"Hidden Whonix" Guide v3.0


"Hidden Whonix" Guide

Tails | Veracrypt | HiddenVM | Whonix


This is a fully offline guide contained in a single HTML file. It uses pure CSS without JavaScript.

This guide may not display correctly in a non-Firefox browser. It is only intended for Firefox. Start by navigating in the top menu.

To view in Tails' Tor Browser, place this file in the ~/Tor Browser folder. Find it as the Tor Browser shortcut in Files app side pane.

Contact:


ttvmassive@riseup.net

"Hidden Whonix" Guide

v3.0 - Tails | HiddenVM | Whonix 15


 
 

INTRO


What Is Whonix?




Whonix is an easy to use, Tor-only operating system that privacy advocates around the world use to protect themselves.

It has superior anonymity protection compared to the Tails OS, and allows you to save all files, settings and bookmarks between reboots automatically. You can use it like a normal persistent operating system, and it allow you to do far more things on a Tor IP than just browsing websites. You can literally do anything in Whonix like a full OS, and means more safety.

Whonix works by using 'VM' technology, or virtual machines. A VM is a software method to run one OS (like Linux) inside another (like macOS), in its own window alongside all your other (e.g. Mac) programs.

It's a safer experience than only using Tails. Tails doesn't 'torify' many parts of the Tails OS and it can be very dangerous to use if you don't know what you're doing. The downside of Whonix is that extra resources are needed to power the VM at the same time as the outer OS. This is because you have to split your PC's RAM and CPU between multiple operating systems - but generally Linux is more resource efficient than Windows or macOS.

The VM - in this case Whonix - is often called the 'guest' OS, and your outer or main OS is 'host' OS. There are a few main VM programs like VMWare, VirtualBox and Parallels. The Whonix project offers the VirtualBox method which is free, open-source, and easy to use.

The actual Whonix operating system (inside the VM) is Linux, and more specifically the Debian variant. It uses 'Xfce' as its desktop environment. Xfce is extremely fast and light-weight, and yet can be configured by to look as sleek as you want by using custom themes and tweak packages. It's similar enough to Windows that you can become confident using it, with some patience and an attitude of learning.

The Whonix project is maintained by hardcore Tor and privacy activists, but is designed for any non-advanced user. This is because they want as many people using it as possible, to increase the anonymity of each Whonix and Tor user. The more people use these tools, the more it benefits us all. The Whonix community has steadily grown since its 2012 launch.


How Whonix works is that you actually run two VirtualBox VMs concurrently:

1. Whonix-Gateway-XFCE is the VM that connects to Tor (with all usual Tor connection options available like obfs4 bridges) and it refuses to pass on connections if Tor isn't working.

2. Whonix-Workstation-XFCE is the VM you actually use for your activity like Tor browsing, file playback, file creation and editing, Tor chat, and anything else you'd do in a regular OS.

The Workstation only receives Internet through a special 'tunnel' from the Gateway via its VirtualBox VM configuration. It is IMPOSSIBLE for your real IP address to leak inside the Workstation (unless there is a VirtualBox zero-day exploit and you are being targeted with it). This is the brilliance of Whonix's design.

However, if you reveal your RL identity on Tor while in Whonix then you still compromise everything. Whonix is not a license to be reckless inside the VM. OpSec is important. Please read our notes later on in the guide to stay safe as a user.

If you are more paranoid please also refer to Security, Privacy, and Anonymity ADVANCED TIPS for some good OpSec ideas.

 



 

What is HiddenVM?



HiddenVM is a new open-source tool launched in 2020 that allows you to run any VirtualBox VM on the Tails operating system.

It is extremely easy to use. It does everything in just one double-click.

The purpose of the program is to allow you to forensically hide the existence of any persistent VM like Whonix, by combining the concept of VeraCrypt encryption with the anti-forensic 'amnesia' of Tails.

The developers state that you can run Windows, macOS, Linux (e.g. Ubuntu), and Whonix all on Tails without a problem.

The existence of this tool means that after following this guide, in addition to a normal Whonix it would be possible to create a Whonix Gateway-torified Ubuntu or Windows VM in Tails, which could be used with the same level of safety. You could use a torified Windows in Tails to do some capping in a very safe, securely torified, and anti-forensic environment.

 



 

What is Tails?



Tails is a famous and easy to use open-source operating system that focuses on privacy and anonymity. Based on Debian Linux and compatible with most computer hardware, most of it is 'torified' to allow you to anonymously browse the web and download files over Tor by default.

Most significantly, Tails leaves no forensic trace on any storage connected to your computer of either its existence or whatever you do in Tails, unless you specifically go out of your way to do that. This guide will instruct you for how to safely do it.

You install Tails by burning it to a USB stick like a 'live Linux' disc. To use it you boot off the Tails USB. The files on your Tails stick are 'read only' by default, like a template that is identical for anyone who downloads Tails. (You can modify a few files like Linux kernel parameters and then save changes to the USB to slightly modify your Tails if it makes it easier to tweak some compatibility of Linux with your hardware.)

When you boot into Tails, it loads the entire Linux OS and live file system into your computer's RAM. It only runs on RAM memory. At no time during your use of Tails - unless you do special admin password-required commands to edit Tails - will the Tails USB stick have any data written to it. This design makes it extremely safe from a forensics point of view.

It also means Tails may run faster, as RAM can be faster than your USB disk's flash speed. But it also means it's recommended to have more RAM than you normally would. 8 GB of RAM is recommended as a minimum for 'Hidden Whonix'.

Tails is a very different way of computing. Because it's all in RAM only, any files you download inside Tails will not exist after you turn off that computer session. They only existed in temporary RAM, and not on any hard drive.

To make Tails useful for 'normal' computing, in which you can access your previous files, programs and settings in every subsequent session, Tails provides an official persistent storage feature. However, it does not yet support VeraCrypt as its method of storage. This guide will instruct you to not use Tails' official 'persistent volume' feature but instead use a simple VeraCrypt method in sync with HiddenVM.

No other OS in the world is as well-designed for robust, anti-forensic 'amnesia' like Tails. It is ideal as the paranoid host OS environment. If the feds suddenly raid you, just unplug your Tails stick and within seconds the system is securely shut down. If you have correctly set things up via the official VeraCrypt method in this guide, this means they cannot get legal evidence of your contents existence even if they seize and analyze your computer equipment or hard drives.

Although Tails is innovative, using Tails alone (without Whonix) is not safe enough to use for online activity. It is very dangerous to rely on alone. Its limitations in anonymity security are why Whonix was created and continues to be needed today. Continue reading to learn why you should use Whonix combined with Tails, as the safest way to do your activity.

 



 

Why You Should Use "Hidden Whonix"


Why not use Tor Browser in a normal OS like Android, iOS, Windows, macOS, or even Linux Mint?

- Any operating system created by Google is spying on, recording, and storing on their servers absolutely everything happening on the device. They profit from recording your every tap, swipe, and pinch to zoom. This includes all desktop Google Chromebooks (Chrome OS), or the default provided Android. All other modern smartphone and tablet OSes such as Apple's iOS and iPadOS are similarly very cloud-connected and unsafe to use. Only recently emerging Linux desktop OS-class smartphones might become safe enough to use. They are still too early to be reliable yet.

