When I start my computer, from the very first time.
When I login into my account. Qubes 4.2.2 starts with WiFi adapter turned on. Looking for connection.
When qubes starts, the WiFi connection always starts as turned on.
Without my doing anything.
WiFi will automatically connect to an open, unencrypted connection if Qubes WiFi adapter sees one.
Or If I have previously used an encrypted connection, like my own home router, and have entered the password. It will connect there.
A start of qubes can start with a connection, ON, to my own, encrypted home router.
I lived for a long time without home internet. When I started my laptop that used qubes, somehow qubes said it needed to accomplish an update.
Windows is infamous, IMO, for getting updates from others nearby computers, even if I have not agreed they are part of my home Network. Maybe that has changed, but.
You might also consider to reset the DNS, (Domain Name Server) inside sys-net, sys-firewall to be encrypted DNS. and I guess, one outside the country.
A long time ago, someone was talking to a fellow who did Network things. Or should I say, the friend installed, updated servers. Ordinary user was telling his friend, the networking guy, he saved and used the specific numbered IP address instead of using using a DNS lookup service. The Network specialist laughed and said, If you use my server, my ISP, whatever IP number you sent me, I can sent you wherever I choose on the internet,
Personally, I am supposing from that, our internet security relies on the browser certificates, and the encryption that comes with them.
You should not trust me, I am not an Networking person. I am sorta spreading rumors.
There are dongles that have a VPN pre built into them, unless those same dongles have been altered by the local government structure. then again, how much can you trust any VPN? Rumors of those who do not trust Tor are around. I am not competent to say. I am sure, Those guys who write, update Tor seem to know a great deal more technically than I do. They keep coming up with features, that when they describe the feature, sound like a great idea.
I see one can purchase some of the Qubes certified computers without a WiFI adapter inside. Guessing the user is planning on using a WiFi dongle later. My problem with that is, If I buy a WiFi dongle, carefully choosing the manufacturer/model chip inside. It comes on a slow boat from China, through my countries own package delivery system.
NitroKey, the company (I have no affiliation, no personal connection) sells a router that has some security features. and sells some other stuff that sounds interesting.
I thought some of this was peripherally interesting to the topic.
Likely, I am wrong… I am often wrong. and giving out of date information.
Anyway, if I was thinking of prevent my ISP from seeing I am using qubes. You could unplug your home router, but your qubes install, first time you start qubes, after the install (re-starting computer to desktop is really part of install) It will announce to all the local routers, hotspot connections. “Hi, I am your new neighbor.”
Those who break codes, from the old days, when it was still possible, used to say. Codes are usually broken in practice, not in theory.
That is, like in front line World War one. Stuff happens, Like an advance might yield a code book that is currently being used, and even the next code book to be used. When codebooks changed, one front-line enemy unit might not have then new codebook, and request messages be sent to them in the older code (giving a crib for the new one) and sometimes insist the message be “in the clear.” Meaning not encrypted at all.
Like, poor password protection. Sit in a coffee shop, enter your logins where others might be able to read what you did. Maybe use poorly chosen passwords. Like all those who used Fox Mulder’s password, “Trust No One”