The release of Whonix 18.0 is now available, aimed at providing guaranteed anonymity, security, and privacy protection. The distribution is based on Debian GNU/Linux and uses Tor for anonymity. The project's developments are distributed under the GPLv3 license. Virtual machine images have been prepared in ova format for VirtualBox (2.5 GB with LXQt and 1.6 GB console) and qcow2 for the KVM hypervisor (3.4 GB with LXQt and 2.3 GB console).
A distinctive feature of Whonix is the division of the distribution into two separately runnable components — Whonix-Gateway, which implements a network gateway for anonymous communications, and Whonix-Workstation, which provides a desktop environment. The components represent separate system environments packaged within a single boot image and run in different virtual machines. Network access from the Whonix-Workstation environment is conducted only through the Whonix-Gateway, isolating the working environment from direct interaction with the outside world and allowing only fake network addresses. This approach protects the user from leaking their real IP address in the event of a browser exploit or a vulnerability that grants an attacker root access to the system.
Compromising Whonix-Workstation would only allow an attacker to obtain fake network parameters, as the real IP and DNS settings are hidden behind the network gateway based on Whonix-Gateway, which routes traffic only through Tor. It's important to keep in mind that the Whonix components are intended to run as guest systems, so there is a risk of exploiting critical 0-day vulnerabilities in virtualization platforms that could provide access to the host system. Therefore, it is not recommended to run Whonix-Workstation on the same computer as Whonix-Gateway.
Whonix-Workstation defaults to a user environment of LXQt. The distribution includes programs such as VLC and Tor Browser. In the Whonix-Gateway package, you can find a set of server applications, including Apache httpd, ngnix, and IRC servers, which can be used to operate hidden Tor services. It is possible to tunnel over Tor connections for Freenet, i2p, JonDonym, SSH, and VPNIf desired, the user can rely solely on Whonix-Gateway and connect their regular systems through it, including Windows, which allows for anonymous access for workstations already in use.
The system environment is based on the parallelly developed secure distribution Kicksecure, which extends Debian with additional mechanisms and settings to enhance security: AppArmor for isolation, updates via Tor, the use of the PAM module tally2 to protect against password guessing, entropy expansion for RNG, disabling suid, no open network ports by default, adherence to recommendations from the KSPP (Kernel Self Protection Project), adding protection against information leaks about CPU activity, etc.
Key Changes:
- The package base of the distribution has been updated from Debian 12 to Debian 13.
- The Xfce desktop environment has been replaced with LXQt. The Wayland protocol is enabled by default.
- Included is the ram-wipe utility, which clears the contents of RAM before system reboot.
- The USBGuard package has been included to manage the activation of connected USB devices to protect against attacks via malicious USB devices, such as BadUSB.
- The privleap framework (analogous to sudo) is utilized to launch privileged processes.
- The nmap and nping utilities are included.
- xpdf has been removed from the distribution.
- The backlight-tool-dist package is used to manage backlighting.
- Packages set-system-keymap, set-console-keymap, set-labwc-keymap, and set-grub-keymap are employed to manage keyboard layouts.
- Boot time has been accelerated and memory consumption optimized.
- The Kloak package has been completely rewritten and ported to Wayland; it is used to counter user identification based on keyboard input patterns and mouse movement.
- Added support for IPv6.
- On the Whonix-Gateway side, the user-sysmaint-split package is enabled by default, implementing separate boot sessions for work and maintenance (SYSMAINT — system maintenance).
Source: opennet.ru
