Forwarded from 0โขBytesโข1
Welcome to my Alice tea party! ๐ซ๐
I decided to write a series of short posts about secure operating systems ๐ฅ๐ง
Today, we'll take a look at Whonix and find out if it's as good and anonymous as people say.Spoiler alert: no, it's not.
Let me clarify right away: Whonix is not a full-fledged operating system, but a tool for anonymity that can work independently or as a router in Qubes OS. In this article, I will focus on analyzing how it works as a standalone system
How does Whonix work?๐งฉ
Whonix is built on two virtual machines: Whonix-Gateway and Whonix-Workstation. Gateway configures and routes all your traffic through the Tor network. Workstation is your workplace. If you want to dig deeper, check out their documentation.
Problems with Whonix ๐
Now to the point: why Whonix isn't really necessary. Let's start with Gateway. It's just Debian with Tor pre-installed and a bunch of scripts that redirect traffic through Tor. Everything is tied to the configuration in the settings file and iptables rules. Cool? Not really. Plus, Whonix drags along old Debian, where packages are updated once in a blue moon.
Whonix positions itself as super protection against leaks, but if you don't understand what you're doing, no virtual machine will save you. For example, if you run a browser with JavaScript or download files and then open them outside of Workstation, your anonymity is gone.
By the way, Whonix can only be run without problems on VirtualBox. You may argue that there are versions for KVM/QEMU on their website. But that's where the problems begin. If you take Whonix for KVM, you won't be able to install it just like that โ you need to edit the configuration, and there are no detailed instructions on how to do this anywhere. With VirtualBox, however, there are no such problems โ everything works out of the box.
But what's wrong with VirtualBox?๐ชค
Besides the fact that it is significantly slower than KVM. In March 2025, a vulnerability CVE-2025-30712 with a rating of 8.1 appeared in Virtualbox. It allows an attacker with access to the host system to perform a VM escape, i.e., to get out of the virtual machine onto your main computer๐ซ . Proof-of-concept is already circulating on the network, and exploitation is easier than it seems. If the host is compromised, all your anonymity goes down the drain, and your real IP or other data may leak.
How to make an analogue of Whunix Gateway? โ๏ธ
But there is another way. The Gateway model itself is not bad. But you can create a machine with it yourself without Whunix, using a minimalist Linux (such as Gentoo or even FreeBSD instead of Linux). Then configure Tor directly. After all, Gateway is just a wrapper around the standard Tor and iptables settings, which can be found on Google in five minutes. Now add the iptables you found and DNSPort to the Tor config so that DNS requests also go through Tor, and that's it. This takes up less space and reduces the attack surface.
Conclusion
To be fair, Whonix isn't always bad. But it can be useful in conjunction with Qubes OS (where it runs in KVM, by the way), which has additional security mechanisms, such as domain isolation, that enhance security. But apart from Qubes, Whonix is pretty pointless. You might think it's suitable for those who don't want to bother with configuring Tor, but that's not the case. To run Whonix on a decent VM, such as KVM, you'll have to go through just as much trouble.
The bottom line is simple: Whonix is not a super-anonymous OS, but a tool that complicates life more than it protects it๐
I hope you found this useful.โค๏ธโจ If you wish, you can explore the topic yourself by reading research and testing the system.
Here are some good articles about Whonix:
THESIS.pdf โ here is an overview of anonymous operating systems, including Whonix.
Whonix and Tor Limitations โ about the shortcomings of Whonix and Tor.
JOSH Article โ analysis of Whonix limitations.
#anonymity #linux #whunix #cve #anonymity_os #tor #security
I decided to write a series of short posts about secure operating systems ๐ฅ
Today, we'll take a look at Whonix and find out if it's as good and anonymous as people say.
Let me clarify right away: Whonix is not a full-fledged operating system, but a tool for anonymity that can work independently or as a router in Qubes OS. In this article, I will focus on analyzing how it works as a standalone system
How does Whonix work?๐งฉ
Whonix is built on two virtual machines: Whonix-Gateway and Whonix-Workstation. Gateway configures and routes all your traffic through the Tor network. Workstation is your workplace. If you want to dig deeper, check out their documentation.
Problems with Whonix ๐
Now to the point: why Whonix isn't really necessary. Let's start with Gateway. It's just Debian with Tor pre-installed and a bunch of scripts that redirect traffic through Tor. Everything is tied to the configuration in the settings file and iptables rules. Cool? Not really. Plus, Whonix drags along old Debian, where packages are updated once in a blue moon.
Whonix positions itself as super protection against leaks, but if you don't understand what you're doing, no virtual machine will save you. For example, if you run a browser with JavaScript or download files and then open them outside of Workstation, your anonymity is gone.
By the way, Whonix can only be run without problems on VirtualBox. You may argue that there are versions for KVM/QEMU on their website. But that's where the problems begin. If you take Whonix for KVM, you won't be able to install it just like that โ you need to edit the configuration, and there are no detailed instructions on how to do this anywhere. With VirtualBox, however, there are no such problems โ everything works out of the box.