- Windows 10 is the single worst piece of desktop computer surveillance software ever created - apart from Chrome OS. It records everything you type on your keyboard and much more, including hash values of all of your personal files, and sends it to Microsoft 24/7 as 'telemetry data'. They are known to compare files to databases of other files. Even if you turn off some of the default telemetry settings, Microsoft has been known to notoriously turn them back on in the background after you install Windows Updates. You have no control in Windows 10. It is suicide for a user to touch Windows 10 if it is not 100% torified in a very secure way from the very beginning, and only ever used for that activity. (With HiddenVM, you can now set up a "Hidden Windows" VM that is torified by a Whonix Gateway.) You might be lucky using regular Windows, but it is at your grave risk.

- macOS is closed-source software. Apple cannot be trusted. They fully cooperate with law enforcement, and they control the background software. They have been known to issue silent updates without you knowing. Even if you do see the updates, it is closed source and there could be telemetry collection occurring without you knowing it. There are default macOS settings which can leak personal data onto Apple iCloud servers such as your macOS clipboard data. Lastly, third party software you may have on macOS spies on your files that you download in macOS in ways you may not realize.

- Even a Linux OS on its own is not safe enough. It is not torified, and there are many ways that downloaded files related to your content can leak into the cloud in such a non-torified environment. This can include video players like VLC, PDF readers like Adobe Reader, and more. There is a lot more 'telemetry' occurring by third-party Linux programs than you realize, and if not torified you can be compromised.

- For all the examples above: Many things you do when consuming files are too risky to do in a non-Whonix and non-torified OS. E.g. you are regularly copying archive passwords for known files in the OS housing your Tor Browser. If you accidentally paste one of those passwords from your clipboard into your non-torified and RL-connected Google Chrome address bar, Google and law enforcement can suddenly discover that you are a file type sharer.

- Also applying to every non-Whonix OS: Some files you download will then accidentally open in non-Tor but Internet-connected programs (e.g. a GIF file which may open by default in your non-Tor Internet browser). Or you might accidentally save an image from inside the standalone Tor Browser to your RL Dropbox folder, instantly incriminating yourself with law enforcement. Opening PDF files in Adobe Reader (on any regular OS) is a risk because it may send data on opened files to Adobe servers. Software programs are increasingly Internet-connected and telemetry is on the rise. You need to completely separate your online life from your RL life, with separate operating systems.

Why not use Whonix inside a regular Linux Mint host OS like the Guide pre-v3.0?

- This Guide had always a major weakness in its design - even though it still was basically the safest method to do activity - which was that even if your Whonix VMs containing your files are protected inside a deniable hidden VeraCrypt volume, your host OS still had undeniable forensic evidence of a 'Whonix' existing in your VirtualBox instance, and a VeraCrypt volume in your VirtualBox program settings. LEA could use such evidence to undermine your deniability, and make it much harder for you if you are prosecuted.

- We need Tails as our host OS from for its powerful amnesic design, to make sure that we never leave a forensic trace of our files on our hard drives ever again.

Why not just use Tails on its own?

- Although it's simpler to boot up, Tails in the end is harder to use due to its strict amnesic design. To use it as your main OS, every time you boot up Tails you have to re-install your programs (like VLC), or re-download any files you downloaded before. Tails has improved its options to save persistent programs, files and system settings, but those features are not yet VeraCrypt-compatible. Tails is still nowhere near as convenient for long-term persistent computing, compared to Whonix.

- Tails is also not safe enough for regular file consumption. The torification it gives to the outer Tails system cannot be relied upon. Tails has a long history of bugs with applications in the outer Tails leaking your real IP address when they were supposed to be securely torified. Recently in 2020, Facebook hired a security firm to catch a serial online child abuser by finding an exploit in the Tails default media player that leaked any user's IP address.

- It is simply too unsafe to have your raw IP address and your Tor IP address both viewable by an OS in which you directly consume files. We need the strongly sandboxed 'virtualization' design of Whonix. Due to its amnesic design and general default torification, Tails is definitely safer than any other host OS for occasionally 'seeing' your files, but for regular paranoid online consumption you need Whonix.

Other benefits of Whonix

- Because your IP can't leak inside Whonix-Workstation-XFCE, Whonix opens up a whole world of services, functionalities and possibilities normally not possible or safe to do with just the Tor Browser Bundle (TBB) in your host OS. In Whonix's Tor Browser, you can more safely use JavaScript and all browser web page functionality to give you the full normal web experience on sites like imgsrc.ru, omegle.com, chatroulette.com, youtube.com and any of your regular image and file hosts. If a site blocks Tor exit nodes, no problem, just use Opera browser's built-in VPN inside Whonix or other free VPNs easy to setup and use as instructed in this guide. Most significantly, you can use any non-browser Internet-related program outside Tor Browser with Tor anonymity, such as JDownloader, File & Image Uploader, or the Linux MEGASync app to back up your files to an anonymous MEGA account.

- You can safely set Whonix's Tor Browser to remember history and passwords and cookies, because in the password-protected environment of Whonix no one can get to this data but you, or at least it's anonymous. If your computer crashes, your Tor Browser session is recoverable again, and browser sessions won't be lost like with the standalone TBB or Tails.

Using Whonix on Tails is a new gold standard in law enforcement-resistant computing. However, we must remain vigilant. Whonix's VM design is not immune to zero-day exploits. There is always the possibility of vulnerabilities existing in the VirtualBox software whereby malware inside your Whonix VM could 'escape' the VM wall and gain your real IP address. Theoretically, this is possible but extremely unlikely. Various factors help to reduce the likelihood of this risk, including: the fact that VirtualBox is open-source; the fact that VirtualBox has a large user community constantly looking at and contributing to its code; and the fact that it is likely very difficult and resource-intensive for LEA to find such a devastatingly powerful exploit in general.

This guide is intended for general community protection. As a whole group of people we are generally below the threshold that justifies powerful exploits being used like the isolated 2020 Facebook Tails example. Targeted exploits are generally reserved for terrorists of high interest to national security, or people of high enough interest to private entities who are motivated to pay for such very expensive hacking. By following this guide's instructions, as a general member of the community you can rise above the threat risk threshold, and stay safe about as much as you can possibly be.

 



 

How to Use this Guide


This guide is tailored to the needs and use case of paranoid users. It is very long and informational. To get started, you only need to use the sections "Intro" and "Setup" until the first part of "Post-Install Steps". After that, everything else is optional.

The Guide is a useful reference for advanced users, but it is also intended to be used by beginners. Some instructions could be slightly under-explained for your level of computer knowledge. This is so that the Guide is easier to read as a reference.

If you are a Linux beginner and do not know how to use Terminal, please read How to Use the Terminal before you do anything else.

Navigation

- By default, this guide is navigated via the top menu which brings up each section one at a time.

- To view the whole guide as one long page, use the toggle button in the very top right-hand corner. This mode makes it easy to scroll from one section onto the next without as much clicking, or to instantly search any word contained in the entire document.

- When you click on any internal link to a section of the guide, it will open a new tab in single section mode. You can use the original tab to continue in scrollable mode to not lose your place in the guide.

Formatting and color map

Italics: The name or URL of a program or web service.

Bold: A named item you have to select or look for on the screen, when instructed in a guide.

White background: Text you have to enter into a GUI text box when instructed in a guide.

Black background: Terminal commands. Don't panic! You won't die. It's all OK. Just...BREATHE...

Tip: Something cool or handy to know during an instruction or mini-guide.


Note: Something important to know or be assisted with when following a mini-guide.


Warning: Something serious about security, privacy, anonymity, data loss, or other possible catastrophes. DO NOT IGNORE.


Enjoy!

 



 

SETUP


Setup Instructions


Note: You may need a few USB drives of at least 4 GB each in size. Possibly at least two of them: one to be your new Tails USB, and one to be either a DBAN HDD wiping boot disk, or your SSD manufacturer's bootable disk utility.


Note: Depending on your current computer environment, you may also need an extra 1-2 large hard drives - whether internal or external - to place your new files in and fully make the transition to HiddenVM.


Note: This setup section involves turning off your current operating system and then booting into Tails to set up your new Whonix situation.

You can follow this setup section while creating your new "Hidden Whonix" by choosing from one of the 3 following methods:

- Use this computer to follow the guide while setting up "Hidden Whonix" on a second computer.

- If you only have one computer, you can put this .html file into your new hidden VeraCrypt volume as soon as you create it. Then when you boot into Tails, unlock your VC volume and open this file in Tails' Tor Browser. You'll need to temporarily copy the .html file into the ~/Tor Browser folder. Find it as the Tor Browser shortcut in Files app side pane.

- Less safe, but possible: Print the Guide onto physical paper. (To print out the whole Guide including SSD wiping instructions, click here to view the whole one-page version of this document. Select all and copy, then paste everything into a blank text or word processing file, then print. Remove some areas if you don't need the whole thing.) After use, burn it with a flame immediately for your own safety.


Warning: If you print this document onto paper, be careful of modern printers which can save to their memory all documents sent to the printer. Research your printer model and reset its firmware after printing this sensitive document if necessary.


Create a Hidden VeraCrypt Volume

VeraCrypt - the successor to the now-discontinued TrueCrypt - is the foundational software for our safety in this entire Guide. It is possible to do things incorrectly, so carefully follow the directions and recommendations of the steps below.

Due to key disclosure laws now common worldwide, LEA can legally force you to decrypt your hard drive upon seizure or forced inspection. Regular forms of encryption such as LUKS (Linux), FileVault (macOS), or BitLocker (Windows) are useless, because they provide no option to hide the fact the encryption exists.

VeraCrypt provides a solution to this problem with its Hidden VeraCrypt volume feature. It is a reliable implementation of cryptographic 'plausible deniability', which means that if your hard drive is seized by LEA, they cannot prove through simply looking at the unlocked disk that there is encrypted data on the disk or that it is meaningful data at all.

A VeraCrypt 'volume' is a large amount of encrypted data that the program will write on the storage media you choose. It makes you create a password that can unlock the volume to then mount it as a 'virtual drive' that works in the same as any external drive you might attach to the computer. You can put all your sensitive files into that hidden virtual drive.

The 'hidden' volume design works by creating an outer 'decoy' volume with its own decoy password that you will set, which is what you can give to LEA to satisfy their key disclosure laws. Inside this outer volume, you can put some harmless non-illegal files, or nothing at all. In most legal jurisdictions, simply creating the 'hidden' volume will keep you safe, from a hard drive analysis point of view. Other factors such as human suspicion on a social level may require more elaborate decoys and explanations for your hard drive's outer appearance to be set up - e.g. many embarrassing but legal files in the outer volume, or a decoy OS with software indicating another explanation for your hidden volume's external appearance. Such matters are out of scope of this guide.

After creating the 'outer' volume in the creation wizard, VeraCrypt will create the 'hidden volume' inside the outer one. You should set a good, long, unique password (of at least 24 characters to unlock the separate and secret 'hidden' area of the volume, which is what you will use to store your HiddenVM installation, your Whonix VMs, and your files.

Warning: The secrecy and privacy of the password you use to unlock your hidden VeraCrypt volume is extremely important and has serious implications for your safety. Never, EVER re-use your VC password in any situation apart from your local situation of unlocking your volume in a safe environment like Tails. Do NOT use it or any password in the same style as it for online accounts, VC volumes unlocked inside Whonix (due to malware JS on sites potentially spying on your keystrokes in Whonix), or anywhere at risk of having software listen in on your password. This password is your most private secret of all.




To safely create your hidden VeraCrypt volume:

Note: Here is how to navigate the Guide, depending on your situation:

- If you are coming from Windows or macOS, and want to securely backup your existing files (including an existing Whonix), you will need to have an extra hard drive to perform this section's instructions on. This extra drive is to be a 'backup' drive, and NOT the main new drive you intend to use your daily HiddenVM installation on. Buy a second extra hard drive if you only have one.

- If you are coming from Windows or macOS, but have no files you want to backup, you do not need to create a VC volume until you have reached the Install HiddenVM section. Don't follow the below instructions until you are in Tails and are instructed to come back here. You will only need one extra hard drive in this case.

- If you are coming from a regular Linux OS, you only need one extra hard drive if it can comfortably fit all your current files plus about 50 GB extra. If you want to securely backup your existing files (including an existing Whonix), continue immediately with the instructions in this section. If there is nothing to bring to your HiddenVM, go to the next section and return here when instructed to during the Install HiddenVM section.


- Download, install and open VeraCrypt in your current operating system.

- Click on Create Volume.

- Choose the partition/drive option (non-system partition/drive option in Windows version).

- Choose Hidden VeraCrypt volume. (Then Normal mode in Windows version.)

- Continue through the wizard, and read below for important choices to make.

- How you create your volume is very important for safety. To be easy to use with HiddenVM and to meet its new standard of forensic deniability, as of v3.0 of this Guide you must create your volume as either a whole disk or whole partition - not as a large file in your current operating system's file system. This means the volume will take up an entire hard drive or a partition on that drive. This could be an internal hard drive in your computer or an external USB. Both options work very well.

Warning: It may be safe to have a regular operating system on the same hard disk as your "Hidden Whonix", if you split it into multiple partitions and make one of those partitions your VC volume. However, it is more risky, especially if you don't encrypt your regular operating system and its file system is readable by Tails every time you use Whonix. The safer and easier solution is to make one entire disk your single VeraCrypt volume. Even in that case, make sure your regular operating system isn't unencrypted or physically readable when booting into Tails. It is safest to use a different computer entirely for your files.


Note: We recommend you to create your hidden VeraCrypt volume in a drive or partition of at least 110 GB in size, or you will run into problems later. Whonix is designed to automatically expand its VM files to 100 GB per VM, depending on whether you fill up the file system inside them. If you create a hidden VeraCrypt volume of only 50 GB and then expand your Workstation beyond 50 GB, it will run out of space in the VeraCrypt container, crash your Whonix VM, and possibly corrupt all the data inside it irreversibly. To be safe, make your VC volume at least 110 GB in size, regularly backup of your files, and regularly keep an eye on how much space your VMs are expanding to.


