Qubes-remote-support - New features and support for Whonix 16

Awesome news that this Nlnet’s funded Accessible Security (Insurgo) Qubes/Whonix merged effort project is getting attention!!!

From earlier testing, some important limitation where noted per Dev/Qubes Remote Support - Whonix

The most important thing missing right now would be a shared and contained terminal to mitigate graphical UX latency over Tor. Some thoughts were exchanged, but the project scope was already defined to change direction.

Considering remote support implies a high level of trust from the user to remote administrator, something like https://www.howtoforge.com/sharing-terminal-sessions-with-tmux-and-screen#sharing-terminal-sessions-between-two-different-accounts would be more then welcome, with the initial project already dealing with the secret generation, establishment of hidden tor service etc. The challenge here being to actually properly limit that shared terminal session prior of having the user land in that shared terminal, and wait for the remote admin to land in that same shared session.

@adrelanos @marmarek : I lost/forgot the conclusions that were said on such shared terminal session sharing, but last time I tested the implementation above, screen delays, and waiting time for the background magic to establish the initial connection were kinda dissuasive.

@alzer89 : Comments on the current implementation?

EDIT: also cross-referencing from Automation of remote administration - #4 by Suspicious_Actions

1 Like