Thanks for the reference. I think the upshot is there are sufficient further privacy features in whonix-workstation-17
to make it a better choice than debian-12-minimal
as a base template despite the larger footprint. Specifically:
uwt
wrappers- timezone obfuscation (UTC)
sdwdate
- “Other numerous security/privacy enhancements”, including kloak (someday)
I could implement them myself in a custom debian-12-minimal
but it would have to be careful work. Perhaps I could lightly trim down a custom whonix-workstation-17
as this user has done but it’s not clear it would be worthwhile.