But what's wrong with VirtualBox?๐ชค
Besides the fact that it is significantly slower than KVM. In March 2025, a vulnerability CVE-2025-30712 with a rating of 8.1 appeared in Virtualbox. It allows an attacker with access to the host system to perform a VM escape, i.e., to get out of the virtual machine onto your main computer๐ซ . Proof-of-concept is already circulating on the network, and exploitation is easier than it seems. If the host is compromised, all your anonymity goes down the drain, and your real IP or other data may leak.
How to make an analogue of Whunix Gateway? โ๏ธ
But there is another way. The Gateway model itself is not bad. But you can create a machine with it yourself without Whunix, using a minimalist Linux (such as Gentoo or even FreeBSD instead of Linux). Then configure Tor directly. After all, Gateway is just a wrapper around the standard Tor and iptables settings, which can be found on Google in five minutes. Now add the iptables you found and DNSPort to the Tor config so that DNS requests also go through Tor, and that's it. This takes up less space and reduces the attack surface.
Conclusion
To be fair, Whonix isn't always bad. But it can be useful in conjunction with Qubes OS (where it runs in KVM, by the way), which has additional security mechanisms, such as domain isolation, that enhance security. But apart from Qubes, Whonix is pretty pointless. You might think it's suitable for those who don't want to bother with configuring Tor, but that's not the case. To run Whonix on a decent VM, such as KVM, you'll have to go through just as much trouble.
The bottom line is simple: Whonix is not a super-anonymous OS, but a tool that complicates life more than it protects it
I hope you found this useful.โค๏ธโจ If you wish, you can explore the topic yourself by reading research and testing the system.
Here are some good articles about Whonix:
THESIS.pdf โ here is an overview of anonymous operating systems, including Whonix.
Whonix and Tor Limitations โ about the shortcomings of Whonix and Tor.
JOSH Article โ analysis of Whonix limitations.
#anonymity #linux #whunix #cve #anonymity_os #tor #security
Please open Telegram to view this post
VIEW IN TELEGRAM
Whonix
Whonix Documentation
A Crash Course in Anonymity and Security on the Internet.
Forwarded from The Cradle
Media is too big
VIEW IN TELEGRAM
โWe treat these civilians in Gaza worse than we treated the ISIS fighters that surrendered in Baghuz Fawqani in Syria in 2018.โ
Retired US soldier who worked at the GHF death traps recounts how little Palestinian boy Amir, who walked 12 kilometers for a handful of lentils, was shot dead by Israeli soldiers moments after receiving the food.
Retired US soldier who worked at the GHF death traps recounts how little Palestinian boy Amir, who walked 12 kilometers for a handful of lentils, was shot dead by Israeli soldiers moments after receiving the food.
Forwarded from No BS it's the Jewsยฎ๏ธ
Tired of getting played...
American Eagle Outfitters _Aeo ad
Jews keep dangling low hanging w's
For a reason. Shiny - using our struggle as Whites for pR and shekels increase...
Jew Schottenstein became chairman of American Eagle Outfitters in 1992 and held the position of CEO from 1992 to 2002, and since December 2015 to Current 2025.
Jerome Schottenstein, are responsible for forging the path that led AEO from its first signature denim line in 1997 to well over $1 billion in annual jeans sales โ and the #1 jeans brand in its demographic and #1 for women across all ages.
American Eagle Outfitters _Aeo ad
Jews keep dangling low hanging w's
For a reason. Shiny - using our struggle as Whites for pR and shekels increase...
Jew Schottenstein became chairman of American Eagle Outfitters in 1992 and held the position of CEO from 1992 to 2002, and since December 2015 to Current 2025.
Jerome Schottenstein, are responsible for forging the path that led AEO from its first signature denim line in 1997 to well over $1 billion in annual jeans sales โ and the #1 jeans brand in its demographic and #1 for women across all ages.
This media is not supported in your browser
VIEW IN TELEGRAM
American Eagle's Stock - $AEO has SURGED over 24% since Sydney Sweeney's Jean Ad's
ADDING +$400 MILLION of market cap
https://x.com/ThePatriotOasis/status/1950212500219158700
#bds
ADDING +$400 MILLION of market cap
https://x.com/ThePatriotOasis/status/1950212500219158700
#bds
Coal Davis (the Australian nazi negro) just provided the supposed text message evidence proving that associates of Avi paid him to disrupt the "Zionist Christian" event.
If this is the same Joseph Cohen from https://x.com/israel_advocacy who was recently seen speaking with https://x.com/OzraeliAvi only the other day, then that's huge. He is probably one of the most prominent pro-zionist content creators currently.
X link to thread: https://x.com/Whats_Newsss/status/1950344238761464042
If this is the same Joseph Cohen from https://x.com/israel_advocacy who was recently seen speaking with https://x.com/OzraeliAvi only the other day, then that's huge. He is probably one of the most prominent pro-zionist content creators currently.
