Qubes-Whonix manual amnesic (maybe better?)

i wonder what is the different between Whonix being amnesic with DVD or on amnesic VM in qubes or manually deleting whonix appvm when finished from using and re-adding whonix appvm from whonix template ? here is my theoretical comparison:-

A- if we say that whonix going to be updated with each release on DVD for example whonix 11 or whonix 12 …etc and the gab between each release let say 1 month the advantage of that is , whonix will be on fixed/narrow media which is the DVD but the disadvantage of it , is the gab time (1 or X months) which may contain critical updates.

B- amnesic qubes-whonix VM:- tho it is not yet fixed , but theoretically it may be acting similar to the manual amnesic rather than the DVD one :point_down:.

C- manually amnesic qubes-whonix:- since whonix root in the templates VM and the functionality in the app VM , then if we delete the appvm eah time after we r finished from our jobs but with keeping the template forever or for longer time to long time reinstalling. it will give us:-
advantage on fixation the gab updates which is lacked feature in the DVD side. disadvantage of it will be higher surface of attack than the DVD one. because we should make sure that there is no successful hardware malicious attack on qubes VM, or parallel malicious vulnerability attack VM to VM or qubes itself compromised (dom0 bye).

so from technical/security point view i wonder which one is useful to recommend ? having updating gabs with narrow surface attack or having continuous updates with larger surface attack ?

To my knowledge, at time of writing, there is no Qubes Live DVD in the works. The Qubes installer DVD is not a Live DVD.

Deleting a TemplateBasedVM is not amnesic by definition, because files are written to the disk while you use it.

And deleting a TemplateBasedVM is not amnesic either, because they are to my knowledge not securely wiped and all traces removed. [If you want to call that this way - this is a Qubes - not a Whonix issue.]

For amnesic Qubes-Whonix we need to wait for DisposableVMs: support for in-RAM execution only (for anti-forensics) · Issue #904 · QubesOS/qubes-issues · GitHub and Whonix specific fixes. (Listed here - Qubes Disposables - and this is also where documentation can be found later once Qubes-Whonix can be used amnesic - goal is Whonix 13.)

1 Like

Good day,

They actually already offer an .ISO file for their lives USB beta: Download Qubes OS | Qubes OS

Have a nice day,

Ego

1 Like

For A: You could update the live dvd as you would update whonix normally. I’m not sure whether this will work in practice since some applications (would be good to know which ones) might require a reboot. Of course you need to run the update process again after each shutdown. Also you would maybe need more RAM for downloading packages and the like.

1 Like