Privacy/security considerations for templates of qubes that route through sys-whonix

Thanks for the reference. I think the upshot is there are sufficient further privacy features in whonix-workstation-17 to make it a better choice than debian-12-minimal as a base template despite the larger footprint. Specifically:

  • uwt wrappers
  • timezone obfuscation (UTC)
  • sdwdate
  • “Other numerous security/privacy enhancements”, including kloak (someday)

I could implement them myself in a custom debian-12-minimal but it would have to be careful work. Perhaps I could lightly trim down a custom whonix-workstation-17 as this user has done but it’s not clear it would be worthwhile.