Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upDocument Torified update checking #1948
Comments
andrewdavidwong
added
enhancement
C: doc
P: minor
labels
May 4, 2016
andrewdavidwong
added this to the
Documentation/website milestone
May 4, 2016
andrewdavidwong
added
help wanted
C: Whonix
privacy
labels
Mar 18, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
unman
Mar 22, 2018
Member
I've pushed some changes to qubes-doc adding more information on update checking etc in 3.2 and 4.0.
dom0, and in qubes
Can you review please @adrelanos and @andrewdavidwong ?
If you're happy, close this.
|
I've pushed some changes to qubes-doc adding more information on update checking etc in 3.2 and 4.0. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Mar 23, 2018
Member
Thank you, @unman. I gather that you're referring to QubesOS/qubes-doc@0366878. Correct?
- Would you mind separating the 3.2 and 4.0 content as prescribed in our Documentation Guidelines?
- I don't think this is an accurate description of how the UpdateVM works in 3.2. The UpdateVM is the VM in which dom0 updates are downloaded, not the VM that TemplateVMs use as their NetVM. Setting the UpdateVM to
sys-whonixwill not result in TemplateVMs downloading updates over Tor if those TemplateVMs still havesys-firewallas their NetVM. In fact, it will probably not even result in dom0's updates being downloaded over Tor, since traffic fromsys-whonixitself is not Torified.
In the future, if you'd like to have a doc contribution reviewed, please consider submitting it as a PR so that we can leverage our established doc contribution workflow.
|
Thank you, @unman. I gather that you're referring to QubesOS/qubes-doc@0366878. Correct?
In the future, if you'd like to have a doc contribution reviewed, please consider submitting it as a PR so that we can leverage our established doc contribution workflow. |
added a commit
to QubesOS/qubes-doc
that referenced
this issue
Mar 23, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Mar 23, 2018
Member
I've reverted QubesOS/qubes-doc@0366878 for now, since the risk of deanonymization from following these instructions has the potential to be dangerous for some users. Perhaps we could take this opportunity to have the revised content submitted as a PR for further review?
|
I've reverted QubesOS/qubes-doc@0366878 for now, since the risk of deanonymization from following these instructions has the potential to be dangerous for some users. Perhaps we could take this opportunity to have the revised content submitted as a PR for further review? |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
unman
Mar 23, 2018
Member
@andrewdavidwong I wasn't actually expecting that to hit the site - in the past when I've pushed changes to qubes-docs they haven't automatically been applied. Apologies.
You're quite right, of course for 3.2 Templates, but not, I think, for dom0 - the existing page says that setting UpdateVM to sys-whonix will torify dom0 updates, so I think the addition to that section should be fine.
|
@andrewdavidwong I wasn't actually expecting that to hit the site - in the past when I've pushed changes to qubes-docs they haven't automatically been applied. Apologies. You're quite right, of course for 3.2 Templates, but not, I think, for dom0 - the existing page says that setting UpdateVM to sys-whonix will torify dom0 updates, so I think the addition to that section should be fine. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Mar 23, 2018
Member
You're quite right, of course for 3.2 Templates, but not, I think, for dom0 - the existing page says that setting UpdateVM to sys-whonix will torify dom0 updates, so I think the addition to that section should be fine.
I see that portion was added over two years ago in QubesOS/qubes-doc@6b8b0ec. However, given that traffic from sys-whonix itself is usually not Torified, I'd love to get confirmation from @marmarek that it actually works as described.
I see that portion was added over two years ago in QubesOS/qubes-doc@6b8b0ec. However, given that traffic from sys-whonix itself is usually not Torified, I'd love to get confirmation from @marmarek that it actually works as described. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
Mar 23, 2018
Member
However, given that traffic from sys-whonix itself is usually not Torified, I'd love to get confirmation from @marmarek that it actually works as described.
That was true about old TorVM. Whonix Gateway have appropriate handling to route dom0 updates through tor (uwt wrapper), when it's set as updatevm.
That was true about old TorVM. Whonix Gateway have appropriate handling to route dom0 updates through tor (uwt wrapper), when it's set as updatevm. |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
|
Ok, great! Thanks, @marmarek! |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Mar 23, 2018
Member
|
Andrew David Wong:
However, given that traffic from sys-whonix *itself* is usually not Torified
It it, always was and will be. :)
What we're away from Qubes being 100% torified is sys-whonix being
capable to act as a ClockVM. (Ticket exists on Whonix tracker.)
|
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
andrewdavidwong
Mar 24, 2018
Member
However, given that traffic from sys-whonix itself is usually not Torified
It it, always was and will be. :)
My mistake! I was confusing sys-whonix with TorVM. Thank you for the correction!
My mistake! I was confusing |
andrewdavidwong commentedMay 4, 2016
https://forums.whonix.org/t/does-dom0-check-update-go-over-tor/2334/2