Can ISP still detect Linux (or Qubes) if sys-whonix handles everything except the physical NIC?

Thank you @Rootman for this detailed explanation and the time you took to write it. I really appreciate you sharing your experience and security philosophy in such depth.

Your approach of “avoiding unnecessary technical layers” is a respectable strategy, and it’s an important reminder that simplicity is often more secure than complexity. Your warning about WiFi as a large attack surface is also a valuable point to consider.

However, I want to clarify that applying this approach fully is not always possible, due to purely practical reasons:

  • In many rural areas, Ethernet (landline cable) is simply not available at all. The only internet access is either through public WiFi or mobile networks (4G/5G).
  • The cost of mobile data (4G) in some countries is very high, and the speed is not always stable, making it an expensive and impractical primary solution.

So in my case, WiFi is not a luxury choice—it is often the only practical option available.

One solution I am currently considering is using a router in WISP mode:
The router connects to the external WiFi network (public or cellular), and then forwards the connection to my laptop via an Ethernet cable. This way:

  • The ISP sees the router (not my laptop).
  • My Qubes system communicates through a wired (Ethernet) connection instead of direct WiFi.

My question to you: In light of your warning about WiFi, do you think this solution (WISP) sufficiently mitigates the risks, or is it simply moving the same vulnerability (wireless connection) to another device? What additional advice would you offer to secure this setup?

I appreciate your caution, and I hope you understand that some of us are forced to deal with these practical constraints. I am looking for a solution that balances security with feasibility.

If this is iran or similar I would not go that route. They are neither poor nor stupid.

I think the goal here is to invest in anonymity, not to much in security (doesn’t hurt of course).

If he is detected, then all the security in the world doesn’t help against “hit him with this 5 dollar wrench until he gives us the password” :confused:

The more I read this thread the more I think we are suggesting highly dangerous things. I assume most of us (or at least myself) work / play with Qubes completely free of any danger. I suppose me being interested in Qubes doesn’t make me less of interest to the gov, but its somewhat normal as well (it is my job too after all).

I feel like the best recommendation here would still be use windows + vmware + kali, not Qubes, as much as it hurts me to say this (I mean I love Qubes ofc, and want him to enjoy it too, but not at cost to his freedom / health / safety ofc).

avoiding unnecessary technical layers

If Qubes stays on the box I think this is sth I’d recommend at last. The more complicated things get, the more can be overlooked. Android + tether + VPN is the simple route to go…

I could write a massive textwall on what else to do, but the whole thread gives me a massive bellyache…

WiFi as a large attack surface…

Dude there are SO many things. It is not realistic that we can help you catch all of them, and even if, you are leaking most likely during the setup where you make mistakes / don’t have solutions installed yet and alike.

moving the same vulnerability (wireless connection)

Mate, iran(?) has MANY MILLIONS OF USD to spend on 0day exploits. We can not help you against those.
I’ve been using Qubes for a LONG time, but I would NOT trust my life on the security of Qubes, as well as my own skills. Loosing money yes, life/health/safety → no.

What additional advice would you offer to secure this setup?

Not using wifi, it just screams around.
And not doing it at all. From the way you are writing, this all is not a good idea I think.

Maybe you are one of the greatest hackers ever in the making… Everybody started small at some point.
Or maybe you will sit in a shitty cell tomorrow, or get kicked out of university, or sth like this.
Is it worth it?
I don’t really want to talk you out of it… But this isn’t the 90s where we still had a fair chance. Its to easy for the gov to spy on people these days. And in dictatorships, spyware is usually installed by default when your phone first connects to the cellular network via some funky 0day. If that is the case in your place, and you trust android + tether, then its already game over TM before it started.

2 Likes

From the universities to the rural parts of the country, we are spoon fed with the news. Sorry. This all screams huge red flags for me.

Having a state actors for adversaries is not for kidding with.

You have to go back to your threat model and not get online until you are not definite with it. After that, lurking for a long time, without logging in especially, if it’s not too late already.

3 Likes

thank you

Hi @corporateblush Thanks for the clear explanation, it really helps put things in perspective. I think my next step is to dive deeper into networking, specifically around Ethernet, so I can figure out which setup best aligns with my threat model and security needs. There’s definitely more we all need to learn before making an informed decision.

2 Likes

Hi @abdullah You’re welcome.
It all clicks now regarding Ethernet. Setting up a separate router in WISP mode is definitely a solid security move, but honestly, it really comes down to your specific threat model. Depending on what you’re protecting against, you might just route everything through a VPN, tweak some advanced configs, or even chain in another router or gateway.

In my view, these steps do help mitigate risks, but if you’re trying to stay off the radar of a determined adversary, you have to critically question every single detail. For example: was your router bought anonymously, or did you use your personal credit card? How many people know you’re running a second router? And crucially, what does your traffic actually look like to your ISP?

You really have to think about the metadata too. Even if the content is encrypted, the pattern of your usage can give you away. Is your home network suddenly acting weird? Are you generating unusual amounts of traffic at odd hours? An adversary doesn’t always need to break your encryption; sometimes they just need to notice that something is different about your digital footprint. So yeah, it’s less about having the “best” gear and more about making sure your whole setup - hardware, payment methods, and behavior - doesn’t raise any red flags. It’s a lot to juggle, but once you start thinking like the person trying to track you, the gaps become pretty obvious.

1 Like

thank you

So yeah, once you have been targeted by an attacker, technology will not save you. You might only make their efforts more ‘expensive’ in practice.

5 Likes

… as long as you have got no family, friends or “real life”.

1 Like