X link to thread: https://x.com/Whats_Newsss/status/1950344238761464042
Forwarded from Derrick Broze's Daily News
One of the problems with people obsessing over the Democrats, the Republicans, the Jews, the Jesuits, the Masons etc is they believe all we must do is remove this group and humanity will thrive.
They ignore the fact that it is the institution of the State which is the problem.
You can remove "The Jews" from power but that won't stop other humans from desiring to control and manipulate the lives of other humans. These psychopaths will always seek to use the institution of the state for their own benefit.
It doesn't matter if you somehow remove your favorite villain from the equation if we continue to think that using government is going to solve our problems. The immoral, non-consensual, and non-voluntary relationship with government is the hindrance to humanity's liberation.
They ignore the fact that it is the institution of the State which is the problem.
You can remove "The Jews" from power but that won't stop other humans from desiring to control and manipulate the lives of other humans. These psychopaths will always seek to use the institution of the state for their own benefit.
It doesn't matter if you somehow remove your favorite villain from the equation if we continue to think that using government is going to solve our problems. The immoral, non-consensual, and non-voluntary relationship with government is the hindrance to humanity's liberation.
This media is not supported in your browser
VIEW IN TELEGRAM
That time Alex Jones casually dropped that we live in a holographic prison controlled by transcendent interdimensional elites
JRE #911 (2017)
JRE #911 (2017)
Forwarded from It's FOSS
Users of Arch Linux and Arch-based distros take note.
https://news.itsfoss.com/arch-linux-chaos-rat/
https://news.itsfoss.com/arch-linux-chaos-rat/
It's FOSS
Someone Slipped a RAT into Arch Linux!
A sneaky menace made its way into Arch User Repository. Another reminder to not blindly trust packages from AUR, PPA and even from Snapcraft.
Forwarded from It's FOSS
Lumo is Proton's privacy-friendly AI assistant. ๐ค
https://news.itsfoss.com/proton-lumo-experience/
https://news.itsfoss.com/proton-lumo-experience/
It's FOSS
I Tried Proton's Lumo AI, a Private Alternative to ChatGPT
Tired of ChatGPT Tracking You? Proton is now offering an end-to-end encrypted AI chats with no data logging or tracking. Here's my experience with it.
Share files quickly between Linux and Android with these apps.
https://itsfoss.com/file-transfer-apps-linux-android/
#file #transfer #share
https://itsfoss.com/file-transfer-apps-linux-android/
#file #transfer #share
It's FOSS
5 Open Source Apps You Can use for Seamless File Transfer Between Linux and Android
Want to share selected files between your Android smartphone and Linux computer? Explore these open source tools.
Data Leak at Corbett Report (and Many Other Sites)!
There has been a data leak at The Corbett Report. One of the latest updates of the GiveWP Wordpress plugin "accidentally" started publishing the email addresses and usernames of some (but not all) Corbett Report users to the source code of the site. The plugin has been deactivated and the email addresses are no longer exposed, but the email addresses were already caught by the spambots. Tens of thousands of websites use this plugin and I was able to personally verify a number of websites where this was happening. UPDATE: GiveWP has finally patched this massive security flaw with their latest update but are still trying to downplay the problem and limit discussion of it in their own forum. Will literally any data security researcher actually publish anything about this massive data leak of email addresses?
I am in the process of emailing every email address that was exposed by this, but if you are a Corbett Report member who has any questions or concerns about this, please contact me directly.
https://corbettreport.com/data-leak-at-corbett-report/
There has been a data leak at The Corbett Report. One of the latest updates of the GiveWP Wordpress plugin "accidentally" started publishing the email addresses and usernames of some (but not all) Corbett Report users to the source code of the site. The plugin has been deactivated and the email addresses are no longer exposed, but the email addresses were already caught by the spambots. Tens of thousands of websites use this plugin and I was able to personally verify a number of websites where this was happening. UPDATE: GiveWP has finally patched this massive security flaw with their latest update but are still trying to downplay the problem and limit discussion of it in their own forum. Will literally any data security researcher actually publish anything about this massive data leak of email addresses?
I am in the process of emailing every email address that was exposed by this, but if you are a Corbett Report member who has any questions or concerns about this, please contact me directly.
https://corbettreport.com/data-leak-at-corbett-report/
The Corbett Report
Data Leak at Corbett Report (and Many Other Sites)! | The Corbett Report
I am in the process of emailing every email address that was exposed by this, but if you are a Corbett Report member who has any questions or concerns about this, please contact me directly.
Forwarded from The Cradle
Cracking Sanaa: The US-Israeli cyber war on Yemen
To fill their gaping intel void on Ansarallah, Tel Aviv and Washington have launched a covert intelligence war on Yemen. But a society steeped in resistance, coupled with Sanaaโs doctrine of silence, is proving far harder to breach than expected.
By Mawadda Iskandar
To fill their gaping intel void on Ansarallah, Tel Aviv and Washington have launched a covert intelligence war on Yemen. But a society steeped in resistance, coupled with Sanaaโs doctrine of silence, is proving far harder to breach than expected.
By Mawadda Iskandar