Release of Whonix 17.2, a distribution for ensuring anonymous communications

The release of Whonix 17.2 is now available, aimed at providing guaranteed anonymity, security, and privacy protection. The distribution is based on Debian GNU/Linux and uses Tor for anonymity. The project development is released under the GPLv3 license. Virtual machine images are prepared for download in OVA format for VirtualBox (2.1 GB with Xfce and 1.4 GB console). The image can also be converted for use with the KVM hypervisor.

A feature of Whonix is the separation of the distribution into two separately launchable components—Whonix-Gateway, which implements a network gateway for anonymous communications, and Whonix-Workstation with a desktop environment. Both components are provided within a single bootable image. Network access from the Whonix-Workstation environment occurs only through the Whonix-Gateway, isolating the working environment from direct interaction with the outside world and allowing the use of only obfuscated network addresses. This approach protects the user from leaking real information. an IP address in the event of a web browser compromise and even during exploitation of a vulnerability that grants the attacker root access to the system.

Hacking Whonix-Workstation would allow the attacker to obtain only dummy network parameters, as the real IP and DNS parameters are hidden behind the boundary of the network gateway operating on the basis of Whonix-Gateway, which directs traffic solely through Tor. It should be noted that Whonix components are designed to run as guest systems, meaning there is a possibility of exploiting critical 0-day vulnerabilities in virtualization platforms that could grant access to the host system. Therefore, it is not recommended to run Whonix-Workstation on the same computer as Whonix-Gateway.

Whonix-Workstation by default provides a customized Xfce environment. The package includes programs such as VLC, Tor Browser, Thunderbird+TorBirdy, Pidgin, and more. The Whonix-Gateway package contains a set of server applications, including Apache httpd, nginx, and IRC servers, which can be used to facilitate the operation of hidden Tor services. Tunnel forwarding over Tor for Freenet, i2p, JonDonym, and SSH is also possible. VPNYou can find a comparison of Whonix with Tails, Tor Browser, Qubes OS TorVM, and corridor on this page. If desired, the user can only use Whonix-Gateway and connect their regular systems through it, including Windows, which provides the ability to ensure anonymous access for workstations already in use.

Release of Whonix 17.2, a distribution for ensuring anonymous communications

Key Changes:

  • The builds based on the secure distribution components of Kicksecure have been updated, extending Debian with additional mechanisms and settings to enhance security (AppArmor for isolation, updates via Tor, using the PAM module tally2 to prevent password guessing, enhancing entropy for RNG, disabling suid, no open network ports by default, employing recommendations from the KSPP project (Kernel Self Protection Project), adding protection against leaking CPU activity information, etc.).
  • Connection to the Tor network is provided by default (without invoking the connection wizard upon first boot). Users who require direct connections to the network are offered to separately invoke the ACW (Anon Connection Wizard).
  • The Whonix-Firewall has been transitioned from iptables to nftables.
  • Enhanced support for IPv6.
  • Work continues on the experimental Live build of Whonix-Host, equipped with an installer. The build is based on the Kicksecure environment and is designed to provide a secure host environment for running virtual machines with 'Whonix-Gateway' and 'Whonix-Workstation'.
  • The versions of Tor and Tor Browser have been updated.
  • Changes have been made to support the decentralized P2P network Bisq 2, intended for cryptocurrency trading and exchange.
  • Templates for the Qubes OS have been updated. The transition from pulseaudio to pipewire has been completed. For routing traffic through Tor, tinyproxy and the SOCKS protocol have been implemented.
  • When running under the KVM hypervisor, the RAM size for the Whonix-Gateway virtual machine has been increased to 1280 MB, and for Whonix-Workstation to 2048 MB, aligning with previously used settings for VirtualBox.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster