I share @ellie_zh view. Compare things that are comparable, like a part of the society constantly asked to justify their specific needs, blamed for expressing them and treated as a worthless minority.
Your experience is not the only one, other people can live and do things differently without being wrong. Let me be a clown too: “I have nothing to hide. Why would anyone want to be anonymous? What prevents them from being fingerprinted?”. Maybe that will help you understand the problem here?
The point of the project doesn’t seem to have changed, because the main page still says that Qubes OS is A reasonably secure operating system. In other words, I can use products like Google Chrome, Opera GX, Discord, Telegram, or any other ones referred to as “spyware”, “fake encryption”, etc. in multiple compartments, and these can only access the information that is present in that compartment, e.g. my login credentials, and perhaps my behavioral patterns like mouse movements - even if the latter is shared across compartments and the providers can 100% confirm that it’s me, in the case of a compromise like malware attack, the credentials are stored in only one compartment. Similarly, these “spyware” products can’t learn my private keys and passwords, which were never passed from a vault qube to the one, where they run.
I’m sure that Invisible Things Lab, ENCRYPTED SUPPORT LLC and Power Up Privacy would be happy to work together on the Qubes-Whonix enhancements like you say. Perhaps you know, how much time and money it would cost for full-time developer work to have this implemented, and are willing to create a written offer for this, and fund the development?
It’s generally the developers job to explain how much work it would take because they are the experts who are familiar with the code.
And FOSS isn’t only about money. I know there are many open source devs who only do what big tech tells/pays them to do. But there are still devs that work on FOSS because they want to make the world better by giving us the digital freedom we need to protect our human rights.
So the question here is which case is it for qubes os devs? Money or freedom? Which has the higher priority?
Your reasoning here is flawed. That’s why I asked you to explain it because I was hoping you would notice the flaw yourself.
Your saying you’re upset/triggered because you think I should know more about assisted technologies and disabilities.
And then you say “instead of learning” when you’re upset I asked a question so I can learn. Instead of answering the question to help me learn, you begin insulting. Who is the one with the attitude?
The reason I asked the question is because Unman was giving very imprecise information which is most likely misleading. This kind of science requires being precise. I’m sure you’ve used some browser fingerprinting apps before so you should know how important it is.
If you really care about privacy and the topic, it would be more appropriate if you send me any new insults in private messages instead. It would make it easier for everyone here to discuss the real topic in a more constructive way.
I’ll take my words back, no need to try and guess, when it’s possible to contact ENCRYPTED SUPPORT LLC and ask - as a good starting point, this will be 200 Euro per hour. Then hopefully the information on total developer hours and price will be clear.
The goal of the Qubes OS project is to provide a reasonably secure OS, and the Qubes-Whonix integration is for privacy, what is explained in the documentation.
Last time I checked, Canada and Germany were capitalist countries. I’ll let you conclude if satisfying basic needs for survival can be done merely by happy thoughts and a burning passion for your definition of freedom and human rights (i.e. anonymous web browsing and obfuscating mouse movements).
Imho the greatest obstacle is still closed sourced firmware. Coreboot is a start, but we stil need a uC without built-in flash-able memory. SSD’s without propriety firmware still don’t really exist. Some starts have been made see: http://www.openssd-project.org/ or GitHub - DFC-OpenSource/ox-ctrl: OX: Computational Storage SSD Controller · GitHub (this to me is the largest risk). Not to mention the various other chips such as wifi, gpu etc that still contain flashable, closed sourced proprietary firmware / identifiers. I think that something like Heads or Linuxboot that can run a small script on every boot to randomize as many HW Identifiers like MAC Address, Serial numbers etc… Would be a good idea, afaik this is doable but nobodies taken up that challenge yet. These things represent real identifiers and backdoors that dwarf mouse-movement or browser fingerprinting. And then there is user error, computing habits and social engineering that have always been the big ones, like getting people to run random scripts, use compromised nefarious VPN’s, and from my experience, many of the “Sass Security” companies, “Smart” Firewalls, Antivirus, anti-spyware, “Privacy” companies have been at the very least honeypots and often just outright spyware themselves. (look into every company or organisation, its roots, its funders, the philosophies of their coders etc…)
I can see why many security researchers throw in the towel and think the whole game is rigged when we are playing in a walled up sandpit run by a handful of companies with proven MIC roots, closed sourced H/W Firmware and when it comes down to it, what can we really do?
