Qubes-Whonix Security Disadvantages - Help Wanted!

** kloak** (Anti Keystroke Deanonymization)


Linux Kernel Runtime Guard (LKRG)


tirdad (TCP ISN CPU Information Leak Protection.)


Kernel Hardening through Kernel Boot Parameters


Strong Linux User Account Separation / Protection against Bruteforcing Linux User Account Passwords



apparmor-profile-everything (AAE) (AppArmor for everything. APT, systemd, init, all systemd units, all applications)


hardened-kernel (HK) patch and config

  • In development.
  • Proof of concept functional in Non-Qubes-Whonix.
  • Broken in Qubes-Whonix.
  • Only developed for Non-Qubes-Whonix by @madaidan.
  • Nobody working on Qubes-Whonix support.
  • github / forum discussion
  • 2024 update: HK is deprecated in Whonix.

Please help fixing these issues!

2 Likes

My impression is that Simplify and promote using in-vm kernel · Issue #5212 · QubesOS/qubes-issues · GitHub will fix a lot of those issues, is that correct?

1 Like

Yes.

1 Like

Why can’t Qubes just use grub.d? Why would it require another kernel?

1 Like

Because Qubes uses at this time by Qubes default a kernel supplied by dom0 (host). Not kernel supplied by VM. VM grub.d / grub.cfg is ignored by default. This might change in future as per ticket Simplify and promote using in-vm kernel · Issue #5212 · QubesOS/qubes-issues · GitHub.

2 Likes

Can we trust that the changes on the default kernel option will land some time soon?
Is there an alternative solution to this, like running the whonix gw and ws as HVMs (maybe?) to provide the security mechanisms?

1 Like

Welcome to Whonix forums and thank you for your question!

No.

Unsupported.

1 Like

Are there any updates on this?

1 Like

No.

1 Like

Hi all, is this topic up-to-date? I looked through what I could on Github. For instance, the first issue, it seems there is still some work to do, but hopefully recent developments will help resolve the issue. And it seems the workaround is to just write what you want to within a notepad and paste the contents into your browser (that ideally doesn’t have JS enabled).

Thanks for your time :slightly_smiling_face:

1 Like

Should there be any substantial updates, these will be notified in the linked tickets.

1 Like

Above post has been updated just now.

1 Like