Whonix live mode / amnesia / amnesic / non-persistent / anti-forensics

Not on purpose. I guess that happened because these boot options are only set when booting for example Whonix-Workstation VM into Live Mode. Therefore overlooked.

Yes, that would be good.

Kernel command line persistent mode changes from ⚓ T950 set kernel.printk sysctl to prevent kernel info leaks were not added yet. But not sure we should add them yet. It’s not time to lower verbosity for Whonix-Host boot yet.
Perhaps rather the opposite. Add more verbosity?

Btw installing package debug-misc on Whonix-Host ISO wouldn’t increase debugging because current implementation ignores that raw image’s /boot/grub/grub.cfg (which is created from /etc/default/grub.d, i.e. /etc/default/grub.d is ignored) (for now hardcoded).

Could use a script to sanity check if kernel boot parameters are sync (no differences for Whonix-Host ISO) but not easy.

Why are kernel boot paramaters (such as spectre_v2=on spec_store_bypass_disable=on tsx=off …) defined in both files:

is one redundant?

Could you please create tickets (separate forum topics) for anything that isn’t easy to resolve? [Don’t worry the forum tags too much. I can do these later.]

One is for GRUB (when booting in EFI), the other is for Isolinux (when booting in BIOS).

1 Like

Any idea how to debug this?

How now set Read-only Mode for VM?

This manual no longer work /wiki/VM_Live_Mode/Read_Only_Mode_Hard_Drive

It is also impossible to start VM with live mode on host. There is an error VERR_DISK_FULL

Not whonix issue:

“I thought it was the VirtualBox’s vdi hard disk drive that was full, but it was much easier. Just a “df -h” and I realized that my host disk was full!”

cc @Patrick maybe we can add this to:

1 Like

Anyone can use the live mod with the recent changes to AHCI? I can’t.

With VB 6.1.18 everything worked great. But wit VB 6.1.2 and with AHCI I can’t start a whonix VB in a live mode with live mode on host.

My disk has enough free space. When I used VB 6.1.18 with LisLogic SAS live mode on the host worked well and I was able to start whonix VB with a live mode on the host. But now when live mode is on on the host I got this error - VERR_DISK_FULL
Also now is impossible to switch AHCI VB to read only.

1 Like

Never mind VB issued version 6.1.22 with fixed LsiLogic SAS problem.

1 Like

Thanks for reporting the bug, Though im getting different error message:(Debian host)


and debian didnt yet upgraded vbox in sid yet to .22:


1 Like

As noticed in above forum thread, /boot isn’t write protected. Any idea how /boot could also be covered?

1 Like

grub-live ported to dracut would be great!

Debian feature request
Boot existing Host Operating System or VM into Live Mode (grub-live)

replacing initramfs-tools with dracut

grub-live dracut support has been implemented.

1 Like

A post was merged into an existing topic: replacing initramfs-tools with dracut

When this becomes available will it be used in very much the same way one would use tails? Burn onto usb or dvdr then use it as an OS like tails?

This feature is already available. See links to wiki (edit) in initial post in this forum thread.