The release of Whonix 18.1 is available, aimed at providing guaranteed anonymity, security, and privacy protection. The distribution is based on Debian GNU/Linux and utilizes Tor for anonymity. The project's developments are distributed under the GPLv3 license. Images have been prepared for download, of virtual machines in ova format for VirtualBox (2.6 GB with LXQt and 1.6 GB console) and qcow2 for the KVM hypervisor (3.8 GB with LXQt and 2.2 GB console).
A key feature of Whonix is the separation of the distribution into two independently bootable components — Whonix-Gateway, which implements a network gateway for anonymous communications, and Whonix-Workstation with its desktop environment. These components are separate system environments provided within one bootable image and launched in different virtual machines. Network access from the Whonix-Workstation environment occurs only through the Whonix-Gateway, isolating the working environment from direct interaction with the outside world and allowing only dummy network addresses. This approach protects the user from leaking real an IP address in the event of a browser hack or exploitation of a vulnerability that gives the attacker root access to the system.
Hacking Whonix-Workstation would allow the attacker to obtain only dummy network parameters, as the real IP and DNS parameters are hidden behind the boundary of the network gateway operating on the basis of Whonix-Gateway, which directs traffic solely through Tor. It should be noted that Whonix components are designed to run as guest systems, meaning there is a possibility of exploiting critical 0-day vulnerabilities in virtualization platforms that could grant access to the host system. Therefore, it is not recommended to run Whonix-Workstation on the same computer as Whonix-Gateway.
Whonix-Workstation by default provides a user environment based on LXQt. It includes applications such as VLC and Tor Browser. The Whonix-Gateway supply includes a set of server applications, including Apache httpd, ngnix, and IRC servers, which can be used to organize the operation of hidden Tor services. Tunneling over Tor for Freenet, i2p, JonDonym, SSH, and VPNIf desired, the user can rely solely on Whonix-Gateway and connect their regular systems through it, including Windows, which allows for anonymous access for workstations already in use.
The system environment is based on the securely developed Kicksecure distribution, which expands Debian with additional mechanisms and settings to enhance security: AppArmor for isolation, updates installed through Tor, the use of the PAM module tally2 for protection against password guessing, increased entropy for RNG, disabling suid, no open network ports by default, following recommendations from the KSPP (Kernel Self Protection Project), and adding protection against leakage of CPU activity information, etc.
Key Changes:
- The Kicksecure environment has been updated, significantly improving support for UEFI Secure Boot — new helper utilities have been added, DKMS security for building has been enhanced, the configuration interface has been expanded, and new diagnostic features have been introduced. Automatic mounting of drives is disabled by default. The installer interface and user interface based on LXQt have been improved. Confirmation for multi-line clipboard pasting in the qterminal has been enabled. A utility for setting screen resolution has been added.
- In Whonix-Workstation, automatic screen resolution changes after resizing the virtual machine window are disabled by default. This will block the use of information about non-standard or frequently changed screen sizes for indirect system identification.
- Disabling IPv6 has been simplified.
- For the SOCKS protocol, the torS0X extension has been implemented for isolating streams with Tor traffic.
Source: opennet.ru