Another topic about anonymity, while lacking awareness that Qubes OS is primarily, almost exclusively, about security, @aronowski emphasized it twice to no avail…
I personally think that this topic is very important despite some of the controversy. There are other topics (like Why Anonymity No Longer Exists in 2026 - Open Discussion) that for new people like myself are very important, because I simply wasn’t even aware of this at all. I also don’t think it’s wise in 2026 to dismiss the importance of privacy that comes along with security. some time ago, I’d never have thought that I would need to protect my online activity from threats like big, regulated companies and even government, simply because they don’t care about normal people anymore and can flag you for whatever reason and with today’s technology it’s as easy as pressing a button. and it’s worldwide. crazy.
But while the subject itself is important(even though Qubes is a security first OS) let’s not shift to other topics so this one won’t get closed as well.
As I see it currently, Unman provided the answer that Qubes is protected by default against this attack and extended a big welcome to whoever wants to test it.
Excuse my poor knowledge and understanding, but if Kloak is installed as an application it will lose the security design behind Qubes, and if it’s installed as a package in dom0 it will also lose the security design behind Qubes. So the real question is how to make Qubes provide appropriate events so the hardening part could happen in the AppVM, correct?
But… instead of forcing an untrusted AppVM to harden itself the event manipulation must happen inside a trusted environment right before it enters the VM. if dom0 sent raw, unaltered events to the AppVM with the expectation that the AppVM would randomize them internally, a malicious website script or a compromised browser could simply peek at the data incoming from the Qubes GUI Agent before your internal hardening tool gets a chance to modify it
The same way it is hard, actually impossible not to think personally when thinking, it is important to constantly clarify to new users that privacy is not the same as anonymity.
That’s why the posts like this serve to Qubes OS (new) users as a reminder not to fall into false sense of security. Not to provoke.
So, when you properly use Qubes OS, there’s no better tool for privacy and security. But when you need anonymity, well, wish you luck.
Grand post @James369
But in the context of qubesos I still think mouse movement fingerprinting is the biggest problem currently.
It’s a problem that can actually be fixed. Qubes event buffering was a good idea and I respect the attempt the developers made. But it seems like they gave up and now that implementation is just blocking other solutions such as Mouser.
The firmware problems you mentioned are a serious problem too but it’s not a problem exclusive to qubes os, and it’s a much more difficult problem to solve.
You’re arguing too strictly about semantics.
Most people want a private browsing history. QubesOS can’t protect that because of mouse movement fingerprinting.
You speak as if you are an official developer, and saying qubes os is not about anonymity, if you want that, then go somewhere else.
But qubes os seems to be more open to solving anonymity problems than you suggest. They did after all try to fix it with qubes event buffering. It’s just unfortunate they gave up on it. Or did money run out? There’s no updates about it so I can only guess.
I think the reason why there is a lot of friction and arguing in the community is because qubes os does put in some effort to improving privacy and anonymity. But then there is always the recurring arguments from users like you that qubesos is about security only, if you want anonymity then go somewhere else.
I wouldn’t be surprised if some of the users who argue against anonymity and privacy are feds.
I think what would help solve a lot of the friction in the community is if qubes os made a more clear statement on how it prioritizes privacy and anonymity.
It’s very clear about security, but how they prioritize privacy and anonymity is vague.
oh Jesus (do I need to clarify I’m not religious? )
Good luck using false equivalence and tautology next time. I won’t respond to these things from you anymore.
The sad part is that you are dismissing your own strong arguments (the 2nd and 3rd paragraphs), and this isn’t the first time you’ve done that. It’s counterproductive and leads the mods to close the topic.
My take is that from the very beginning the ITL considered x86_64 security a solvable problem only if they attached the adjective, reasonable, to it. I don’t think privacy was ever considered unimportant, just beyond practical scope and always at risk due to Intel ME. So in my mind privacy gains are made by users who are enabled by Qubes and those gains are accelerated by offering the community forum. There can never be a legitimate promise of privacy, only vigilance and solidarity of purpose. So I don’t think privacy is a fair question to put to the devs, but their alignment with our goals for privacy is clear and I do think it’s fair to ask that they never undermine community led efforts to make further privacy gains with the OS. Of course, the rubber will meet the road if Zuck gets his way on the age verification crap…
Anonymity, otoh, is more of a moonshot. If you want it, you’ll have to convince a much larger community to care about it.
I am truly surprised that no one has yet come up with one elegant and simple solution: just use two different input devices!
Let’s say you use a touchpad for anonymous activity, and a mouse for non-anonymous activity. I doubt that the mouse and touchpad give an absolutely identical fingerprint.
You can even do without two devices and for different activities just use… different hands!
Everyone knows perfectly well that when you write with different hands, you get different handwriting. This principle should also apply when using input devices with different hands.
And anyway, I’m not entirely sure that the public here doesn’t overestimate the threat of mouse fingerprinting. Do I understand correctly how this mechanism works? The essence of the mouse fingerprinting method is that:
The adversary must have influence or control over a specific site (to obtain mouseprint data from it).
A victim who is trying to act anonymously must go to this site, use it, then someday go to the same or another site (which should also be somehow controlled by the adversary), but only this time not anonymously - also use it - and thus the adversary will see the complete similarity of the two fingerprints and de-anonymize the victim (because he left his fingerprint during anonymous and non-anonymous activity on the adversary’s sites)?
Then tell me:
How likely do you think it is that the victim will conduct anonymous and non-anonymous activity on the same site(s) without being an idiot?
How likely is it that a victim who realizes that he is engaged in activities for which he can be prosecuted will end up on several sites controlled by the adversary, and what kind of adversary is it that can control so many sites that the victim has such a high probability of visiting them?
And if the victim does not conduct non-anonymous activity, then what? Then, whether they can de-anonymize him will depend on how significant the data is that the adversary can collect in the profile, based on what he was able to dig up about the victim from its activity on the resources under his control. And this directly depends on how much this victim, realizing what he (victim) is doing, allowed himself to give about himself.
Well, how threatening is this threat really? Are you absolutely sure that you are not overthinking here?
First part about left vs right hand and mouse pad vs mouse device:
It gives a very limited amount of identities. And most people are going to learn about mouse movement fingerprinting too late so they have probably already been fingerprinted using both a mouse pad and mouse with their real identity.
Second part about your questions is really more about if you trust big tech, feds and their gag orders, government, wef etc.
Do you trust Google and mitm cloudflare?
I don’t think it’s so useful to go indepth into discussing if they should be trusted or not, and their history and their plans for the future.
But all it takes for mouse movement fingerprinting is using a snippet of JS to send their mouse movement to the backend, where it gets fingerprinted.
I want to be careful and not mention any software which does this because it’s easy to get something wrong. But if you do a search there are proprietary mouse movement fingerprinting softwares that are production ready.
I also thought more about unman wanting someone to test if vnc can defeat mouse movement fingerprinting, and I already explained why it shouldn’t be able to. But if he still insists that it should be tested, so in other words, he is asking someone to build an open source mouse movement fingeprinting tool.
The problem with that is it sets a benchmark for him that if he can just defeat that fingerprinting script, then all other more advanced proprietary fingerprinting tools are also defeated. But that wouldn’t be true. All mouse movement fingerprinting tools aren’t equal.
Interesting - you are concerned about a threat but you have not taken
any steps to see if that threat is valid in ordinary Qubes use.
You could, of course, actually read the Whonix wiki on the subject, and
follow up on the material suggested for Kloak.
There are large corpora of mouse and keyboard data available. I have
used those with custom ML to see what effect using VNC and separate
qubes has on data acquisition. You could do the same.
You are wrong, but it would be worth while testing this further…
I can only report on estimates made from surveys. If you read in to the
field yourself you would see that there are very few surveys of (eg) VI
computer users, and informed estimates are all we have. An interesting
statistic is that take up of assistive technology like screen readers, is
relatively high among non impaired users.
I see that other users have commented on this. I am somewhat more resigned
at such comments than they are. I would say that it’s an area where you
might like to inform yourself further.
There are many impairments that make mouse or trackpad use difficult:
beside VI, many motor difficulties make accurate mouse use difficult,
but a simple keyboard overlay can help. Users who rely on pointers or
wands, users with RSI - I’m sure you can think of more yourself.
Many of these people will use a normal keyboard and a “normal” browser.
Some will use a screen reader. Relatively few will use text based
browsers.
If you read only one article on computer use by VI I recommend this outline by Karl Dahlke
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.