didnt think you were still on this thread.

when im stuck on hardware or a workload that qubes doesnt work for, i 
usually do vagrant with virtualbox or kvm depending. its not as good, of 
course, so still be careful. use packer to make your vagrant boxes. 

github has a lot of great starting points to work from. when making your 
vagrant boxes, make sure you set the mic off in virtualbox, and, of course, 
disable clipboard sharing. you can temp make it single direction when 
copying passwords. you can script it with vagrant ssh and X11 commands 
(xsel / xclip). just make sure your using X11 and not wayland. eventually 
you'll have to adapt to wayland. they're may be a way to script it with 
vboxmanage. or virsh if your using kvm.

also remember to disable sym links with vboxsf, 
VAGRANT_DISABLE_VBOXSYMLINKCREATE=1 in shells start up files should work. 

firejail will be great with wayland. right now, working around x11 is a 
pain. i used xnest (xephyr) and that seemed ok. xpra was took flakey but 
maybe its better now. was years ago.

if you just want it for tor browser, heres their notes on using 
apparmor https://www.whonix.org/wiki/AppArmor#Maintain_Tor_Browser_Functionality

if you go with vagrant-libvirt, you can run vagrant/virtualbox in it with 
nested virtualization in case anyone sends you a virtualbox vagrant file. 
outside of nesting, the two tend to not play well together. should also 
work with vmware which is pretty solid in nesting.

On Tuesday, August 27, 2019 at 11:39:06 AM UTC-7, O K wrote:
>
> You mean I create a VM with Whonix OS installed (using virtualbox I'm 
> guessing)?  I will have to research that, but yes I do need to use a VM, or 
> multiple VM's.  I'd also like to find a way to use Firejail to sandbox 
> whatever browser I'm using, if that's possible.
>
> On Friday, August 23, 2019 at 6:03:55 PM UTC-4, Jackie wrote:
>>
>> O K: 
>> > Thanks for all the help but I've been trying to figure out how to get 
>> Qubes 
>> > running for months and I've decided it's just a giant waste of my time 
>> > because every time I get one bug fixed, two more show up to take it's 
>> > place.  I think it's a brilliant idea but it needs a lot of work and 
>> > streamlining before it's ready for public use.  It's a shame because my 
>> > privacy and anonymity online are a matter of my personal safety and it 
>> > would be nice to have a secure OS.  TAILS is not a fully usable system 
>> > either.  I will have to install Ubuntu.  Good luck, everyone. 
>>
>> Hi, 
>>
>> Qubes definitely has a learning curve, but i think it's worth it (and 
>> i'm definitely no linux expert). 
>>
>> But if you don't want to use qubes, one thing you can do for better 
>> security and privacy is install debian/ubuntu and use non-qubes whonix 
>> (you can use virtualbox, which is pretty easy to use). You can have 
>> multiple whonix workstations, and you can create other VMs like debian 
>> as well to compartmentalize your workflows. A solution like this is more 
>> insecure than qubes, but definitely less insecure than just using bare 
>> metal debian/ubuntu for everything. You still get the benefits of 
>> virtualization and compartmentalization, but without the extra security 
>> features of qubes (i'd recommend not using the host os for anything 
>> directly, and doing everything in VMs). 
>>
>

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/be537c0e-b591-4853-84f4-8fb28abdb38b%40googlegroups.com.

Reply via email to