Onionizing Qubes-Whonix Repositories

Ticket created.
use onion sources list for apt-get updating by default
https://phabricator.whonix.org/T812


Status:

Due to flakiness of onion v4 this should be postponed.

A fix has been implemented and is expected to arrive in Tor 0.3.5 in December.


While we are at it… Should we separate Whonix webiste onion and Whonix repository onion? We would keep Whonix website onion as is (even functional for apt-get to not break it for anyone) but the next upgrade of Whonix wuould move everyone else to a another, fresh onion address.

Why?

  • separate website and apt-get downloads
  • future-proof with respect to future server load
  • we could move apt-get downloads to a different server when needed

Should we even create 2-10 or even 10-100 different onion domains and randomly assign Whonix users one? Why: load balancing. Why not: probably overkill. Debian manages without such gymnastics. But they don’t have onion v3 yet as far as I know.

Perhaps we’ll wait for onionbalance v3 support?

Research on this is low priority due to above status.

//cc @mig5

1 Like