up implementing some of the iPhone/Android security features in Linux (desktop) distributions too. If it gets added to Kicksecure that’s great, but if others focus on other Open Source Linux distributions that’s a net benefit too.

And if you’re wondering why it lists some disadvantages of iPhone/Android are listed, that’s to show in how many ways others are messing up. Tor create awareness of these issues (precondition for fix) and to not mess up in similar ways in future. Illustrating project goals, values, awareness.

Concept of Open/Free/Libre Software is great. However, since the inception of the 4 original essential software freedoms, other issues came up sometimes called tivoization, malicious feature, antifeature, tyrant software, treacherous computing or DRM (digital restrictions management). Also data portability, open databases, open source hardware, first mover effects, network effects, and more.

We have enough walls of texts. Some like tables, some don’t. In this case I found a table to be looking good.

2 Likes

Not to the same extent. The page is saying that the security features in Android are the exact same in Kicksecure but better which isn’t true.

They mess up far less than Linux does.

It doesn’t matter if it looks good. It’s conveying incorrect information.

[Imprint] [Privacy Policy] [Cookie Policy] [Terms of Use] [E-Sign Consent] [DMCA] [Contributors] [Investors] [Priority Support] [Professional Support]