The grandest obstacle to making anonymous web browsing possible in QubesOS

Both (A) and (B) explain clearly what they do. They are aimed to show you 2 extreme cases. According to your theory of fingerprinting, (A) is much more identifying because it is much more rare but the fact is (A) reveals far less overall information and sends zero biometrics.

You and Unman are being very vague and jumping all over the place from terminal text browsers to curl etc. It’s just noise and distracting from the real topic.

@unman provided 2 possible workarounds: VNC and using a text browser.
I also linked to quBO which gives you a Tor Browser with no JS or CSS.

How exactly does that make us “very vague and jumping all over the place”?

While I have no doubt mouse movements can be part of a fingerprint (but unlikely as the only factor, even less “the grandest obstacle”), I don’t think the way you are approaching the issue correctly. Hammering around that “Kloak is the solution” and demanding it must become project’s to priority is not going to work. You have to understand why Kloak is incompatible with Qubes for now.

But you have to be specific from now on if you want me to reply to you and not see your replies as noise and distractions.

If you feel any of my replies breach the community guidelines, please feel free to report them to @moderators.

2 Likes

I had to scroll up to see what “A” is. You are talking about using curl to browse the web?
Or are are you talking about another specific terminal browser?
That’s what I mean you are jumping all over the place and not being specific.
Because we were talking about terminal based text browsers, and then you suddenly talk about using curl as your browser.
And you still haven’t said what the fingerprint is for curl.
I know what the fingerprint is for some of the terminal browsers and they will give you a unique fingerprint because there’s not enough people using them.
If you really want to prove something you need to be specific and show us the fingerprint and statistics to show it’s non-unique.
I’m not going to go through every single web browser that exists and list pages of information. But I can do it for one or two browsers if you are specific about which one you want to learn about.

And don’t forget something important which was mentioned in the first few posts, that it’s important to be able to participate in the internet as well. To be part of communities, discussions, content sharing, normal stuff. Not only read. I don’t think that received much attention in this topic so I think it’s worth pointing that out again.

But you are correct that using such browsers solves the mouse movement fingerprinting problem, and I have acknowledged that. But it doesn’t solve the tracking problem because you switch a unique mouse movement fingeprint to a unique browser fingerprint.

And VNC would be a good suggestion by Unman but he’s saying it definitely solves the mouse movement tracking problem without giving proof of it. He only says “test it” and “I tried a custom ml”.

All I did was point that out, and ask for more precise info, better proof, explanations.
And some users made a lot of distracting noise making it challenging to focus on the scientific issue.

2 Likes

I was not going to reply to you further, but I can not let this ride.

Let’s be specific. You made a comprehensive and critical remark about
“the grandest obstacle to making anonymous web browsing possible
in Qubes.” You relied on unsubstantiated and false claims about the
requirements for Javascript, the use of browsers,and untested assumptions
about the relevance of mouse fingerprinting in Qubes.

So have you tested it or no? If not, you are relying on advertising puff
from companies with a vested interest in promoting the capabilities of
their products.
If you do not think there is a good way to test, then what makes you
think that Kloak provides any solution? If it does not, then the
absence in Qubes is irrelevant.

If you have ever had the misfortune to have to work on this sort of
network then for authentication the FRR is quite high when using Qubes

  • not quite unusable, but regular calls to support are required. (Which
    overrides the main point of this sort of schema.) You can readily find
    studies which show that FRR and FAR performance degrades at scale -
    the idea that you could scale up to internet users seems completely
    unfounded to me. (Or even just the relatively tiny subset of Tor
    users.) But perhaps you have evidence to support this? Specific evidence?

You are right, I did not explain: let me do so now.
I started from the observation that Qubes use seemed to interfere with
authentication. The available free datasets are relatively small, but I
had access to data gathered in house and was able to inject data gathered
from free movement in separate qubes. The classifier used (I think) micro
mouse movements together with keyboard data and user interactions,
and I focussed on the first. I used a Random Forest classifier trained on
debug data and groupings of data from different qubes - if qubes have no
effect here then you would expect to be identifiable between different
qubes, with low FRR. (I think that RF generally give a FRR of around 1%

  • I dont have a reference for that here, but could probably dig one
    up.) Results indicated that there was a measurable difference between
    data gathered from separate qubes, and a resulting high FRR, which
    confirmed our user experience. I no longer have access to that data set.

