The release of Whonix 18.2 has taken place, aimed at providing guaranteed anonymity, security, and privacy protection. The distribution is based on Debian GNU/Linux and uses Tor for anonymity. The project's developments are distributed under the GPLv3 license. Download images are prepared of virtual machines in ova format for VirtualBox (2.6 GB with LXQt and 1.5 GB console) and qcow2 for the KVM hypervisor (4 GB with LXQt and 2.3 GB console).
A key feature of Whonix is the separation of the distribution into two independently bootable components — Whonix-Gateway, which implements a network gateway for anonymous communications, and Whonix-Workstation with its desktop environment. These components are separate system environments provided within one bootable image and launched in different virtual machines. Network access from the Whonix-Workstation environment occurs only through the Whonix-Gateway, isolating the working environment from direct interaction with the outside world and allowing only dummy network addresses. This approach protects the user from leaking real an IP address in the event of a browser hack or exploitation of a vulnerability that gives the attacker root access to the system.
Hacking Whonix-Workstation would allow the attacker to obtain only dummy network parameters, as the real IP and DNS parameters are hidden behind the boundary of the network gateway operating on the basis of Whonix-Gateway, which directs traffic solely through Tor. It should be noted that Whonix components are designed to run as guest systems, meaning there is a possibility of exploiting critical 0-day vulnerabilities in virtualization platforms that could grant access to the host system. Therefore, it is not recommended to run Whonix-Workstation on the same computer as Whonix-Gateway.
Whonix-Workstation by default provides a user environment based on LXQt. It includes applications such as VLC and Tor Browser. The Whonix-Gateway supply includes a set of server applications, including Apache httpd, ngnix, and IRC servers, which can be used to organize the operation of hidden Tor services. Tunneling over Tor for Freenet, i2p, JonDonym, SSH, and VPNIf desired, the user can rely solely on Whonix-Gateway and connect their regular systems through it, including Windows, which allows for anonymous access for workstations already in use.
The system environment is based on the securely developed Kicksecure distribution, which expands Debian with additional mechanisms and settings to enhance security: AppArmor for isolation, updates installed through Tor, the use of the PAM module tally2 for protection against password guessing, increased entropy for RNG, disabling suid, no open network ports by default, following recommendations from the KSPP (Kernel Self Protection Project), and adding protection against leakage of CPU activity information, etc.
Key Changes:
- The Kicksecure environment has been updated, where instead of GnuPG, the Sequoia-PGP package (an OpenPGP implementation in Rust) is used, the Debian Fast Track repository is disabled by default, Qps (a process viewer interface) is no longer installed when using LXQt, and support for qemu:///session has been added for running virtual machines by unprivileged users.
- An internal security audit has been conducted, and an external audit has been initiated.
- The Kloak package has been enhanced, which is used to counter user identification based on keystroke patterns and mouse movement.
- The Qubes-Whonix-Gateway now includes the fwupd-qubes-vm package.
- The Whonix-Windows-Installer and Whonix-Windows-Starter have been rewritten.
- The build for devices with Apple Silicon processors has been improved.
Source: opennet.ru
