Whonix 18.2, a distribution for anonymous communications, is released

The Whonix 18.2 distribution, aimed at providing guaranteed anonymity, security, and privacy protection, has been released. The distribution is based on Debian GNU/Linux and uses Tor to ensure anonymity. The project's work is licensed under the GPLv3 license. Images are available for download. virtual machines in ova format for VirtualBox (2.6 GB with LXQt and 1.5 GB console) and qcow2 for the KVM hypervisor (4 GB with LXQt and 2.3 GB console).

A distinctive feature of Whonix is ​​the distribution's division into two separately executable components: Whonix-Gateway, which implements a network gateway for anonymous communications, and Whonix-Workstation, which contains a desktop. The components are separate system environments, delivered within a single boot image and run in different environments. virtual machinesAccess to the network from the Whonix-Workstation environment is only possible through the Whonix-Gateway, which isolates the work environment from direct interaction with the outside world and allows only the use of fictitious network addresses. This approach protects the user from real-world data leakage. IP addresses in the event of a web browser being hacked or a vulnerability being exploited that gives the attacker root access to the system.

Hacking Whonix-Workstation will allow the attacker to obtain only fictitious network parameters, since the real IP and DNS parameters are hidden behind the border of a network gateway powered by Whonix-Gateway, which routes traffic only through Tor. It should be taken into account that Whonix components are designed to run in the form of guest systems, i.e. the possibility of exploitation of critical 0-day vulnerabilities in virtualization platforms that can provide access to the host system cannot be ruled out. Due to this, it is not recommended to run Whonix-Workstation on the same computer as Whonix-Gateway.

Whonix-Workstation comes with the LXQt user environment by default. It includes programs such as VLC and Tor Browser. Whonix-Gateway comes with a set of server applications, including Apache httpd, ngnix, and IRC servers, which can be used to run Tor hidden services. Tunneling over Tor is possible for Freenet, i2p, JonDonym, SSH, and VPNIf desired, the user can use only Whonix-Gateway and connect their usual systems through it, including Windows, which allows for anonymous access to existing workstations.

The system environment is based on the protected distribution Kicksecure, which is being developed in parallel by the same developers and expands Debian Additional mechanisms and settings for increased security: AppArmor for isolation, installing updates via Tor, using the tally2 PAM module to protect against password guessing, expanding the entropy for RNG, disabling SUID, not opening network ports by default, using recommendations from the KSPP (Kernel Self Protection Project), adding protection against leakage of CPU activity information, etc.

Major changes:

  • Updated the Kicksecure environment to use the Sequoia-PGP package (an OpenPGP implementation in Rust) instead of GnuPG, and disable the repository by default. Debian Fast Track: When using LXQt, the installation of Qps (an interface for viewing running processes) has been stopped; support for qemu:///session has been added for running virtual machines by unprivileged users.
  • An internal security audit has been conducted and an external audit has been initiated.
  • Improved Kloak package, used to counter user identification based on keyboard input and mouse movements.
  • The Qubes-Whonix-Gateway distribution includes the fwupd-qubes-vm package.
  • Rewritten by Whonix-Windows-Installer and Whonix-Windows-Starter.
  • Improved build for devices with Apple Silicon processors.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster