Qubes Isolation Best Practices?

Correlation attacks are probabilistic. Theoretically, the more proxys you sting together, the better your chances, but it’s not as simple as that and one configuration alone is not enough.

It has been shown that there can be correlation attacks behind tor and vpn together. Padding helps a little, like downloading stuff in the background etc.

This is more than enough for passive surveillance, but if you are targeted, with enough time and resources I believe they’d have a statistically significant probability to identify you.
You can keep rotating servers, make sure you can’t be fingerprinted, mix with traffic from other proxys (like browse the internet through the vpn while using tor, so it’s hard to correlate) and so on to mitigate.

To clarify, someone that is correlating your traffic from Tor, still have no idea what data go through the VPN, or even the clear net (which can look into once they identify you) because it’s encrypted.

Never trust any VPN provider, even the ones that “got raided”.

If you want to go a step further, get a VPS with crypto and setup amnesiac vpn.

EDIT. Read the discussion I have with abdullah here,

1 Like