Note: To create VC volumes larger than 2TB in size (e.g. a 4 TB external disk), you will need to use a drive that presents itself with a 4096-byte logical sector size, and not just 4K physical sector size. The only reliable way to achieve this in 2020 onward is by buying a '4Kn' drive. These drives are more expensive than normal '512e' drives, but they may be more reliable for long-term use. The more common '512e' type of drive has a 4K physical sector size, but it presents itself to the computer with a 512K logical sector size and this is set at the firmware level which usually cannot be changed. In years past, there were certain devices to make >2 TB non-'4Kn' drives work with VeraCrypt, but those solutions no longer exist.


- Right after the Hidden Volume Password stage of the wizard, it takes you to Large Files. Make sure to choose I will store files larger than 4 GB on the volume, or you might accidentally choose a file system that can't contain the Whonix VMs.

- Finally, you must choose the correct Filesystem type for your hidden volume. If you're coming from a Linux OS, choose Linux Ext4. If you're on Windows or macOS, you must choose exFAT.

Tip: If you are extra paranoid or higher in the paranoid sector, you can choose something more heavy duty during VeraCrypt's Encryption Options than the default AES option. Some people think AES is now crackable by NSA, but only you can decide what you believe. Either choose AES(Twofish) as a double encryption option, or even the triple AES(Twofish(Serpent)) for full-scale paranoia. Depending on how good your CPU, SSD and other components are, these extra layers may come at a huge performance cost inside Whonix, affecting the smoothness of video playback or slowing down the speed of creating and extracting archives and file processing like re-encoding videos. You can measure the performance difference on your hardware by using VeraCrypt's Benchmark feature under Tools or during the same wizard step, but real-world testing may be different.


Warning: After you have created your hidden VeraCrypt volume, it is best NEVER to mount your outer volume ever again when you're using your computer. Using the outer volume can overwrite and permanently corrupt your inner hidden volume, even when just reading it without writing files. However, DO remember what your decoy password is - it is what will prevent your jail sentence if LEA seize your hardware. Write it down somewhere so you don't forget, which is safe to do since it will reveal nothing sensitive. If you want to mount the outer volume at any time, only mount it while using the Protect hidden volume when mounting outer volume or Mount volume as read-only feature in the Mount window's Options > button. The time to put in decoy files in the outer volume is during the creation wizard, and never after the wizard completes.


Thank you to Massive for getting rid of the bullshit.

 



 

Securely Backup Any Existing Files

If you have existing files you want to keep before moving to "Hidden Whonix", now is the time to move all files into your newly created VC volume using the instructions from the previous section.

If coming from Windows or macOS, move your files to the exFAT VC volume on your currently designated 'backup' hard drive.

Right after doing this, you will be able to access these files on both your current OS and your upcoming Tails OS.

Tip: Make sure your new volume is big enough to hold Whonix in addition to your existing files. For some tips on disk space management, click here.


 



 

Securely Wipe Any Existing Unencrypted Files

Tip for those using Mac hardware: At this point in the Guide it's a good idea to create a macOS USB installer before you wipe your Mac's SSD. A macOS installer disk may be needed to perform low-level tasks on your Mac like setting or changing the firmware password or doing an NVRAM / PRAM reset. It may also be needed to update the firmware of your Mac's hardware so that it works better with Linux. To do this you may need to fully install macOS onto a drive temporarily connected to the computer such as internal SSD or external USB, and then upgrade macOS within that system. See more here.


Before you install "Hidden Whonix", you should securely wipe any files that was not formerly stored inside a hidden VeraCrypt volume. Incriminating forensic data that LEA can find includes file passwords copied to your old operating system's clipboard.

Even if you have deleted the files in a normal way, LEA could use advanced restoration techniques to retrieve the data. It is especially important to wipe your disk if it is not going to be converted to a whole-disk hidden VeraCrypt volume.

To be safe, either physically destroy such a disk (e.g. take it apart and melt its components with flame), or follow the software steps in the hard drive wiping guide linked below, which contains the most comprehensive instructions for non-physical wiping possible:

How to Securely Wipe Your SSD / HDD

 



 

Install Tails

Tip: If you only have one computer, now is when you should copy this .html file into your hidden VeraCrypt volume. Once you boot into Tails, unlock your VC volume and open this file in Tails' Tor Browser to continue through this section. In Tails you will need to copy the .html file into the ~/Tor Browser folder. Find it as the Tor Browser shortcut in Files app side pane.


Now that your existing files are securely wiped and/or backed up, it is time to install Tails. Tails is the environment in which you will use "Hidden Whonix". You will find it different, but quite pleasant, stable, and easy to use.

Installing Tails takes some time but is fairly simple to do. Have 1-2 USB drives ready and go to the Tails website to follow their instructions for creating a Tails USB.

Boot into Tails to test it works on your hardware, and if applicable, continue following this Guide on Tails.

Tip: When booting into Tails, if you get stuck at a screen like Invalid Partition Table, just keep pressing Enter.


Note: Every time you boot into Tails you must choose an Administration Password via the Tails login screen. This is to be able to use HiddenVM, or perform certain Tails instructions in parts of the guide. It is only a temporary password for each Tails session, can change every time, and does not need to be a complex password if there is no imminent risk of physical seizure.


Warning: It is not recommended to have JavaScript enabled in the outer Tails Tor Browser. To read this guide more safely in Tails, set Tor Browser's SECURITY LEVEL to Safest, then open this .html file.


Warning: Unlike Whonix, Tails can access your real IP address. Malware via JavaScript, downloaded files, zero-day exploits, or security design defects have been known to leak your real IP address. If you have unlocked files in a Tails session, do not do web browsing or use any application in the outer Tails environment unless it is absolutely necessary. You can also reduce risk by using "Hidden Whonix" completely offline, which prevents any temporary IP-leaking malware from 'phoning home' even if it is running in Tails. Most Tails malware will only survive one session due to Tails' powerful amnesic design. More dangerous malware may trick you into entering your Tails admin password, so that it can inject permanent malware files into the Tails USB. Be very skeptical of entering your Tails admin password after you log in. Overall, these risks are very rare, but possible.


 



 

Install HiddenVM

Tip: Before you install HiddenVM, it is a good idea to make a second Tails USB. Due to the complexity of running a VM on Tails, on extremely rare occasions Tails can lock up, and needs to be forcibly powered off. This can corrupt your Tails USB stick and make it become non-bootable. To get back into your HiddenVM with more privacy, keep a backup Tails stick to re-create your main Tails USB once more. To make a backup Tails, follow Tails' very quick process for cloning one Tails to another.


Each time you start Tails, access your VC volume with Unlock VeraCrypt Volumes app. (Search for ver after pressing Win.) It can unlock much faster than the official VeraCrypt app because it has extra open-source code to better use AES acceleration.

Note: If you came from a Windows or macOS environment and you only have a VeraCrypt volume using exFAT or another non-Linux file system, now is the time to create an ext4 VeraCrypt volume on a different disk that you intend to be your main HiddenVM hard drive.

If you are coming from Linux and have not yet created an ext4 hidden VeraCrypt volume, now is the time to do this. If you already have one due to bringing over some existing files including an existing backed up Whonix, simply mount your existing volume and select it as your HiddenVM installation location below.

To create a VC volume in Tails, refer to the backup instructions.


Once you have an ext4 hidden VeraCrypt volume mounted in Tails, it is time to install HiddenVM.

Installing HiddenVM is very easy. Go to the HiddenVM Github and follow the instructions.

The first time HiddenVM runs, it will ask you where to put your persistent HiddenVM installation. Choose your ext4 hidden VeraCrypt volume as the location.

When HiddenVM finishes installing, and also at the end of each HiddenVM launch, it automatically opens the latest version of VirtualBox so that you can start using VMs like Whonix.

Any VMs that you will add to this VirtualBox, including their settings and any other VirtualBox settings will be stored persistently in this VirtualBox program. It is all stored within your hidden VeraCrypt volume.

Each time you launch the HiddenVM AppImage in Tails, your VMs appear exactly like how you left them. You are now ready to use Whonix in HiddenVM.

Tip: HiddenVM allows you to persistently customize your Tails experience via its Extras and Dotfiles feature. You can have it install your own third-party programs each time it launches, and customize any setting in Tails GNOME that you can think of.


Tip: HiddenVM brings such a high level of safety that it is now safe to consider using another guest OS securely torified by a Gateway as an alternative to Whonix Workstation. It might be safe to do capping in Windows if you knew what you were doing.


 



 

Install Whonix

Tip: If you already have a Whonix VM that you have set up, you don't need to follow all steps in this section. Refer to the handy Mini Migration Guide to Move an Existing Whonix Into HiddenVM, so that you don't have to start all over again.


Whonix installation in HiddenVM is simpler than the official instructions provided by the Whonix project.

Follow these steps in Tails:

Step 1: Download Whonix

Go to the Whonix download page and under section 1. Download Whonix Xfce for Windows, macOS and Linux, download the OVA file via the Download button.

Note: There is no need to install VirtualBox in Tails. It is already installed if you have launched HiddenVM.


Step 2: Import Whonix into VirtualBox

- Using Tails Files app, move the Whonix OVA file into the HiddenVM installation folder in your hidden VeraCrypt volume.

- In VirtualBox, select File > Import Appliance... and navigate to the HiddenVM folder. Select and open the OVA file. For further screenshots to help guide you with the importing wizard, see section 3. of the Whonix download page.

Note: If there is an error saying Failed to import appliance, close off VirtualBox. Open VirtualBox again (find it by pressing the Win key in Tails and searching typing in virt), and importing will work the second time.


Tip: Keep a copy of the OVA Whonix file in case you need to start again or you ruined your current Whonix for some reason.


Tip: For the 100% paranoid, you can turn off VM 'Preview' in VirtualBox, to further prevent leakage of Whonix imagery to possible malware present in Tails. The risk is almost zero. Before you turn Whonix VM on, do the following: Single-click on any single VM in VirtualBox, right-click anywhere inside the main pane on the right-hand area of the program (underneath New, Settings, Discard, Start), and make sure the Preview menu item is unticked.



 



 

"Hidden Whonix" Is Ready to Use

Tip: If you are comfortable enough with terminal, you can put the Gateway VM in CLI mode to free up over 1 GB of memory for Workstation VM. In Tails, memory is a precious resource.

Gateway only provides Internet for Workstation. Just a few basic commands are needed to maintain it. After you power on Gateway, you don't need to log into its terminal window for its Tor process to connect in the background. If you want to log in, the username is user and password changeme.

You will still have to periodically apply updates or check Gateway's Tor status when troubleshooting. The most common commands are: whonixcheck (then you read its output), sudo apt update && sudo apt full-upgrade if whonixcheck instructs you to, and if the Tor connection is not working just close off Gateway by doing sudo poweroff then start the VM again, no need to turn off Whonix-Workstation-XFCE during this process.

To set Gateway to CLI mode, in VirtualBox right-click on the Whonix-Gateway-XFCE VM and select Settings... and go to System. Change the Base memory down to 256 MB, then click OK.

However, do note that in order to perform system upgrades inside Gateway, you will need to temporarily assign the VM its default 1280 MB of RAM each time you do those updates.

You can also experiment with lowering the video memory to 16 MB.


Before you even turn on Whonix, go through the next section to optimize the VM experience.

Once you are ready, you can turn on Whonix-Gateway-XFCE and Whonix-Workstation-XFCE by double-clicking each one in VirtualBox and letting them load up at the same time. Follow the two Whonix first-run wizards that show up and choose all defaults. As you will briefly need to use the Terminal to apply system updates in both VMs, refer to the How to Use the Terminal section if you need help.

 



 

Recommended Settings to Optimize Your VM


Note: Power down Whonix-Workstation-XFCE before performing the steps under this entire 'Optimize Your VM' section.


Warning: Unless you know what you are doing, do not change any VM settings for your Whonix VMs apart from what's instructed in this guide. It could change settings in ways that completely deanonymize you.


Hardware Virtualization

To ensure good VM performance on your hardware, make sure hardware virtualization is enabled in your BIOS, UEFI, or Mac Firmware. For Macs, it is enabled by default and re-enabled by doing an NVRAM / PRAM reset. For PCs, it depends on your manufacturer so there is no one-size-fits-all instruction. Research online, or explore your BIOS / UEFI.

Note: For Mac hardware, if you have a firmware password turned on you must temporarily turn it off in order to reset the NVRAM.


 



 

Performance Optimizations

Right-click on Whonix-Workstation-XFCE in VirtualBox and select Settings... for the below steps:

- System > Motherboard > Base memory: Assign as much as you can from your computer's available memory. Leave enough for Gateway VM and leave at least 2 GB for Tails itself. This allocation is used for both normal RAM and video RAM in Whonix.

- System > Processor: Here you can choose how many CPU cores Whonix can access when doing CPU-intensive tasks. Set to the maximum level for optimum performance, especially if you will be doing multi-thread tasks in Whonix like compressing archives or encoding videos.

Tip: Ignore any warning messages if you set it past the orange levels. For top performance, set to full orange maxed out.


Increase video memory

Increase video memory from the default 128 MB to 256 (the maximum possible). In Tails host Terminal do: sudo -u clearnet vboxmanage modifyvm "Whonix-Workstation-XFCE" --vram 256 then confirm that it changed in the VirtualBox window.

Speed up VM boot time

You can reduce the VirtualBox logo splash screen to almost non-existent in any VM by doing after the following example in Tails Terminal:

sudo -u clearnet vboxmanage modifyvm "Whonix-Gateway-XFCE" --bioslogodisplaytime 1

Repeat or modify for any VMs in VirtualBox such as "Whonix-Workstation-XFCE".

Then, inside both Whonix VMs you can remove the 5-second blue-colored screen that shows Debian's alternative bootup options. In both VMs, in Terminal do: sudo sed -i 's+OUT=5+OUT=0+g' /etc/default/grub && sudo update-grub

 



 

Security Optimizations

There are no longer any default recommended security optimizations for "Hidden Whonix", because the amnesic environment of Tails since v3.0 of the Guide makes the default Whonix VM settings extremely safe and low-risk. However, for more paranoid users, some optimizations are recommended.

Right-click on both Whonix-Gateway-XFCE and Whonix-Workstation-XFCE in VirtualBox and select Settings... for the below steps:

Disable audio in Whonix-Workstation-XFCE

- Audio > Untick Enable Audio.

Disabling audio in all VMs is especially recommended if you have not physically disconnected in-built speakers in your Hidden Whonix machine. Audio Input is most important to have disabled by default, but even Audio Output could be a risk if you have in-built speakers connected physically. Websites can play inaudible surveillance beacons from inside your Whonix Tor Browser. Google on your smartphone nearby could be listening to that beacon.

Disable Shared Clipboard and Drag'n'Drop

- General > Advanced > Set both Shared Clipboard: and Drag'n'Drop: to Disabled.

Note: With Tails as the host OS and minimal use of Tails while using "Hidden Whonix", shared clipboard is extremely low risk. It is only worth disabling if you are 100% paranoid, or you do regular browsing in outer Tails Tor at the same time as Whonix (which is a very bad idea).


 



 

Post-Install Steps


Your Whonix is now ready to power on. Turn on both Gateway and Workstation.

You can then move this file into your Whonix, or re-download the Guide when inside Whonix. In Whonix you can safely double-click on the .html file and let it open in Whonix's Tor Browser.

To make life easier, copy and paste any Terminal commands from here into Whonix's Terminal.


Tip: If a VM on Tails boots into a blank / black screen, try toggling full-screen on and off by pressing [Host Key]-F. It could be a temporary bug depending on your hardware.


Tip: If a VM starts to freeze up in Tails, immediately move out of the VM and into your outer Tails environment by pressing the [Host Key] and then Alt-Tab etc. Quickly do the following in Tails to force quit the VM: sudo -u clearnet gnome-system-monitor Then find the VirtualBoxVM item in the list pertaining to your frozen VM. (Hover mouse over its Process Name to see the VM name.) Click on the item and then End Process. You can now re-launch the VM from VirtualBox.

The cause of this issue may be having too little RAM in your computer or too much RAM being allocated to the VM. The inconvenience and reduction in stability due to the RAM-only environment of Tails is worth the massive security increase in leaving no forensic trace. To make your experience better, try to have as much RAM as possible.


Essential Tools You Must Install to Follow This Guide

First, in Terminal (Terminal Emulator) do: sudo apt update && sudo apt full-upgrade

(This is your first time installing updates in the Whonix OS.)

Then in Terminal do:

sudo apt install xfce4-goodies gvfs gvfs-backends gvfs-fuse eject file-roller rar unrar unar tar zip unzip unace arj p7zip p7zip-full p7zip-rar liblzma-dev libwxgtk3.0-dev bzip2 gzip pulseaudio git gdebi software-properties-common exfat-fuse exfat-utils jq netcat xterm xdotool fonts-roboto firefox-esr -y

What these packages enable: basic Xfce extended functionality; ability to mount and eject external drives in Whonix; basic function for extracting and creating password-protected archives; audio playback in Firefox; functionality to easily install various programs in the guide; support for the exFAT file system in Whonix (e.g. to mount or create an exFAT VeraCrypt volume); 'jq' (just look it up); 'nc' (needed for PlayOnLinux needed for some programs); 'xterm' (a tiny but useful third-party terminal app for a couple things in the guide); 'xdotool' (common tool for automation and keyboard shortcuts used by different apps); a better font; 'firefox-esr' which is Firefox ESR, a vanilla version of Firefox which is useful for using a VPN IP with to bypass Tor blocking inside Whonix. Overall they're packages needed for many things in this Whonix guide which just won't work if you don't follow this step.

Then in Terminal do:

sudo mv /usr/bin/gdebi-gtk{,.bak} && echo -e '#!/bin/bash\npkexec /usr/share/gdebi/gdebi-gtk "$@"' | sudo tee /usr/bin/gdebi-gtk && sudo chmod +x /usr/bin/gdebi-gtk && sudo cp /usr/share/polkit-1/actions/com.ubuntu.pkexec.gdebi-gtk.policy{,.bak} && sudo sed -i -e 's#/usr/bin/gdebi-gtk#/usr/share/gdebi/gdebi-gtk#g' -e 's#_active>auth_admin#_active>yes#g' /usr/share/polkit-1/actions/com.ubuntu.pkexec.gdebi-gtk.policy

Then in Terminal do:

sudo cp /usr/share/polkit-1/actions/org.freedesktop.UDisks2.policy{,.bak} && sudo sed -i -e 's#_active>auth_admin_keep#_active>yes#g' -e 's#_active>auth_admin#_active>yes#g' /usr/share/polkit-1/actions/org.freedesktop.UDisks2.policy

Warning: The above Terminal commands are a workaround for a longstanding bug affecting Whonix. While we wait for the bug to be fixed, this is the smoothest fix for your Whonix. Please be aware that this step turns off password authorization for the installation of .deb files in your Whonix OS and the manual GUI mounting of external drives, which brings a potential security risk, but with low a likelihood. This is not ideal, but for now it's the smoothest solution.


Note: If you do not follow all of the above steps in this section, many of the mini-guides or instructions in this entire Guide will not work. This post-install step is for making all how-to's more streamlined. Advanced users can avoid installing some of the packages if they know what they're doing.


 



 

Random Whonix Bugfixes

Prevent long shutdown

Depending on what you install in Whonix, there might be an annoying bug where Whonix can intermittently take an extra 90 seconds to shutdown the VM every time. Skype is one example in causing it, but there are several others.

To fix this bug permanently in your Whonix, you can change the max countdown to 10 seconds which will mitigate it in a way that will be stable enough.

In Terminal do: sudo sed -i 's+#DefaultTimeoutStopSec=90s+DefaultTimeoutStopSec=10s+g' /etc/systemd/system.conf && sudo systemctl daemon-reload

 



 

Improve Whonix Appearance

Fix blurry fonts

Depending on your hardware, Whonix's fonts and system text rendering may look unattractively blurry by default.

To make them clearer and crisper, open Appearance from the Whisker Menu > go to Fonts tab:
  • Try setting the Default Font to Roboto (Regular).

    Try setting Hinting: to Full.

    Try changing the Sub-pixel order setting.
Make Whisker Menu look nicer

Right click on the Whisker Menu icon in bottom left-hand corner. Select Properties. Down the bottom, change Background Opacity to something lower like 85%. Click Close.

Tip: There are further improvements you can make to Xfce in 'Further Tips, Tweaks, and How-To's' section, such as Make the Taskbar Better.


Note: A newer version of Xfce version (4.14) has now been released and it will finally bring proper display of fonts on HiDPI displays to make it as crisp as your Tails would look. But until Whonix 16, Xfce 4.14 probably won't be available.


Thank you to Massive for contributing appearance tweaks!

 



 

Turn off Private Browsing Mode

In the safe environment of Whonix, you can reasonably turn off private browsing mode in Tor Browser to turn it into 'normal' mode so it saves your browsing history, bookmarks and more for handy re-use each session.

