Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support Whonix persistent files #28

Open
tasket opened this issue Jul 12, 2019 · 1 comment
Open

Support Whonix persistent files #28

tasket opened this issue Jul 12, 2019 · 1 comment

Comments

@tasket
Copy link
Owner

tasket commented Jul 12, 2019

Currently vm-boot-protect is the most compatible mode for Whonix VMs (but see issue #31).

It might be desirable to explore using the more extensive vm-boot-protect-root mode for whonix-ws VMs by mapping which Tor and Whonix files in /rw should be whitelisted. Going beyond whitelists to use deployment files and hashes might also be useful.

The goal would be to provide some after-restart mitigation to whonix-ws AppVMs that have experienced some kind of attack involving a successful privilege escalation. Hopefully, this attack resistance would be in addition to whatever persistence (bookmarks, saved documents, etc.) that the user gains vs using a DispVM.

cc @adrelanos

@adrelanos
Copy link
Contributor

adrelanos commented Jul 15, 2019 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants