Whonix KVM dnsmasq - listen port on host operating system - attack surface reduction

I hate to be the bearer of bad news, but our security choices and improvements do have a unique fingerprint on the network for those who want to look. The fact we disable TCP timestamps and remove TCP ISNs is readily apparent. Rather than stick to the less secure defaults that can endanger users in other ways, we have chosen to move ahead and adopt these improvements.
.
If having a firewall solves this - which I think Patrick said, then the solution is easy enough to apply and I hope satisfactory

2 Likes