Go to Preferences > Privacy & Security, scroll down and untick Always use private browsing mode then restart the browser.

You can then go to Preferences and tick Restore previous session under Startup.

You can also go to Preferences > Privacy & Security and tick Ask to save logins and passwords for websites.

Now you can save your sites with their unique and long passwords without compromising your security, making it both safer and easier for you to navigate the online community.

 



 

Disable JavaScript on Specific Sites

Even though it is generally very safe to browse the Internet in Whonix with JavaScript fully enabled, due to the targeted status of sites and our knowledge that LEA have secretly seized them in the past and planted malware in JavaScript to deanonymize users, it's still recommended to disable JavaScript for your sites, even in Whonix.

It's very unlikely for LEA malware to be Linux malware, and to therefore affect Whonix users. Even if it is, it's unlikely for it to be able to penetrate the powerful virtualization wall between the torified Whonix VM and your non-Tor IP address outside it.

But inside Whonix, JavaScript-planted malware can still spy on and deanonymize you in other ways, such as a Linux keylogger that can reveal secret passwords or other information normally private to your Whonix. Such leaked data could deanonymize you.

Instructions:

While browsing a site, click on the uBlock Origin button, then the More ﹀ button, then the blocking button in the top right-hand corner, to permanently block JS on any webpages on that domain.

Refresh the page and on some helpful sites you will no longer see a JS warning due to having turned on.


Warning: If you are particularly concerned about browser fingerprinting, you need to do things very differently in your Whonix Tor Browser. You should disable JavaScript entirely in your Tor Browser by setting its SECURITY LEVEL to Safest. Visit http://panopticlick.eff.org to test your fingerprinting uniqueness if that is a metric that matters for your particular needs. Do consider that on a deeper level, completely disabling JavaScript can make you unique in a different way. It depends who you are trying to be more anonymous from. Sometimes you have to choose, or not do any Internet browsing at all. To most sharers, due to Whonix's robust anti IP leakage design, fingerprinting shouldn't be a concern. You might be 100% unique as a person being tracked by LEA, but you're still an anonymous unique person because your real IP is extremely hard to unmask.


 



 

Enable Win Key Shortcuts of Any Type

To enable the Whisker Menu to be invoked by the Win key and yet also use Win as a modifier for other system hotkeys, you must do the following:
  • 1. Download the latest ksuperkey .deb file from its repository such as this latest one.

    2. Open the file and click on Install Package, using password changeme when asked, and finally click close, then it's ready to use.

    3. Next, to turn on ksuperkey and also add it to Whonix startup, do the following command in Terminal:
    ksuperkey && echo -e "[Desktop Entry]\nName=ksuperkey\nExec=ksuperkey\nType=Application\nMimeType=text/plain;\n" | sudo tee /etc/xdg/autostart/ksuperkey.desktop
    4. Next, you can configure the Whisker Menu to be toggled by the single Win key. Open Keyboard from the Whisker Menu. In Application shortcuts tab, first remove the existing item called xfce4-popup-applicationsmenu, then add a new item with command xfce4-popup-whiskermenu and assigning it Alt-F1.

    5. Now the Win key will toggle the Whisker Menu. You can now also configure other hotkeys in your Whonix to use Win. For system shortcuts open Window Manager from the Whisker Menu then Keyboard tab. For application shortcuts open Keyboard from the Whisker Menu then Application Shortcuts tab. Find examples in these five successive mini-guides.
 



 

Add Desktop Icons

Once you have a program installed (some of which are already there like Tor Browser), in the Whisker Menu you can right-click on any item and Add to Desktop for your convenience.

 



 

Add Support for Other Languages in Whonix

Some videos you might download are named in other languages using non-Latin characters. Chinese, Japanese and Russian work fine in the current Whonix Xfce, but others like Korean, Thai, and Hindi need extra packages to make them display properly.

To add support for languages like those ones above, in Terminal do: sudo apt install fonts-unfonts-core fonts-ipafont-mincho fonts-arphic-ukai fonts-thai-tlwg fonts-indic

 



 

HOW-TO'S


How to Use the Terminal



Using Terminal is easy once you get used to how the terminal behaves. The default screen has a cursor after user@host:~$ and to use it you type a command at the cursor, press Enter, and see the results 'printed' on screen. Usually the command you enter will start and finish by itself before returning to the default prompt, ready for another command. Sometimes, it can ask for further small interactions such as the simple examples below.

If at any time you are not sure what Terminal is doing, or whether you should close it or not, just patiently wait further for it to finish its task. It might be needing some time if it's a command that uses up a lot of CPU like when re-encoding a video file, or a large file download. Some tasks do need to be manually closed off if you want to return back to the command prompt, e.g. after running OpenVPN from the command line. In most of these cases you press Ctrl-C while in the Terminal to do that. Confusing shortcut, right? Yes, long story, it does not mean 'copy'. Instead think 'C' for 'close'.

Instead of typing out a big long command, in Terminal you can paste any text into the prompt and then press Enter. After copying a command into the clipboard, you can then paste it into Terminal by pressing Ctrl-Shift-V, or right-click and select Paste. Not so bad, right?

To copy text from the command line (to paste somewhere outside of Terminal): click and drag to select the text you want to copy, then do either Ctrl-Shift-C or right-click and select Copy.

When Terminal asks for a password (e.g. with sudo commands), by default in Whonix it's changeme

Note: There's no serious security need to change Whonix's default Terminal password, but if you're paranoid about malware inside Whonix, customizing it may give you some security benefit.


- If you see Do you want to continue? [Y/n], if you are happy to proceed you type the letter y and press Enter.

- When working with files in the command line (e.g. inspecting file's metadata with the command mat2), Terminal doesn't like spaces or special characters in file names or the folder path before the filename. If you're having trouble, modify the filename, or "/you/can/put/quotations/around/the file path/like this.mp4". Another way to more easily work with a file: go to the folder in Thunar File Manager, right-click or go to File and then Open Terminal Here which opens a Terminal window with the working folder as the current one in Thunar. Now you can do commands as simple as mat2 -s filename.mp4 instead of mat2 -s "/long/cumbersome/path to/filename.mp4"

 



 

Essential Mini How-To's and Recommended Programs


Move Files into Whonix

Option 1 Move files directly from Tails

- First power down Whonix-Workstation-XFCE, then select it in the VirtualBox main window with a single click.

- Go to the VM's Settings > Shared Folders and click on the plus folder button.

- Select (and if necessary create) a folder inside your HiddenVM installation files, tick auto-mount and then click OK twice.

- Power on Whonix-Workstation-XFCE and in Whonix's Thunar File Manager the shared folder will show in the left-hand pane under Devices (or navigate to the /media file path).

- If you are 100% paranoid, when not using this feature you can power down Whonix then remove your shared folder from the VM settings.

Option 2 Move files directly from a USB.

For this, refer to the mini-guide, Use External Drives with Whonix.

Tip: After importing your original files into Whonix, you should clean them from any metadata attached to your previous OS. Firstly toggle to show hidden files to reveal compromising data files you should delete, then use the metadata stripping tool to clean your media files.


