Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upDocument qubes.PostInstall service, `/etc/qubes/post-install.d`, qvm-features-request #2829
Comments
marmarek
added
C: doc
P: major
labels
May 26, 2017
marmarek
added this to the Release 4.0 milestone
May 26, 2017
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
marmarek
May 26, 2017
Member
@adrelanos can you list what dom0 changes you'd like for better privacy in Whonix VMs (both WS and GW)?
|
@adrelanos can you list what dom0 changes you'd like for better privacy in Whonix VMs (both WS and GW)? |
added a commit
to marmarek/old-qubes-core-agent-linux
that referenced
this issue
May 26, 2017
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
adrelanos
Jun 3, 2017
Member
@adrelanos can you list what dom0 changes you'd like for better privacy in Whonix VMs (both WS and GW)?
That's a pretty broad question.
Generally, not just dom0:
- Whonix related tickets: https://github.com/QubesOS/qubes-issues/issues?q=is%3Aissue+is%3Aopen+whonix+label%3A%22C%3A+Whonix%22
- privacy related tickets: https://github.com/QubesOS/qubes-issues/issues?q=is%3Aissue+is%3Aopen+whonix+label%3Aprivacy
dom0 specific:
- Disable speaker output for Whonix WS-based AppVMs by default - #2724
- Whonix default VM settings fixes - salt management - #1954
- clocksource issue - #2044
- somehow sort out default VM screen resolution - #1856
- Anti-Keystroke Fingerprinting - #1850
- set random clock offset for Qubes-Whonix VMs using mgmt to prevent clock correlation attacks - https://phabricator.whonix.org/T440
- prevent dom0 telling Qubes-Whonix VMs the time by using the mgmt stack for that - https://phabricator.whonix.org/T397
- make sure Qubes-Whonix has no access to clocksource=xen - https://phabricator.whonix.org/T389
- forward randomness from /dev/random to VMs in Qubes - https://phabricator.whonix.org/T31
- enforce maximum system resources a virtual machine may use - https://phabricator.whonix.org/T12
- https://phabricator.whonix.org/T541
- (see also https://www.whonix.org/wiki/Advanced_Deanonymization_Attacks)
Block clflush and tsc instructions. Remove all timers. Avoid multi-threading VMs. Alternatively use non-interleaved NUMA with pinned vCPUs.
- https://phabricator.whonix.org/T539
- (see also https://www.whonix.org/wiki/Advanced_Deanonymization_Attacks)
Pin vCPUs to separate pCPUs. Block tsc instructions. Remove all timers.
That's a pretty broad question. Generally, not just dom0:
dom0 specific:
|
marmarek commentedMay 26, 2017
•
edited
Edited 1 time
-
marmarek
edited May 26, 2017 (most recent)
Document mechanism used by VMs (especially templates) to announce what "features" it support. This apply to things like:
This is about #1637