Hello. I’m not sure if this is the right place to post this. I’ve been looking for an alternative to QubesOS for a secondary device. And I’ve decided to go with Kicksecure.
However, I’ve encountered some online comments that seem to discredit both Kicksecure and Whonix. Especially the GrapheneOS community seems to distrust these two projects. I’ll link just the main post that I found:
Additionally, there is something I find wierd with the Kicksecure download page. When downloading the ISO, the website seems to almost discourage signature verification by saying it’s, quote, optional and only useful for very experienced users. Which seems to me at least like a strange decision for a security-focused distribution.
Although these claims are “unofficial” they have sparked some doubt in me about the credibility of these distros. So I am asking here: are Kicksecure and Whonix (since they seem to be developed by the same group of people) currently to be trusted (i.e. are not currently working against the goals of digital security, privacy and anonimity) and considered more secure and anonymous than the average Linux distros and thus make a valid alternative to Qubes if one is looking for a secure but more lightweight system?
First, don’t take anything I say blindly: I’ll try to summarize it in a balanced way, but trust is an inherently fickle thing. They may seem well-intentioned but not be, for instance. That being said, I don’t think they’re outright malicious. I try to stay away from the people and more towards the actual products though, because at the end of the day pointing your efforts to a person, other to than to take a general perspective of all they’ve done, is misguided. Your real concern is about the code. That said, Kicksecure/Whonix do accomplish some, but I would say that they have not done well on the security front.
Basically, Linux has a lot of options for security, but a lot of them restrict the ability to use a lot of programs currently available because it would, say, remove an insecure functionality that the program relies on. Kicksecure seems to be calling itself a secure distro, but then when faced between security and X, they choose X (with X being binary compatibility, Libre values, etc.). Nothing wrong with prioritizing some of those because, for instance, security may be pointless of you don’t have the transparency to actually verify that it’s secure.
Overall, I would say that you shouldn’t consider either distro secure, but I don’t think the devs are actually malicious either.
That is the definition of an echo chamber forum!
The dev very unprofessionally start talking shit about other projects in his own forum and a bunch of sheep are cheering for approval.
I’m not surprised. Daniel Micay is toxic. He gets into public altercations with youtubers and stuff. Drama queen.
That is a shame, because I use GrapheneOS myself and it’s great.
Personal opinions aside, the main point I keep reading in the forum is that Kicksecure dropped hardened_malloc for compatibility, which is fair. The community was split on that and I think it was a mistake too.
The rest is just people sucking each others dicks. Rehashing the hardened_malloc 10 times, saying there is no kernel hardening (which is simply wrong), criticizing the default browser (lol), claiming that debian, the OS that pretty much all servers run on, is not secure, no sandboxing, etc.
Kicksecure is an OS. Once installed you can get whatever browser you want and do whatever sandboxing you want. Do we really need a noob friendly version that’s setup out of the box?
The claim that ‘ Kicksecure is not secure at all ‘ (immutable, with root/user kernel separation, apparmor, etc.) is just false.
The fact is that Kicksecure with Whonix is the best of anonymity, and that is what I use it for. I use a different distro for my hardened qube.
I’m not sure about SecureBlue, I haven’t used it. Maybe we can get a community template some day.
Yes, I agree completely that he acted a jerk. I’m not defending how he went about things*. But the point remains that he’s a brilliant programmer evidenced by GrapheneOS, the only competent security-focused mobile OS I know of**. How he went about it has literally nothing to do with the fact his statements are true, and your statements aren’t actually based on the facts of Kicksecure’s security. Your statement about Debian ignores the fact that server security and desktop security are different ballgames. Your statement about Kicksecure having no kernel hardening being false is correct at face value, but is ignoring a common rhetorical device where they are saying that Kicksecure’s kernel hardening does basically nothing. As for hardened_malloc being rehashed, it is rehashed in response to this question being asked so many times. My point is that Kicksecure’s security stature just makes no sense, and I think it should be evaluated fairly based on that fact. If you want to convince me otherwise, and it’s worth your time, then get a good-faith list of the accusations against Kicksecure’s security and point to obvious facts or git commits where any are false or made in bad faith.
As for Whonix, I use it personally. I don’t have a vendetta against it or the devs. I think Whonix has made contributions to anonymity, and that the approach of using OS-level anonymity protections/mitigations should be copied and looked into more closely as there’s only so much the browser can do. I, however, depend on the security of Qubes and not Whonix in these usecases.
