Whonix 17.3 release, a distribution for anonymous communications

The release of Whonix 17.3 has been made available, aimed at providing guaranteed anonymity, security, and privacy protection. The distribution is based on Debian GNU/Linux and utilizes Tor for anonymity. The project's developments are distributed under the GPLv3 license. Virtual machine images in ova format for VirtualBox (2.3 GB with Xfce and 1.5 GB console) have been prepared, which can be converted for use with the KVM hypervisor.

A key feature of Whonix is the separation of the distribution into two separately executable components — Whonix-Gateway with a network gateway implementation for anonymous communications and Whonix-Workstation with a desktop environment. The components represent separate system environments, provided within a single boot image and launched in different virtual machines. Network access from the Whonix-Workstation environment is only via the Whonix-Gateway, isolating the working environment from direct interaction with the outside world and allowing only the use of fake network addresses. This approach protects the user from the leakage of real an IP address in the event of a browser hack or exploitation of a vulnerability that gives the attacker root access to the system.

Hacking Whonix-Workstation would allow the attacker to obtain only dummy network parameters, as the real IP and DNS parameters are hidden behind the boundary of the network gateway operating on the basis of Whonix-Gateway, which directs traffic solely through Tor. It should be noted that Whonix components are designed to run as guest systems, meaning there is a possibility of exploiting critical 0-day vulnerabilities in virtualization platforms that could grant access to the host system. Therefore, it is not recommended to run Whonix-Workstation on the same computer as Whonix-Gateway.

Whonix-Workstation by default provides a customized Xfce environment. The package includes programs such as VLC, Tor Browser, Thunderbird+TorBirdy, Pidgin, and more. The Whonix-Gateway package contains a set of server applications, including Apache httpd, nginx, and IRC servers, which can be used to facilitate the operation of hidden Tor services. Tunnel forwarding over Tor for Freenet, i2p, JonDonym, and SSH is also possible. VPNIf desired, the user can rely solely on Whonix-Gateway and connect their regular systems through it, including Windows, which allows for anonymous access for workstations already in use.

Whonix 17.3 release, a distribution for anonymous communications

Key Changes:

  • In Whonix-Workstation with the Xfce desktop, the default user account is split into two different users: user — for everyday tasks, and sysmaint for system management and performing administrative tasks like updates and installing new software.
  • Updated builds based on the components of the secure distribution Kicksecure, which extends Debian with additional mechanisms and settings to enhance security: AppArmor for isolation, updating via Tor, use of the PAM module tally2 for protection against brute-force attacks, entropy extension for RNG, disabling suid, no open network ports by default, use of recommendations from the KSPP (Kernel Self Protection Project), and adding protection against information leakage about CPU activity, etc.
  • A welcome page has been added to whonix-welcome-page.
  • The application anon-gw-anonymizer-config is launched using the privleap framework (similar to sudo).
  • A new theme for the GRUB boot menu has been added.
  • The gnome-keyring has been added to the list of recommended packages, resolving issues with the Signal messenger.
  • The installation of the qubes-core-agent-passwordless-root package is no longer default in Whonix-Workstation.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster