Qubes Isolation Best Practices?

Just wondering how people organize their qubes, or what you consider would be the best isolation practice?

Tor / vpn/i2p → f/w → Sys-net → NIC1 → WWW

Personal (banking, work, loacalIP etc) → fw → sys-net → NIC1 → WWW

or

Tor/i2p/vpn → f/w → sys-net → NIC1 → WWW

Personal (banking, work, loacalIP etc) →fw2 → sys-net2 → NIC2 (USB) → WWW

or

Tor/i2p → VPN1 →fw → sys-net →NIC1 -www

personal(banking, work, localIP etc..) → VPN2 →fw → sys-net →NIC1 → WWW

or even

Qubes Laptop (only vpn/tor/i2p) → WWW

laptop2 for Work/ personal / localIP → WWW

Just curious how to best separate things as I sometimes wonder if ISP or 3rd party can correlate

Tor / vpn/i2p → f/w → Sys-net → NIC1 → WWW

Personal (banking, work, localIP etc) → fw → sys-net → NIC1 → WWW

or other setups?

1 Like

I’m not a fan of using i2p exit nodes. It’s very slow and defeats the purpose of the network. You might as well use Tor.

Also, you seem to be passing everything through tor which puts a lot of unnecessary load on the network. Downloading torrents, or watching (HD) video on youtube you can do behind just a VPN.

Personal opinion, I like to have one well configured firewall, rather than separating the networks. I know the tradeoffs, it’s just a personal preference.

I have a chain of proxys and different qubes use different “links” of the “chain:.

sys-net →sys-firewall →sys-vpn*→Whinox(gw)→VPS

*sys-vpn also runs a fludfill i2pd. i2p runs behind the VPN. Set to autostart so I contribute to the network when my PC is on.

Appvm qubes connected to,

sys-firewallI, I do my banking, taxes, local google searches, etc.

sys-vpn, I watch stupid YT videos, torrents (i2p), high-bandwidth apps (GPU-passthrough).
Assume, this is always monitored.

Whinox(gw), I do all my private searches, access onion sites. Low-bandwidth.
This will give you very “reasonable” anonymity, unless you are targeted by a nation state.
I also watch non-HD YT videos here that I wouldn’t want the algorithm to know.

The reason everything is going through sys-vpn is because that is all I want my ISP to be able to see. Everyone has a VPN these days. I blend in better.
Tor doen’t have as many users to bend in, and I’m sorry but I don’t trust Tor entry nodes either, I feel very exposed. If everyone used Tor it would be great, but not that many people do.

I have a personality profile for each of my qubes connected to the chain,
sys-firewallI, public me, what I want people to know about me
sys-vpn, average-joe me, what I want “adversaries“ to know, when they think I’m not looking.
Whinox, ghost me, when I want to “watch feet” on the darkweb.

3 Likes

Thanks for your feedback, sorry if it was not, clear, I do not pass everything through tor.

The tor/ i2p / vpn are all just the anon-qubes. so its either, tor, i2p or vpn. at the moment I am running tor through a vpn, as I also dont want the isp seeing the tor connection.

Can you please expand by what you mean by a well configured firewall?
How does that contribute to better isolation?

I agree with you, I don’t torrent or do high bandwidth stuff through tor, I do that through a vpn.

My main question really is, if clear-net traffic from my local ip could be correlated to the vpn or tor traffic? If an ISP or 3rd party saw connections to my banking, personal emails and logins or work and correlated them to tor or vpn traffic? At the bare minimum they would see the vpn or tor alongside the personal stuff if all was going through the same NIC/ ip.

1 Like

They certainly can:

3 Likes

thought so, how do you get around that if you need clearnet for banks and stuff? Separate NIC? Separate machine even?

1 Like

sys-net ← sys-firewall ← sys-whonix ← sys-vpn ← browser-vm

(If I got your question correctly)

1 Like

No, my work, banks, email etc, the real ‘me’ can’t do that chain.

I also don’t put anything from the real ‘me’ in tor, i2p or even most vpns, it would pollute that whole chain and defeat the purpose.

There are also different ‘shades’ of anon in my model. some like signal, telegram, some emails and personalities I would put into a pseudo-anon category.

1 Like

I do not use banks.

2 Likes

lucky you! I envy that, hopefully one day I can do that too, (And also ditch phones completely while I’m at it.) Unfortunately I am still in the matrix, but working my way out of it.

1 Like

Viable alternatives?

Get payed in crypto and use cash I suppose.. Could be an option I guess.. Transaction / cash out costs are a bit annoying. But I never looked to much into it.

First problem would be how do I pay myself in crypto lol (I run a german GmbH (normal company form in Germany). I actually can pay myself in crypto, thats legal, just not sure how (my bank doesn’t support that, but they do say they are very social lol).

3 Likes

social! lol, as in friendly or socialist?

1 Like

As in hugging trees and stuff.

1 Like

Cash-chequing services, BTMs, and P2P exchanges (RetoSwap). The best Qubes OS isolation practices in my workflow treats the real world as a compartmentalization layer, so they are directly correlated yet occupy separate mediums without expanding the attack surface of one side or the other, instead distributing them to reduce overall complexity.

4 Likes

Are you sure anyone can correlate my accessing to this forum via tor in a minimal dispVM where I do not access any other site, with another clearnet minimal dispVM where I am accessing my bank and not any other site?

1 Like

I’m not sure I understand the question.

1 Like

Then probably I didn’t understand the question @FranklyFlawless answered to.

It was:

I guess no one sane would use Qubes and would do such things from the same browser instance / dispVM, hence my question

1 Like

Have a read at this,

TLDR, think of each sys-firwall as its own network. Connecting qubes together has security risks that can be mitigated by keeping those qubes isolated in their own “network”.

1 Like

Ah yes I see, I use multple firewalls, almost all them mirage-fw.

The question is how best to organize / isolate qubes in order not pollute streams (one identity leaking into another) and mitigate correlation attacks. For example, tor and clearnet (with identifiable information) from the same IP/ stream. Other examples could be a vpn where you are logged into your identifiable work, bank or email shared with a tor or stream you want to keep anon. So the questions are how do you best isolate qubes to stop these Identity cross contamination.

1 Like

Correlation attacks are probabilistic. Theoretically, the more proxys you sting together, the better your chances, but it’s not as simple as that and one configuration alone is not enough.

It has been shown that there can be correlation attacks behind tor and vpn together. Padding helps a little, like downloading stuff in the background etc.

This is more than enough for passive surveillance, but if you are targeted, with enough time and resources I believe they’d have a statistically significant probability to identify you.
You can keep rotating servers, make sure you can’t be fingerprinted, mix with traffic from other proxys (like browse the internet through the vpn while using tor, so it’s hard to correlate) and so on to mitigate.

To clarify, someone that is correlating your traffic from Tor, still have no idea what data go through the VPN, or even the clear net (which can look into once they identify you) because it’s encrypted.

Never trust any VPN provider, even the ones that “got raided”.

If you want to go a step further, get a VPS with crypto and setup amnesiac vpn.

EDIT. Read the discussion I have with abdullah here,

1 Like

Thanks,

On that note, I posted this the other day

https://forum.qubes-os.org/t/identification-method-for-torr-over-vpn-anonymous-network-flow-and-service-type-thereof/42413/1

So you think chaining is better? Do you think that for example:

(eveything chained)

Sys-net ← f/w ← VPN1 ←  Identity 1 (Identifiable qubes ie personal email, banking,etc)

        <- f/w   <- VPN1     <- Whonix  <-  VPN2 or Proxy -<-Identity 2

Would be better than :

Seperated:

Sys-net ← fw1 <-VPN1 <-Identity 1

Sys-net   ← fw2 ← sys-whonix /tor ← tor browser

Sys-net   ← fw3 ← VPN2 - Identity 2

(Sorry I am no good at doing this diagrams)

1 Like