ppl who didn’t realize it until now: GOS’s “autistic” fuck(the founder) is doing his best to discredit others who crossed his retarded world view order of things.
and GOS is highly likely a honeypot. it’s already known for YEARS in certain circles.
kicksecure/whonix is trusted. I personally don’t like how the founder is dealing with lots of things, but his “goals of digital security, privacy and anonimity” r highly transparent n good, mostly. he also don’t afraid to admit his own mistakes, even tho he’s a bit stubborn at times.
Since you are familiar with whonix usage, do you have any thoughts on whether it is better (from privacy/security standpoint) to use fedora with sys-whonix as network when you want to use a program with sys-whonix or use whonix ws with sys-whonix. The program wouldn’t be Tor browser but something like trezor suite.
I used to use fedora with sys-whonix because I figured it was more updated and secure than debian (which whonix is based on) but then I switched to whonix ws because I thought I might be defeating some of the benefits by not using the default (like fingerprinting)
Your post has two main points: 1. general opinion of GrapheneOS community. 2. the wording used that digital verification is optional.
GrapheneOS is run by extremely ban and censorship happy moderators. They will ban and censor anyone who disagrees with them and makes them look bad. They delete posts. They create a narrative in their comunity by only making posts visible if they agree with the official narrative. GrapheneOS is not a place to get truthful information from. Take a look at topics which discuss simple things, and you can see that most of the community don’t know anything at all. They say if you have the choice between using a vpn or nothing to hide your IP, then it’s better to not hide your ip at all. Stay away from grapheneOS community if you want to learn. But you can still use their OS.
The wording they use in the docs is correct. It’s optional and PGP technology is known to be complicated to use, so recommending it for advanced users makes sense.
Whonix/kicksecure promotes the PGP/GPG technology more than any other project that exists. When you find a guide on whonix/kicksecure on how to install/configure an app, it always includes instructions for digital verification. And sometimes, it’s thanks to Whonix/kicksecure some projects have PGP signatures at all because they added the digital signatures after whonix/kicksecure officially asked for it, through for example a github issue.
Alpine, or any minimal distro, with mullvad-browser disp through that, or Tor-browser, with tor disabled (no tor over tor) . I think re fingerprinting its ok to use the standard mullvad browser over tor proxy as it was built like that (a tor browser without tor). For the general distro hardening, this is still relevant: Linux | Madaidan's Insecurities . After setting them up, I clone them, and then see what can be removed / hardened (depends on distro) without braking its functionality on the clone.
I think whonix with whonix g/w is best as they were built for each other.
Re Fedora, I don’t really know, it depends what your used to, I am better with debian, but at the moment I hardly use debian at all, most of my browsing / office qubes are Alpine or Devuan minimal.