Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upQubes Whonix-Gateway should have persistent /var/lib/tor to make entry guards persistent like non-Qubes Whonix Gateway #1137
Comments
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Aug 19, 2015
Member
Currently Whonix-Gateway VMs have volatile /var/lib/tor, which means that entry guards are not saved across reboots, which is potentially dangerous since persisting them mitigates against attackers who set up malicious entry guards.
This behavior also differs from the non-Qubes Whonix Gateway, which is surprising for users who move to Qubes.
Confirmed. Agreed.
Actually, having the whole /var being persistent on all Qubes VMs seems the most reasonable approach, since being persistent, mutable and per-machine is pretty much the whole point of /var, but that's a separate consideration and there might be reasons I'm missing to do it like Qubes does now.
That should be discussed elsewhere.
Confirmed. Agreed.
That should be discussed elsewhere. |
added a commit
to Whonix/qubes-whonix
that referenced
this issue
Aug 19, 2015
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Fixed with the above commit. Will appear in Whonix 12. |
qubesuser commentedAug 19, 2015
Currently Whonix-Gateway VMs have volatile /var/lib/tor, which means that entry guards are not saved across reboots, which is potentially dangerous since persisting them mitigates against attackers who set up malicious entry guards.
This behavior also differs from the non-Qubes Whonix Gateway, which is surprising for users who move to Qubes.
Actually, having the whole /var being persistent on all Qubes VMs seems the most reasonable approach, since being persistent, mutable and per-machine is pretty much the whole point of /var, but that's a separate consideration and there might be reasons I'm missing to do it like Qubes does now.