*I will, however, point out that his past business dealings and some alleged (‘alleged’ because I didn’t personally follow up to see if it was true) mental health issues should go a long way in making it understandable. Not excusable, but I couldn’t say I wouldn’t have acted the same way in those circumstances if I went through those things. Again, not saying it’s right or that I support his actions but it frustrates me that the first thing to be brought out against the facts is Micay’s social standing.
**There’s nothing wrong with using other smartphone OSes because you don’t want to support Google, or you want to support Linux on phones, or whatever reason you want. My point is that GrapheneOS is the only one with reasonable security/maturity.
I don’t think we are too far apart here, but I disagree that kernel hardening does nothing for security. Longer conco, if you want to have it.
Kicksecure is not the most secure OS out there, but it is what it says, a very harden linux distro. Might not be harden enough for some, but that is far from the claim that it’s not a secure distribution at all.
Like I said, I’ve chosen to harden a different disto myself.
Can you provide any examples of this?, Do you mean prioritizing open source is a bad thing?
In which way? Can you provide any examples?
In reply to OP, this spat between Whonix/ Kicksecure and Graphene is also addressed on the Whonix forum in depth, so look at the argument from both sides and you may get a better picture. IMO, I found how Patrick responded and addressed the criticism to be amicable fair and unbiased.
That said, Whonix, Kicksecure, like the other Qubes packaged Templates are a good turn-key solution. Though I think nothing can replace an in depth knowledge of how things work.
I think there is too much stuff in whonix, to big of attack surface. Personally I only used it for tor-browser and copying files to offline VM’s, where I work on them. So that could be cut right down.
I don’t like how they messed around with sudo / sysmaint, which is very frustrating.
I think the integration between qubes and whonix is hitting a lot of barriers and there is obviously some issues there (see the thread on whonix forums of unresolved issues).
Whonix was not built with qubes in mind (mostly Virtual Box -which in itself raises a lot of issues).
If you look you will find that many of the so called kicksecure mitigations, do not really apply to qubes. I.e cpu, kloak, etc..
As someone who regularly uses Qubes Whonix and GrapheneOS on my Google Pixel, I’d say this: Whonix (like kicksecure, on which it’s based) is far from a perfect OS in terms of security. The Linux kernel also contains tons of bugs, and new CVEs are discovered literally every day. But we have nothing better.
The GrapheneOS main developer is extremely categorical and loves to delete nasty comments on the forum and GitHub that point out his deep technical errors. I don’t deny that GrapheneOS is essentially the best we have, but at least the Whonix forum doesn’t resort to similarly demanding help for every technically impossible-to-fix issue (it seems they’ll only be satisfied when Whonix makes its own kernel instead of Linux, preferably in Rust and with a security chip).
Qubes Whonix on a PC/laptop and GrapheneOS on mobile devices. It would be great, of course, to be able to run Qubes as a vm in GrapheneOS, but that’s a distant dream.
Disclaimer: I have never used GrapheneOS or Kicksecure. Only Whonix in Qubes.
The question in the title expects a Yes/No answer. It also asks about 2 separate OS and refers to a discussion with a lot of exaggerated claims. Distro wars style…
I would approach it this way:
Define your goal clearly - what do you want to use the software for, incl. threat model. Nobody can tell you better what you need.
Proceed from that:
What does trusted mean? Trusted by whom? For what purpose?
What verifiable facts exist supporting anyone’s claims? Has the developer openly provided evidence to facts that one can check for oneself? Are these balanced or biased?
How healthy is the reasoning behind any project decisions?
It is very easy to say “X is not secure” without explaining in what exact situation certain specifics make it insecure. There is one basic (verifiable) truth: GNU/Linux is as secure as you make it. Proprietary OS are as secure as the proprietor decides.
Much of the information is long outdated. Also, this post was thoroughly examined by the Kicksecure/Whonix developers 2 years ago. But even back then, this post looked like simply emotional ignorant hate
For me this is one of the biggest selling points for security! I’m not sure if SecureBlue has that.
I understand that it might not be convenient, but it’s a great security feature. In QubesOS it’s very easy to use too. Set the user kernel for appvm / sysmaint for the template, and you can forget it’s even there.