But you do not need me to tell you this. If you used Vinnie Monaco’s device
fingerprint tests (as suggested in the Whonix documentation), and run the
mouse classifier, you will likely get completely different profiles from
different qubes. Any one can try that: you could already have tested
using this tool.
Of course, this is not the same as a commercial offering which probably
gathers data from multiple features of mouse movement as well as mouse
usage, combined with other use and timing patterns, but it’s a simple
demonstration, and cited in Whonix (which appears to be your source)
as relevant.

I have not “admitted” that - strange choice of word. I suggested that you
educate yourself in this area, but you obviously have not done so. The
estimates are just that, as my initial use of language suggested. They
are based on a range of different surveys, and as reliable as currently
available.

I do not think you understand how this works, or what the significance
is. You cannot make a leap from “relatively few” to “a unique browser
fingerprint”. Also, the “fingerprint” of a text browser,such as it is,
is highly customisable, and gives far less data than a GUI browser. It’s
true that the user pool is small, but the ability to control what data
is exposed to servers can outweigh that.
You should think about this. Anti capitalist protesters who wear V masks
are part of a large pool but are far less effective than gray folk. It’s
much easier to infiltrate finance houses in a suit - you choose the
characteristics you reveal as appropriate to your intentions.

I ask you to be specific. If you think that Kloak provides an answer to
mouse fingerprinting, explain why, and test this for yourself,
using different qubes under different configurations using the Whonix
recommended tool. If you think that fingerprinting techniques are scalable
to internet scale, provide specific references for that claim.

Please do not add further noise until you have done this.

5 Likes

Unman, it seems I underestimated your suggestion.
I have done more research now on the new info you have given.
But let me first highlight the irony in that. That I, a user, needs to do the research, instead of the expert/developer.
I have been very comprehensive in my posts, and detailed. Explaining where I’ve learned (Whonix docs and forum) and why I see the issues I describe.
I think you should as a developer see that the problem is a lack of documentation. Because the statements you are making are undocumented. Such as qubes event buffering being unnecessary because qubes by default already has enough random delays to prevent being identified by mouse movement fingerprinting.
This makes what the undocumented statements you say, contradicting to the information in Whonix docs.

I will tell you what I’ve found out with my new research, but I also must point out that it’s not ideal that I, the user, is doing this. It really should be another expert, such as one of the developers of Kloak, who are specialized in mouse movement fingerprinting, to debate with you.

But with that said (me not actually being qualified), I think your solutions have a lot of merit. This is why (warning: I used an AI to help me research):

Your custom ML uses Random Forest algorithm, is much better than VMONACO which uses k-NN. It shows you know what you are talking about, which I previously wasn’t sure about.
This is what the AI said (after it rigorously studied all the source code):

The vMonaco test uses a k-Nearest Neighbors (k-NN) algorithm, which works by memorizing your specific mouse movement features (velocity, angle, acceleration) and comparing new movements directly to them based on mathematical distance.

Why k-NN Fails Against Obfuscation (Kloak): k-NN is a “lazy” algorithm that relies on the exact numerical values of your features. Obfuscation tools like Kloak work by introducing random time delays and path jumps.

Because velocity = distance / time, randomizing the time completely scrambles the velocity value.
Because k-NN measures the “distance” between data points, this randomization makes your obfuscated movements appear mathematically far away from your original clean data.
The algorithm sees a completely different pattern and fails to match you. It is highly sensitive to this specific type of noise injection.

Why Big Tech (Deep Learning) Would Be Better: Big Tech likely uses Deep Learning (LSTMs/Transformers), which are fundamentally different:

  • Pattern Recognition vs. Direct Matching: Instead of comparing raw numbers, these models learn underlying behavioral patterns. They understand that “a user who types fast usually moves fast” or “a user who hesitates before clicking has a specific rhythm.”

  • Robustness to Noise: These models are trained on massive datasets with natural variations. They can filter out random jitter or minor delays to find the core “signature” underneath.

  • Temporal Context: Deep Learning models analyze the sequence of events over time. Even if Kloak adds random delays, the relative order or high-level rhythm of your actions (e.g., “mouse moves to button, pauses, clicks”) may remain detectable to a sophisticated model, whereas k-NN sees only chaos.

Conclusion: The vMonaco test proves that simple, naive algorithms can be easily broken by obfuscation. However, it does not prove that sophisticated, AI-driven trackers used by Big Tech cannot identify you, as those models are specifically designed to ignore the exact type of noise that fools k-NN. Passing the vMonaco test confirms you are safe from basic scripts, but not necessarily from advanced behavioral biometrics.

It also said this about deep learning vs Random Forest (Warning: I sensed the AI might be making a mistake in the below info. An expert would need to verify if this is wrong or correct):

Adversarial Defense
Random Forest: Can sometimes be tricked by simple noise injection.
Deep Learning / LSTM (Likely used by Big Tech): Often more robust against sophisticated obfuscation (like Kloak’s random delays).

Cross-Session
Random Forest: Struggles to link sessions months apart without re-training.
Deep Learning / LSTM (Likely used by Big Tech): Can build long-term “personality” profiles that persist over years.

There are many things that really needs more answers, research, work on. But the most immediate question I have, is also an answer to your question about why I think Kloak is necessary.
The reason I think so is because the unintended random delays qubes cause by default, even without VNC or qubes event buffering, as you explained, is randomly unreliable if that phrasing makes sense.
The problem i see is this:
If I have two accounts but I don’t want big tech to know they are both mine, so I need to avoid being identified by mouse movement fingerprinting.
If i successfully obfuscate and avoid being identified 9 consecutive days, then on the 10th day, the randomly unreliableness of qubes unintended delays, cause me to become identified. Then it doesn’t matter if I was avoiding identification the previous days.

Kloak ensures that obfuscation is intentional and constant. It’s dependable.
Kloak can ensure that there’s constant criterias being applied. For example: maximum 10 hz frequency, 20% packet loss, jitter.
Does qubes do that by default? Because this really should be precise science.

I could argue more things you said which I have a problem with, such as your claim that many things I said in first post are unsubstantiated but you didn’t explain why. How am I supposed to defend myself against that when I don’t know what exactly is the issue?

But I will just let all those other things you said slide so we can get back to making constructive progress on what matters most.

4 Likes

Thanks for the extra info about your mouse moves, now I am going to use it against your own “arguments”:

You have proved you are not paying attention to what was said, yet you are accusing others for being “vague” and “noise”.

You see? - One doesn’t need JS or even a browser for behaviour tracking and Kloak is irrelevant. Moral of the story: privacy requires awareness, not just tools.

2 Likes

“i had to scroll up” doesn’t necessarily mean I used the mouse wheel to scroll up. It’s an expression. I wish big tech adversaries were as simple as you are. Then we certaintly wouldn’t need Kloak.

It’s obvious you’re not actually here to have constructive discussion.
I gave you several chances to be specific and clear and you yet again just keep jumping around creating more distracting noise.

2 Likes

@plankretriever

Being simple, I will put it simply:

If Qubes, its devs, or the answers its community provides don’t satisfy your requirements, you can install non-Qubes Whonix and use Kloak.

2 Likes

I hope this idea isn’t stupid for reasons i dont understand but do any (but gaming) apps even need to know that I move the mouse?
If not couldn’t we build something that lets the mouse jump to the spot I click on when I click… As in the rest of the time its moving in dom0, but not the Qube.

I didnt research how to implement this (or if its more or less easily possible) - but if the mouse doesnt move but only jump to another point (think xdotool or what this was for the mouse) then there is no mouse movement fingerprinting.

Update: I asked ChatGPT and it said:

  • yeah kinda possible

Problems:
- sites still see click positions and timing
- hover menus/tooltips/CSS :hover may break or feel weird
- drag/drop, text selection by mouse, games, maps, drawing apps break badly
- anti-bot systems may fingerprint the “teleporting cursor” behavior itself

If you have a mouse with more than 3 buttons (left middle right) maybe you could bind one to “set point A and point B” so you could drag / drop… As for hover idk. Suppose sth could be hacked together there too.

What would be left would be the keyboard - dumbest idea here (I’m a bit i3 fan) would be some keybind that spawns a text-editor-field-thingy in the VM that you have focused atm, where you type stuff, and then another keybind puts that into the copy buffer or so, so you can paste it in the website. This would get rid of keyboard fingerprinting too.

If this were to be implemented well, it might be similarly somewhat-annoying to use as Qubes crtl shift c crtl shift v thing (so usable as soon as you have the muscle memory for it). The issue with fingerprinting here would ofc be that the userbase for this might be small.

2 Likes

Thank you @unman , gonna try it out the VNC solution . Does this work the same in combination with a Whonix Workstation qube, for best overall privacy?

This statement seems a bit averse to Kloak. Do you think Kloak is not effective in obfuscating keystrokes and mouse movement - or was it just a suggestion to test all tools thoroughly, before making up claims?

Isn’t the biggest advantage of Kloak being a “boring”, easy to use, quasi-standard tool for key and mouse obfuscation? I think, most utterly important for anonymity to blend in with the masses. We would have an issue, if there were X versions of Tor Browser out (let’s count Mullvad Browser as derived from it).

Overall it might be best to agree on and continue development of a single keystroke/mouse obfuscation tool. Kloak is just a popular example . Is it technically possible to replace Qubes-internal buffer solution by Kloak?

2 Likes

@kuhbs I agree with your post. Such a solution where the mouse movement is removed, and only the clicks remain is ideal for anonymity.
In the link I shared in the first post, there are some posts that talk about such a tool called Mouser. And the developer of Mouser is also present in that topic.
But unfortunately, Whonix devs don’t want to use Mouser, and I think their reasoning is very weak. Especially considering that Qubes Event Buffering doesn’t work and they seem to have given up on it. They should let Mouser be used if they don’t complete Qubes Event Buffering.
And many of the problems you thought of with a tool like Mouser, can also be solved. There are some solutions mentioned in the replies of the linked topic.

This is the most important. Even if a tool like Mouser is better for anonymity, it’s actually useless if there isn’t a big user base to blend in with who also use Mouser. So Both Kloak/qubes event buffering and Mouser are good solutions, but only if they complete Qubes Event Buffering so it actually works the same way as Kloak does.

I know feds would love it if the privacy users can be silenced and bullied away.
You are actually making it very obvious how biased the moderation is in this forum. You continue making constant non-constructive, off topic, combative posts, and moderators do nothing. But if it was the other way around, if I would invade other topics and mimic your behavior, it would be a quick ban.

You are also exposing yourself very well, showing everyone your interests. Because you choose to be against privacy. And it seems your excuse for that is you don’t like me for some reason? I don’t know. But that shows your priorities.
I noticed similar with Unman, when he said he wasn’t going to reply to me again. He chooses to make it personal and about ego instead of trying to solve an important problem that qubes os is facing.

I am a humble person, as you could see in my recent reply to Unman, where I chose to commend him and ignore some of the less important incorrect statements he made, so we can focus on what’s important. This is not about ego for me. I genuinely want to make Qubes OS better and help the community to understand real threats to their privacy when using Qubes OS.

2 Likes

@kuhbs I agree with your post. Such a solution where the mouse movement is removed, and only the clicks remain is ideal for anonymity.

Well it would “solve the problem of there being data to fingerprint”, but it would only be anonymous if everyone uses it, because if you are the only one delivering no data, that is a VERY unique fingerprint.

I was thinking you could just use a hermes bot running a browser with sth like agent-browser xD this is very much anonymous (millions of other bots do it too xD) and you can say in human language what you want from the browser :wink: “log into this website and do this”.
This might just be the most anonymous solution (actually this time), given that half the internet traffic by now is bots already.
This WOULD solve the problem and be VERY anonymous. It might not be very private, unless you are rich and can afford a bunch of good GPUs - otherwise you share it with ChatGPT or so.
You dont even need a keyboard, hermes has a speech to text mode if you have a working microphone x)

About qubist and unman

Don’t wanna get to involved here, but I think when you dedicate half your life to coding qubes and moderating this forum than it is not physically possible to be against privacy and security.

PS: I thought about the hermes bot again, and I think this should be the solution to this thread actually xD Hermes interprets websites from their source and doesnt move the mouse, it just clicks on links directly. There is little way to be more anonymous than that (if you just look at mouse movement fingerprinting and text, bcs the text is actually written first and then “copy pasted” into the browser by hermes (mostly)). Even if your hermes has its own fingerprint, you can just reset it and it has a new fingerprint (actually not sure if all hermes have the same fingerprint here, I suppose there are differences, but its definitely not YOUR fingerprint). You could start a fresh hermes for each browsing session… Only issue is captchas… Maybe if you use a touchscreen for those, but thats still fingerprintable. So even this has its limits.

3 Likes

Is Hermes a fine-tuned version of Llama? And then you run it inside OpenClaw?
It’s a good suggestion but it takes a lot of RAM. Not many Qubes OS users have 32 GB RAM.
Buying a raspberry pi probably won’t work because they have too little RAM and a bad CPU.
But a user can buy a second laptop for this.
I’m not sure right now what do to do about isolation though.
Because if you use OpenClaw for all your online identities, you should really have OpenClaw installed into many different VMs or qubes.
Qubes OS would be great but need a 32GB computer which works with Qubes OS.

Your solution is very good but it doesn’t account for cost/hardware requirements. It’s a solution many people won’t be able to use.
If they currently have a laptop with 16GB RAM, they have to decide if they will buy a new computer, only for protecting themselves from mouse movement fingerprinting.

Another issue is OpenClaw is built to use and optimized Chromium browser with puppetteer or playwright, not tor browser.
That means losing all the fingeprinting protection from tor browser, just to protect yourself from mouse movement fingerprinting.

I think your solution is the future, but it doesn’t seem to be ready yet.
I think we still need Kloak/Mouser for now, until we reach the point where OpenClaw is more accessible and can use Tor Browser effectively without breaking the fingerprint of tor browser.
Imagine a future of Qubes OS where OpenClaw is installed by default into every Template.

1 Like

Link to hermes: https://hermes-agent.org/

I use it with ChatGPT codex behind it, but you can use pretty much any provider or your own LLM. So not private towards ChatGPT or whatever provider you choose, unless you run the LLM yourself. But the browser fingerprint (especially mouse + typing) isn’t yours anymore. Its not even your typing style if you just tell it roughtly what to say and let it formulate it together.

I can’t say it uses a lot of ram. I am running one right now and the free -m says it uses 1GB of its 4GB of ram.

As for tor browser, I asked hermes if it can operate a tor browser and how xD and it said (summarized by me) “yes, but not with regular browser automation tools - it would use screenshots and then xdotool and alike”.
hermes is quite crazy, it can do pretty much anything, so I haven’t tried that but I’m sure it would get from A to B.

If you setup the right permissions you could probably even run hermes outside of whonix itself and then let it communicate what it wants to do in the whonix-workstation VM.
BUT keep in mind it needs a LLM behind it, so you self host it or you use a provider - which then ofc sees all that data.

2 Likes

This is the exact same thing I addressed here, but there it was about “feds [that] would love if all discussions about intel me was deleted”.

Given this, and what I answered here, and what others have answered, we can learn that:

  • OP is defenseless, despite the existing privacy measures implemented in various software products (Qubes-Whonix and non-Qubes-Whonix) and because of Intel ME existing,
  • because of that, OP is being bullied by “the feds” for trying to “defend freedom”,
  • that “freedom” being achievable only by the not-implemented-out-of-the-box features, that Invisible Things Lab and ENCRYPTED SUPPORT LLC should implement as free labor,
  • OP is not willing to support the development of those features financially, but willing to keep on complaining about the lack of them, about other methods being ineffective, about “biased moderation” and about others being “anti privacy”

There already were solutions presented, but if they are not satisfactory, then I don’t know what’s the goal of this thread (what OP is trying to achieve), other than a constant stream of complaints and rejection of ideas.

4 Likes

Please don’t forget the other significant resources …

https://inteltechniques.com/links.html

2 Likes

Ok, so Hermes is a competitor to OpenClaw. That means the system requirements are similar.
I am not sure you’re aware of this but when you’re not using a local LLM with Hermes, you are putting a lot of trust in a corporation to not log your queries and meta data.
That’s one of the reasons why people who want privacy use a local LLM.
If you only use Hermes to automate web browsing, then a LLM with <8b parameters is enough. That’s 6-8 GB RAM minimum requirement. Hermes is another 1GB ram.
Then think about all the minimum qubes you want to use.
I think a computer with 16 GB ram is going to be borderline yes/no possibility. A very tight fit if its possible.

But with some ai assisted research, it seems your solution of using Hermes with xdotool is a great solution.
I made AI write a guide on it. We can use as a first draft for a community guide.

I still think it’s very important to make Qubes event buffering work, or replace it with Mouser. But until the devs give any update on why the developement has been stopped, we need alternative solutions like yours.

I think it’s probably important that everyone uses the same configuration for Hermes and xdotool because otherwise we will have unique mouse and keyboard fingerprint. Kloak and Hermes will not have the same mouse movement fingerprint. Mouser and Hermes will also not have the same fingerprint. And if we don’t use the same hermes configuration, even 2 different hermes users will have different mouse movement fingerprint. We will not blend unless we use the same configuration.
I guess a temporary solution is to change the configuration for each identity. But that also counters the idea of everyone using the same configuration.

Below is draft 1 for a community guide, thanks to you for coming up with the idea.

================================================================================
GUIDE: AUTOMATING TOR BROWSER WITH HERMES & XDOTOOL IN WHONIX 18
================================================================================

1. WHY THIS METHOD PRESERVES ANONYMITY
--------------------------------------------------------------------------------
The core principle of Tor Browser anonymity is ensuring your "fingerprint" 
(unique digital ID) matches the crowd. Traditional automation (Playwright, 
Selenium) fails here because they inject code into the browser, setting 
flags like 'navigator.webdriver = true' that immediately reveal you are a 
bot .

Using Hermes Agent with xdotool avoids this entirely:

A. NO BROWSER INJECTION
   - Hermes does not touch the browser's internal code.
   - It does not open CDP (Chrome DevTools Protocol) ports.
   - It does not expose 'navigator.webdriver'.
   - The browser sees only standard input events, indistinguishable from 
     a physical human using a mouse .

B. PIXEL-LEVEL OPERATION
   - **Input:** The agent sees the screen via screenshots (vision).
   - **Output:** The agent uses 'xdotool' to simulate physical mouse 
     movements and keystrokes at the Operating System (X11) level.
   - **Result:** The browser receives events exactly as if a real hand 
     moved the mouse. The "source" of the input is invisible to the 
     browser's fingerprinting scripts.

C. TOR'S LETTERBOXING PROTECTION
   - Tor Browser forces window sizes into "buckets" (multiples of 200x100px) 
     to prevent screen resolution fingerprinting .
   - Whether you run in a virtual display or a native window, Tor's 
     built-in "Letterboxing" ensures the reported window size is identical 
     to thousands of other users, masking the underlying OS environment.

--------------------------------------------------------------------------------
2. PREREQUISITES FOR WHONIX 18
--------------------------------------------------------------------------------
- **OS:** Whonix 18 Workstation (running on a host with Wayland).
- **Critical Fact:** Tor Browser in Whonix runs on **X11** even if your 
  desktop is Wayland. This allows 'xdotool' to work directly .
- **Network:** Ensure all traffic routes through the Whonix Gateway (default).
- **Tools:** Install 'xdotool' and 'scrot' (for screenshots).

   sudo apt update
   sudo apt install xdotool scrot

--------------------------------------------------------------------------------
3. METHOD A: NATIVE X11 (VISIBLE & INTERACTIVE)
--------------------------------------------------------------------------------
Best for: Manual monitoring, debugging, and seeing the automation in real-time.
Risk Level: Low (Standard Tor fingerprint).

STEP 1: Launch Tor Browser
   - Open Tor Browser normally from the Whonix menu.
   - **CRITICAL:** Do NOT maximize the window. Let it start in its default 
     size (usually ~1000x1000px). This allows Tor's Letterboxing to work.

STEP 2: Identify the Display
   - Open a terminal in the Tor Browser window (or a new one).
   - Run: echo $DISPLAY
   - Note the value (usually `:0` or `:10`).

STEP 3: Configure Hermes Agent
   - Open a terminal for your Hermes Agent setup.
   - Export the display variable to match Tor Browser:
     export DISPLAY=:10  (Replace ':10' with your actual value)
   - Ensure Hermes is running in the same Whonix Workstation VM.

STEP 4: Run the Automation
   - Start Hermes Agent.
   - Give instructions via the Hermes window (e.g., "Go to example.com").
   - Hermes will take screenshots of the *visible* Tor window and use 
     'xdotool' to click/type.
   - **Your Interaction:** You can click/type in the Hermes window freely. 
     Tor Browser will **not** see these actions; it only sees the 
     'xdotool' events targeted at its own window.

--------------------------------------------------------------------------------
4. METHOD B: VIRTUAL DISPLAY (HEADLESS & MAXIMUM ANONYMITY)
--------------------------------------------------------------------------------
Best for: Production use, perfect consistency, and hiding the window 
          from the physical desktop.
Risk Level: Zero (Perfectly standardized fingerprint).

STEP 1: Install Virtual Display Tools
   sudo apt install xvfb

STEP 2: Create a Virtual Screen
   - Start a new virtual display (e.g., on display :99) with a standard 
     resolution (e.g., 1280x720). Tor will auto-adjust this to a safe 
     bucket via Letterboxing.
   
   # Run this in a terminal:
   xvfb-run -a --server-args="-screen 0 1280x720x24" --auto-servernum echo "Ready"

STEP 3: Launch Tor Browser in Xvfb
   - You must kill the normal Tor Browser if it's running.
   - Launch Tor Browser specifically within the Xvfb environment:
     
     # Create a script 'run-tor-xvfb.sh' or run inline:
     xvfb-run -a --server-args="-screen 0 1280x720x24" --auto-servernum \
       /usr/bin/tor-browser/Browser/start-tor-browser

   - Note: The browser window will NOT appear on your desktop. It is 
     running in memory on display :99 (or whatever number xvfb assigned).

STEP 4: Configure Hermes Agent
   - Open a terminal for Hermes.
   - Point it to the virtual display:
     export DISPLAY=:99  (Or the number assigned by Xvfb)
   - Install a screenshot tool to capture the virtual screen:
     sudo apt install scrot ffmpeg

STEP 5: Run the Automation
   - Start Hermes.
   - Hermes will use 'scrot' to capture the virtual screen and 'xdotool' 
     to control it.
   - **Visibility:** You will NOT see the browser window. You must rely 
     on Hermes to describe the page content to you via text.
   - **Fingerprint:** This method guarantees the browser sees a 
     standardized, headless Linux environment, making it indistinguishable 
     from any other Tor user.

--------------------------------------------------------------------------------
5. IMPORTANT CONFIGURATION TIPS
--------------------------------------------------------------------------------
- **Typing Speed:** 'xdotool' types instantly. To avoid "robotic" behavioral 
  flags (if a site checks typing speed), add a small random delay in your 
  agent script:
    xdotool type --delay 20-40 "search query"
- **Mouse Movement:** Use 'xdotool' with 'mousemove' and 'mousemove_relative' 
  to simulate natural, slightly curved mouse paths rather than straight lines.
- **Whonix Gateway:** Never disable the Whonix Gateway. If Hermes tries to 
  access the internet directly (bypassing Tor), your real IP is leaked.
- **Window Size:** In Method A, never maximize the window. In Method B, the 
  Xvfb resolution is fixed, so Tor handles the rest.

--------------------------------------------------------------------------------
REFERENCES
--------------------------------------------------------------------------------
 Tor Project Blog: "Browser Fingerprinting: An Introduction"
 hermes-computer-use GitHub: "Pixel-level browser automation"
 Tor Browser Support: "Fingerprinting protections" (Letterboxing details)
 Whonix Documentation: "Tor Browser on Wayland/X11 compatibility"

================================================================================
END OF GUIDE
================================================================================
1 Like

I was joking in the beginning, but its kinda not wrong.
I think installing hermes in whonix, or touching whonix at all, makes it less anonymous. I always thought (am I right? not sure, I kinda dont use tor at all) that you a) keep whonix-workstation upgraded and b) keep torbrowser upgraded and c) otherwise dont touch that thing at all - to stay most anonymous with it.

Anyways, I think it might be best to have a hermes Qube that has user@ rights on the whonix qube, ideally in a way that does not modify the whonix-workstation VM in any way.
Maybe I’m wrong here, but my assumption being that we assume torbrowser can be hacked while Qubes / XEN can not, so if sbd owns the browser and can “look around” in whonix-workstation, but not escape the VM and not get the users real IP, we don’t want to modify whonix-workstation in a way thats fingerprintable.
Maybe I went to far here, not sure.

If that is not the case then yes, your approach sounds good.

I’d still feel better with putting hermes into another VM.

As for the privacy implications of LLM - there are only so many solutions that are affordable to most users, that would be ChatGPT I assume, or similar providers. They are very much not privacy friendly.
Only very few users would be able to afford to run their own LLM. I think most providers do not provider a proper way of anonymous payment. But as said above, at least then only the LLM provider knows what you do, not everyone else.

So it all has up and downsides. If somebody sets this up pls share a video, would be funny to see.

2 Likes

How exactly is my suggestion that you use exactly the solution of your choice related to “silencing and bullying privacy users”, and what have “feds” to do with anything I said?

Do you realize you have just proved you are not looking for any solution at all?

1 Like

People must realize that certain topics require at least basic understanding of how related technology works (which needs more than reading a few articles, “Whonix docs and forums” or asking AI) before opening threads with sensationalist titles and accusing others for their own limited view on otherwise important matters.

2 Likes

Noise. All you are doing is making it harder for the community to discuss and find a solution.
I know it’s a frightening thought for feds that the public can find ways to improve their privacy, and AI helping to educate the people. The power dynamic is shifting. Feds are losing their power, and the people are increasing their power.
Remember this everyone: don’t let feds intimidate and bully you. You have to stand up for your rights. Let reasoning guide your path forward, not the harsh word of authority, which some feds seem to believe they have here.
Expose corruption and flaws. If they respond with aggression, deflection and distractions, instead of trying to solve the problems with reasoning, that’s a sign of an even deeper problem.

I had the same thought as you did but didn’t look into it. But now I have used an AI to look into it. I don’t know if the AI is right or not. I’m aware that human experts are often better than AI in these kind of complicated questions.
But the AI says it’s not possible, and I have pasted its answer below.

================================================================================
WHY A "HERMES QUBE" CANNOT CONTROL "WHONIX" WITHOUT MODIFICATION
================================================================================

1. THE CORE ARCHITECTURAL LIMITATION
--------------------------------------------------------------------------------
Qubes OS isolates VMs (Virtual Machines) completely. 
- VM A (Hermes) cannot "see" VM B (Whonix).
- VM A cannot send mouse/keyboard events to VM B.
- VM A cannot take screenshots of VM B.

Unless a specific communication channel is explicitly created, they are 
air-gapped from each other by design.

--------------------------------------------------------------------------------

2. THE "XDOTOOL" DEPENDENCY PROBLEM
--------------------------------------------------------------------------------
To automate a browser, the tool `xdotool` (or `scrot`) must interact with 
the X11 display server where the browser is running.

- X11 is a local socket protocol. It does not work over the network.
- `xdotool` must run INSIDE the VM where the browser window exists.
- If `xdotool` is not installed in Whonix, it cannot run in Whonix.
- If you install `xdotool` in Whonix, you have MODIFIED the Whonix Qube.

RESULT: You cannot drive the browser from a separate VM. The driver 
must live in the same VM as the engine.

--------------------------------------------------------------------------------

3. WHY REMOTE CONTROL ATTEMPTS FAIL (THE "MODIFICATION" TRAP)
--------------------------------------------------------------------------------
To make VM A control VM B, you must create a bridge. Every bridge requires 
modification to VM B (Whonix):

A. SSH METHOD
   - Requirement: Install and configure an SSH server in Whonix.
   - Modification Status: MODIFIES Whonix (installs packages, changes config).
   - Risk: Increases attack surface; violates "pristine" requirement.

B. CUSTOM RPC METHOD
   - Requirement: Write a script/daemon in Whonix to listen for commands 
     and execute `xdotool` locally.
   - Modification Status: MODIFIES Whonix (installs scripts, changes policies).
   - Risk: Requires persistent changes to the VM template or config.

C. X11 FORWARDING (QUBES GUI)
   - Requirement: Allow Whonix to push its display to Hermes.
   - Modification Status: MODIFIES Whonix (requires changing Qubes RPC 
     policies to allow the display stream to flow OUT to Hermes).
   - Result: Even if the binary isn't changed, the security policy 
     is modified, altering the VM's fingerprint and behavior.
1 Like