Whonix live mode / amnesia / amnesic / non-persistent / anti-forensics

As noticed in above forum thread, /boot isn’t write protected. Any idea how /boot could also be covered?

1 Like

grub-live ported to dracut would be great!

Debian feature request
Boot existing Host Operating System or VM into Live Mode (grub-live)
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=991276

replacing initramfs-tools with dracut

grub-live dracut support has been implemented.

1 Like

A post was merged into an existing topic: replacing initramfs-tools with dracut

When this becomes available will it be used in very much the same way one would use tails? Burn onto usb or dvdr then use it as an OS like tails?

This feature is already available. See links to wiki (edit) in initial post in this forum thread.

Thanks for getting back. But isn’t there something still in development where we would be able to boot a usb stick or DVD and it will take us straight into the whonix environment? Whonix live ISO or something…Without using any virtual machine? If so is it ready for end users yet? Thanks again for response :grin:

You can combine

with

That’s the most you can get for now.

Future:

No ETA.

Cool… well I’d happily donate towards it I think it’s a great idea and am in full support of it. Unfortunately though with my lack of technical knowledge I can’t be of much help in that area :tired_face:

Added to Combine Kicksecure ™ Live VMs with Read-only Mode for Virtual Hard Drives chapter VirtualBox in Kicksecure wiki just now:

On Debian bookworm based Kicksecure ™ 17 (and above) / Newer VirtualBox versions:

  • VirtualBox might no longer support VBoxInternal/Devices/lsilogicsas/0/LUN#0/AttachedDriver/Config/ReadOnly. Settings set thorugh VBoxManage setextradata are not officially supported and might be gone at some time such as now.
  • VirtualBox documentation chapter Special Image Write Modesarchive.org mentions immutable images but this might not be as good as read-only images.

Above two issues are not easy to fix.

Help welcome!

Link to source code:

rootovl vs overlayfs discussed here:
Boot Existing, Usual Linux Installation from Hard Disk in Live Mode / read-only mode with dracut · Issue #1565 · dracutdevs/dracut · GitHub

https://www.reddit.com/r/Whonix/comments/15q7vcs/have_the_dev_team_tested_the_antiforensic/

1 Like

issue with older build versions still using initramfs-tools and fix: