What is Qubes + Whonix common history?

I clearly remember when asked why choosing fedora for dom0, the devs answered: because we have to trust someone since we can’t develop our own OS.

So they choose Whonix too. And I see this topic as a challenge to their judging, thus challenging our trust in Qubes.

But I am not forgetting: I have to trust someone when I want online. That’s default Qubes in a whole, when I am.

1 Like

“I clearly remember when asked why choosing fedora for dom0, the devs answered: because we have to trust someone since we can’t develop our own OS.”

Could you provide a URL or pointer to where “the devs” said or implied “we can’t develop our own OS.”?

“So they choose Whonix too. And I see this topic as a challenge to their judging, thus challenging our trust in Qubes.”

Think I understand your position. No intent by me to challenge trust in Qubes. Still questioning “their judging”, or rationale, is not meant as attack and I hope not perceived that way. Am I out of line @unman @adw @marmarek and all?

Appreciate you. Apologizes if my questions and/participation in this thread was disruptive!

3 Likes

That was discussed in a dedicated thread, so please let’s stay on topic.

2 Likes

Will do. Thank you for link. On topic, I hope, any idea why “What is Qubes + Whonix common history?” appears to (me at least) to focus more on TorVM than Qubes + Whonix common history?Maybe I missed it, but this thread has little to no input from the Whonix team and dare I quote it

I may not agree with @rideordieII on style and even some substance but things like

though polite, and possibly even informative to someone, reads as not staying on topic itself.

But I will assume that was not your intent and I am just in a bad mood atm.

So to get back to the beginning.

Reading the Qubes mailing list discussions and the Whonix wayback machine (sorry Internet Archive) pages from the time, what questions still remain?

Yes I am

:confused:

Your help and insights would be most welcome.

1 Like

Just for the record, there is no such user as “rideordieII” on the Whonix forums. As a moderator of those forums, I have no reason to believe the user has ever been present there (though it looks like they were aware our forums are a thing). Certainly if they did there what they did here, their personal attacks against Qubes staff would have been deleted. The moderation teams for Kicksecure and Whonix do not tolerate abuse of other individuals on our forums and do not condone them anywhere else.

As for the rest of the discussion about the history behind the projects, I’m not aware of when or how Qubes-Whonix became a thing despite contributing heavily to Whonix and occasionally to Qubes as well, since I spend most of my time maintaining and developing new features for Whonix and its less anonymity-focused spinoff, Kicksecure. Taking the time to go through the mailing lists and the like would take valuable development time away from the project. Given some of the conversation above, it kind of sounds like it would mostly provide something to criticize rather than something of real value. Therefore I simply will reiterate what unman said; reading the mailing list archives is the best way to get background on this.

While they are notoriously unreliable, if someone is interested in getting a summary of the history, doesn’t have the time to put one together themselves, and can’t convince someone else to put it together for them, LLMs frequently work as great summarizing mechanisms, so long as one is willing to fact-check them thoroughly. You’d want to fact-check any summary built by someone other than yourself anyway for best results.

6 Likes

@rideordieII = @rideordie

2 Likes

Thanks, was not aware of that.

1 Like

Since no one has addressed this point, Whonix is offered as a community
template and included on the install iso. There are many examples of
development work done in Qubes to support and maintain Qubes-Whonix.
It’s explicitly stated in the FAQ that “The main way Qubes OS provides
privacy is via its integration with Whonix”. I would have thought that
any reasonable person would conclude that the Qubes team has confidence
in the Whonix team and software.

I’ll see about including some comment in the documentation, but it’s
likely to point to the mailing list sources. I’m not clear what
“statements and claims” you think Qubes could make that are not
already made, or are to be found in the Qubes-Whonix documentation.

I never presume to speak for the Qubes team. When I comment in the Forum I speak for myself.
2 Likes

I have already done that and could not find the answers to the questions put here. If I am supposed to find there yet another shallow key “answer”, like the one of “Why trust Fedora?” (because one person “liked it” in distant past), that actually provides zero meaningful information.

1 Like

Unlike the documentation, that can be signed, the mailing list archive is not really a reliable source, especially considering that now Qubes docs are even behind Cloudflare (which was not the case before the migration).

Also, perhaps nobody would like to waste time to find the essential info in tons of other words, so a decent summary seems more appropriate.

I am saying this because:

  • You confirmed the validity of the questions put here
  • There is still no valid answer to “Why trust Fedora?” (as can be seen in the other thread)

So, I really hope this thread won’t also end up in just a lot of noise, although the first attempts already started.

I’m not clear what statements and claims you think Qubes could make that are not already made, or are to be found in the Qubes-Whonix documentation.

I think all initial questions except #1 and #3 remain.

I also still hope for your answer about the “among other reasons” (as part of #2). If you feel that is too personal or conflicts project positions, please say so directly and I will never ask again. I accept “no” as an answer.

I keep asking because you always have good technical reasons for the things you do and I think it is valuable to learn from that.

1 Like

Why? Couldn’t trusting the boundaries of XEN eliminate all kinds of ‘quality’ debate concerning the software running in a qube itself?

When no other strings are attached, I find it not implausible to choose what you like or what works best for you at a given time.

In that sense it doesn’t matter whether it’s $DISTRO in dom0 or another template shipped.

Rather than pretend that we can prevent these inevitable vulnerabilities from being exploited, we’ve designed Qubes under the assumption that they will be exploited. It’s only a matter of time until the next zero-day attack.

3 Likes

Well, even @unman couldn’t succeed to get the answer on why, it looks.

2 Likes

hi, me & others have not so much free time so what is appreciated is just asking about whatever is missing from what can be found online, and being clear what your underlying/actual question is so it can just be answered directly instead of what feels like an information fishing expedition / delivery service.

like what are you actually interested in knowing - why Qubes OS is shipped with whonix rather than torvm?

my understanding is whonix provides more features and is easier for a less-technical user: there is a GUI for interacting with the tor service, enabling bridges, etc., as well as work done re: time syncing (a hard problem in tor - sdwdate: Secure Distributed Web Date , Tails - Time synchronization). the whonix workstation is an important part of a safer (tor-powered) user experience, as otherwise a user needs to customize their tor browser instance to not double-tor, configure thunderbird to listen to the right port, etc.

my goal has always been to try to get Qubes OS more friendly for less-technical relatively-high-risk users who would benefit from it.

i asked the team some years ago whether there is still value in shipping whonix-gateway vs torvm and they said yes - i’m happy to ask them again. @unman is right when they say torvm is smaller & more minimal, and therefore has smaller attack surface. for some more technical users’ needs maybe it is the right solution for them. for less-technical folks who need some guidance in using tor safely, i think the added usability & features of whonix are beneficial.

everything else about the integration has been shared in this thread or in links here… literally the first link shared (thanks @OvalZero!) is to wikipedia which links to a blogpost discussing the integration, history, funding…

How did it all start?

people seeing need/opportunity of integrating more usable privacy-focused tooling into Qubes OS, or the inverse: taking advantage of Qubes OS’s security features to provide more dependable privacy-protecting environment.

How was it decided?

people saw value in it, community started working on it led by Jason Mehring’s efforts. i pitched to find funding to support/complete this work, among other efforts that would make Qubes OS more usable for less-technical users (some have taken a lot longer… Offline documentation · Issue #1019 · QubesOS/qubes-issues · GitHub ). i found a funder (OTF) who saw value in supporting the integration and usability work, and the team was interested in having the additional capacity to do this work.

What was before that?

abe luck’s qubes torvm - GitHub - abeluck/qubes-tor: DEPRECATED . DO NOT USE . torified proxyvm for QubesOs · GitHub (what unman’s torvm is built off of)

How was trust established?

seeing each others’ work/code/projects? at the time the projects were going to CCC so i think we were able to meet in-person & discussed a little there as well

What disagreements exist between the two projects? (if any)

?

Any additional info is welcome too

?

10 Likes

hi, me & others have not so much free time so what is appreciated is just asking about whatever is missing from what can be found online, and being clear what your underlying/actual question is so it can just be answered directly instead of what feels like an information fishing expedition / delivery service.

like what are you actually interested in knowing - why Qubes OS is shipped with whonix rather than torvm?

my understanding is whonix provides more features and is easier for a less-technical user: there is a GUI for interacting with the tor service, enabling bridges, etc., as well as work done re: time syncing (a hard problem in tor - sdwdate: Secure Distributed Web Date , Tails - Time synchronization). the whonix workstation is an important part of a safer (tor-powered) user experience, as otherwise a user needs to customize their tor browser instance to not double-tor, configure thunderbird to listen to the right port, etc.

my goal has always been to try to get Qubes OS more friendly for less-technical relatively-high-risk users who would benefit from it.

i asked the team some years ago whether there is still value in shipping whonix-gateway vs torvm and they said yes - i’m happy to ask them again. @unman is right when they say torvm is smaller & more minimal, and therefore has smaller attack surface. for some more technical users’ needs maybe it is the right solution for them. for less-technical folks who need some guidance in using tor safely, i think the added usability & features of whonix are beneficial.

everything else about the integration has been shared in this thread or in links here… literally the first link shared (thanks @OvalZero!) is to wikipedia which links to a blogpost discussing the integration, history, funding…

Qubes OS Project gets OTF funding to integrate Whonix, improve usability | The Invisible Things Blog

How did it all start?

people seeing need/opportunity of integrating more usable privacy-focused tooling into Qubes OS, or the inverse: taking advantage of Qubes OS’s security features to provide more dependable privacy-protecting environment.

How was it decided?

people saw value in it, community started working on it led by Jason Mehring’s efforts. i pitched to find funding to support/complete this work, among other efforts that would make Qubes OS more usable for less-technical users (some have taken a lot longer… Offline documentation · Issue #1019 · QubesOS/qubes-issues · GitHub ). i found a funder (OTF) who saw value in supporting the integration and usability work, and the team was interested in having the additional capacity to do this work.

What was before that?

abe luck’s qubes torvm - GitHub - abeluck/qubes-tor: DEPRECATED . DO NOT USE . torified proxyvm for QubesOs · GitHub (what unman’s torvm is built off of)

How was trust established?

seeing each others’ work/code/projects? at the time the projects were going to CCC so i think we were able to meet in-person & discussed a little there as well

Thanks Michael for that summary.
The only point where I would disagree with you is that a Tor qube is simple
to use for non technical users - it just slots in to the Qubes system
and users need have little interaction with it.

There seems to be one unanswered question:

What disagreements exist between the two projects? (if any)
I am not aware of any disagreements. There are sometimes discussions
about issues affecting Qubes-Whonix in the development process, but
these are usually resolved.

I never presume to speak for the Qubes team. When I comment in the Forum I speak for myself.
1 Like

Thank you @michael.

I have done everything possible to clarify that I am asking for facts and reasoning. I tried to have the questions as clear as possible too.

The underlying reasons for this particular thread are just as public as anything else:

  • Whonix is the only community (non-ITL) template that ships with Qubes installation
  • A team member and respected community fellow has repeatedly stated that he does not use Whonix, and distributes parallel to Qubes a separate minimalist solution that has been explicitly removed from the project for Whonix
  • Whonix project leader explicitly and publicly rejected plans for minimal Whonix (link in previous post)
  • the question of (dis)trust is of ultimate importance for security
  • minimalism (not GUI) is an essential system security approach
  • firewall (not GUI) is an essential network security tool

like what are you actually interested in knowing - why Qubes OS is shipped with whonix rather than torvm?

I didn’t ask any why questions, but since you suggest, it would be interesting to know:

A) Why has TorVM been removed as an option considering:

  • it is still supported by a Qubes team member and a working solution
  • has the benefits of minimalist approach (just like we have the minimal templates by ITL)
  • it supports Qubes firewall (which Whonix after years still does not)?

B) Why did @unman’s technical questions on the mailing list remain unanswered?

C) Why is there no common effort of both teams to bring about a minimal solution?

D) Does funding for the external project mean that all privacy related matters and decisions are delegated entirely to the other project? (to the extent that if the other projects says “no minimal”, then that’s it)

How did it all start?

people seeing need/opportunity of integrating more usable privacy-focused tooling into Qubes OS, or the inverse: taking advantage of Qubes OS’s security features to provide more dependable privacy-protecting environment.

To someone like me, who is not closely familiar with the actual set of events, that sounds somewhat different from the story about the mailing list archive and the odd user.

How was it decided?

What was before that?

Thanks.

How was trust established?

seeing each others’ work/code/projects? at the time the projects were going to CCC so i think we were able to meet in-person & discussed a little there as well

What is CCC?

What disagreements exist between the two projects? (if any)

?

Read above. I have tried to clarify what seems contradictory.

Any additional info is welcome too

?

Anything related to the topic and questions.

1 Like

Chaos Computer Club.

2 Likes

… and CCC’s ChaosCommunicationCamp or ChaosComunicationCongress provide regular opportunities to meet each other.

2 Likes

Thank you @unman That question (and curiosity about trust history) drew me into this thread. Concerned @qubist might provoke FUD intentionally or not.

Most grateful @michael answered

Just one question (which I hope you will ignore if it is a dumb one)

when you wrote

were you speaking about torvm versus sys-whonix?

Maybe qubes provides a private, leak-resistant environment that does not easily reveal IP addresses or leak DNS requests. That question is asked in good faith and upmost respect. Although I can not locate the old torproject torrification page atm, that was one the main advantages of whonix-workstation (along with their docs) when I first started using it. michael may have said it better

Just to ensure I am still on topic

2 Likes

FWIW…

1 Like

it sounds like it is worth having more documentation on the Qubes OS side on how whonix within Qubes OS is useful (which maybe also clarifies why we felt the move from torvm to whonix was justified)? as most of the documentation is on the whonix side.

when i mentioned the additional features of whonix, this includes stream isolation, which is very useful feature if you dont want different qubes using the same torvm/sys-whonix to be correlated:

but that feature comes with the downside of not being able to use the qubes firewall to manage traffic:

and this is the type of stuff that the whonix-workstation tries to solve:

3 Likes