On 2/19/19 6:45 PM, 'awokd' via qubes-users wrote:
> ashleybrown...@tutanota.com wrote on 2/19/19 4:05 PM:
>>
>>
>>> Creating a tor
>>> netvm is rather straight forward (and a dispvm that includes the Tor
>>> Browser if you like to use that as well). If there is enough interest, I
>>> can also write up a summary on how to do that in Qubes.
> 
>>
>> Please, it would be greatly appreciated. Especially on how to ensure
>> no clear traffic happens and that it only goes over tor.
> 
> What you're describing is one of the primary goals of Whonix. 

Right. I have no trust in their capability to design and write secure
software nonetheless.


> They have
> also done a lot of work around anonymizing applications and time sync,
> which I doubt the procedure above will cover. Unless you know and are
> prepared to address the possible anonymity compromising details of the
> individual applications and distribution you are planning on using (see
> https://phabricator.whonix.org/maniphest/query/all/ for ones they've
> considered), it's likely safer to stick with Whonix. See also
> http://www.dds6qkxpwdeubwucdiaord2xgbbeyds25rbsgr73tbfpqpt4a6vjwsyd.onion/wiki/Trust
> for a longer discussion on Whonix and trust.

Clock synchronization over Tor is not rocket science and pretty much
straight forward. Furthermore, if you need to ensure that separate Tor
paths are used for particular applications, you can either simply use
separate Tor netvms or depend on handcrafted, error prone circuit
isolation in Whonix. I'd prefer the former, simpler option but YMMV.

Regards

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/5e965953-a746-642d-3834-3579243ed7e9%40posteo.de.
For more options, visit https://groups.google.com/d/optout.

Reply via email to