Ignoring the word “trusted” because the issue is far more complicated than that. Qubist’s post explained it well
I’ve used qubes and graphene for 5+ years. For a short while I “trusted” graphene more than qubes largely due to my newness, ignorance and graphene’s opinion on Linux inherent flaws and their assuredness of their own superiority. Then I noticed more and more Daniel’s behavior. Regardless of whatever excuses you come up for him and accomodations you make due to his self professed victim status, I’ve been around long enough to know his type and know how much I “trust” that type. Also same thing for people, in any industry, who make shitting on their competitors a substantial part of their shtick.
I still use both, graphene I use for quick and easy internet for low threat things. Qubes for everything else, for learning, for testing, for this forum and its good education and posters, for the excellent although sometimes outdated or confusing documentation, for my most important and privacy/security conscious use cases.
I “trust” whonix devs as much as qubes. In fact, due to recent difficulties and changes with root vs sysmaint vs user, I “trust” whonix for the most privacy/security tasks on qubes. Whonix devs are obviously focused on hardening and securing as much as is possible.
I agree it is frustrating but I appreciate the attempt to lock down whonix and don’t mind the extra hassle, I can use other templates for less frustrating.
Do you think the tradeoffs are bad ? Or that it is a negligible improvement ? Or just too frustrating to use regardless of any benefit ?
For me anyway, many things in Whonix are unnecessary. I started to strip it down, and worked to make a whonix-minimal a while ago, I spent a bit of time going deep into whether or not things were needed.
I personally found, although it was a lot more effort, that it was easier to just start from scratch. Make a minimal TorVm and a browser qube, (security by minimalism approach.)
But that is up to everyone, I am not giving advice here. I mostly qvm-console into my qubes or qvm-run –pass-io…. and remove the terminals. So for me and my workflow the sysmaint / sudo thing was just a pain in ass.
When I went through the whonix / kicksecure packages I found that most didn’t really apply to qubes.
(I even found that sdw-date was not really that useful.) It is very difficult to debloat / customize because so many of packages are locked down and dependent on one another, and then updating after customization is a nightmare!
I like to tinker, and although devs hate that (esp Graphene!) if I understand whats going on it gives a better understanding of its security. Whonix could give people a false sense of security, but as I said earlier, I think its a great turn-key os for its purpose.
Interesting. How much work/time is involved in getting a minimal template working just for Tor browser ? Do you do minimal for gateway also or just workstation ?
Both. I realized I only used Whonix for a disposible Tor Browser (also Curl or wget, which wasn’t in Whonix ) and a Tor G/w ( without all the tor-guis, sdwdate etc…) Everything else was bloat. All the other stuff I do I move into a Vault or work-disp. So if its just a disp tor browser and a gw. Then… Thats why I gave up minimalising it, you can see some back and forths about it on the whonix forum. In the end I think Patrick said it would be to much work and unsupported.
Oh so to answer your question Too much work / time! Quicker to start from scratch on a deb13 minimal
Yes, also about the limitations of debian, systemd and the kernel. Lots of the so called ‘fixes’ are pretty hacky and there is a lot of security fluff out there. I became much more interested in things like Alpine, Devuan, BSD, TinyCore etc.. So much to learn, makes me feel more stupid every day
Oh so to answer your question Too much work / time! Quicker to start from scratch on a deb13 minimal
I kinda had a similar thought.. I’d love to give people a “kuhbs-net-tor” (as in a custom whonix-gateway) which isn’t THAT giant and eats ressources like mad. But I kinda never use tor and I’m a bit scared to mess that up.
Is it more than apt install tor + a funky config?
What I would love to provide is pretty much just a tor gateway and a tor browser VM based on debian-13-minimal - if you guys could share your approaches here (paste your bash setup scripts lol) that would be lovely
Alpine, Devuan, BSD, TinyCore
Yeah same here. I’m not super happy with debian-13-minimal… Its still so much stuff to run LOL.
Alpine would be lovely, OpenBSD properly integrated into Qubes is kinda what I dream of at night lol.
Right now I’m thinking about kicksecure..
What do you guys thing is the best template right now if you “just want to run thunderbird” or “just want to run signal-desktop” or something in a Qube? (security wise). Would you go with kicksecure? (PS: needs full qubes support, so OpenBSD template doesn’t cut it).