 



 

Use External Drives with Whonix

Want to transfer files into Whonix directly from a USB stick, copy some files safely onto an external disk, or expand your regular Whonix storage using external drives?

Note: Since v3.0 of the Guide, this section no longer involves installing the VirtualBox Extension Pack, which is a closed-source binary blob unlike the VirtualBox program itself. Now that we have Tails, the new method below is a much safer one. Tails is both open-source and amnesic. That makes it very low-risk for Tails to directly 'see' your files.

However, inside your VC volumes it would still be safer to store your files in Virtual Hard Disk VDI files which you can attach to your Whonix VM. This would ensure that even Tails cannot easily see your files. To do this, combine the instructions below with the VDI method instructed in the expanding storage section.


Temporarily connect an external drive to your Whonix

- Connect your external drive to the computer and unlock its VC volume with Tails Unlock VeraCrypt Volumes app.

Note: In order for this to work, your external VC volumes must have an ext4 (or other ext*) file system. If it is another type like exFAT, you must use backup media to move it to another drive and then re-create your VC volume in Tails as ext4. To do this, refer to the backup instructions.


- Navigate to the mounted volume in Tails Files app, then go one level higher (Alt-⬆).

- You must make a shortcut to your drive's folder and place it in your HiddenVM installation folder:
    - First create the shortcut. Either Ctrl-Shift-drag the folder to any white space below it. Or, go to Files preferences (via the three-lined hamburger menu near top right-hand corner of the app, or via Files drop-down menu on top menu bar) > Behavior > Tick Show action to create symbolic links and close, then right-click on your drive's folder and select Create Link.

    - Then cut and paste the link into your main VC volume's HiddenVM installation folder.
- Now add the shortcut to your VM as a shared folder, using these instructions.

- Restart or power on your Whonix VM, and the external drive will show up as an editable shared folder in Thunar File Manager.

Permanently use an external drive in your Whonix (plug and play capable)

Once you set it up with the instructions below, permanently using an external VeraCrypt drive in "Hidden Whonix" is very convenient and safe. No need to even reboot your VM when attaching the USB, just plug in and unlock the external volume in Tails and it will show up in Whonix.

- Connect your external drive to the computer and unlock its VC volume with Tails Unlock VeraCrypt Volumes app.

- Navigate to the mounted volume in Tails Files app, then go one level higher (Alt-⬆).

- Note down the external volume's "UUID" in a temporary text file. This is the volume's long numeric string as the folder name.

- Also note down the "UUID" of your main VC volume containing your HiddenVM installation folder. It is an adjacent folder you'll see there.

- Go to your VC volume's HiddenVM installation folder. Navigate to extras folder. Open extras.sh and add a single line in the file after the following example, with your external disk's "UUID" as the first string, and main VC volume the second one: echo -e UUID=EXTERNAL-DRIVE-VERA-CRYPT-UUID /media/amnesia/HIDDENVM-MAIN-VERA-CRYPT-UUID/HiddenVM/ExpansionDrive1 ext4 defaults 0 2 | sudo tee -a /etc/fstab

- Now add the folder ExpansionDrive1 (from the above example) to your VM as a shared folder, using these instructions.

- Close off all of VirtualBox, then re-launch the HiddenVM AppImage. Now it is ready to use.

 



 

Use VeraCrypt Inside Whonix

Warning: JavaScript malware on an LEA-seized site could spy on your Whonix keystrokes. This is another warning to NEVER type in Whonix the same password or password style that you use to unlock a VC volume that is in your 'direct' physical possession and that can be 'directly' unlocked with that password. It would be safer and 'indirect' if it were a volume within a different volume with a different password that is never typed in your Whonix. It would be safer to unlock a direct VC volume in the Tails host.


Some reasons you might want to do this:
  • - Transfer files to and from external storage in a way that hides more strongly from Tails. (Note the strong warning above.)
    - Create encrypted volume files to securely and anonymously backup your files to the cloud.

To install VeraCrypt in Whonix:
  • 1. Download the Debian 10 GUI .deb installer file from their Downloads page.

    2. Open the file with GDebi Package Installer and click on Install Package, using password changeme when asked, then finally clicking Close.

Tip: When using VeraCrypt for personal cloud storage backup, to save space or upload / download time, you can first compress your files with 7-Zip compression (no archive password needed), then put the .7z file(s) into the hidden VeraCrypt volume file.


 



 

Unblock Sites That Block Tor IPs

Want to anonymously use Google without being blocked, or sites like omegle.com that normally ban Tor IPs?

Use Opera with its built-in free VPN.

Tip: Sometimes all you have to do is select New Tor Circuit for this Site. Either find the menu item in top right-hand corner of Tor Browser, or press Ctrl-Shift-L on the page.


To install:

Tip: Opera may hijack the default browser setting in Whonix (for when you click on a hyperlink from a non-browser program). To reset it back to Tor Browser you may have to do either or both of the following:

  • 1. In Terminal do: sudo update-alternatives --install /usr/bin/x-www-browser x-www-browser /usr/bin/torbrowser 200

    2. Open Preferred Applications from the Whisker Menu and under Web Browser click on Debian Sensible Browser and re-select that item again. Click Close and it is fixed.

Note: Although you install Opera via a standalone DEB file, Opera intelligently adds its own repo to your Whonix APT so that it can update itself automatically going forward.


To use a VPN IP with non-browser programs in Whonix, or if a site blocks Opera's VPN: Use OpenVPN with VPN Gate

To install: To use:

Each time go to vpngate.net, find one from the list, and open its TCP raw IP file directly from the Tor Browser.

Wait a short time for the VPN to start working in the Terminal and it will work once it says Initialization Sequence Completed. If it doesn't reach that message, press Ctrl-C in the Terminal and try another one from the VPN Gate list.

You can verify it worked by visiting a site like whatismyipaddress.com in Firefox ESR. The VPN does not affect Tor Browser.

To stop the VPN, press Ctrl-C in its Terminal window. (Closing off its Terminal via the mouse will actually continue the VPN process in the background. To stop it, in case you accidentally do that, do: sudo killall openvpn)

 



 

File, Image and Video Downloader

Want to queue up large or multiple files, image URLs, or video links to download in the background, with pause and resume functionality across reboots or connection time-outs and with full archive and password auto-extract capability?

Use JDownloader.

To install:
You can now customize and tweak JDownloader in many powerful and useful ways.

To make the downloading experience more clean and seamless, you can go to:
To make it far easier to start downloading processed JD links, assign a shortcut like Ctrl-D. To set shortcut: Right-click anywhere in the LinkGrabber tab > select Open Menu Manager. Select Start All Downloads item and you will see a way to give it a shortcut.

To turn off advertisements in the application (which may improve privacy and safety), go to Settings > Advanced Settings and locate lines with the following keywords and do the following to their Value fields:

Tip: JDownloader saves all previously entered archive passwords for future auto-cracking and extracting, via its Password List feature in Settings. So once you build up your password list in JDownloader, downloading from frequent file uploaders becomes extremely painless. To add a list of file passwords you may already have collated elsewhere, go to JDownloader Settings > Archive Extractor, scroll down to Password List and paste them there.


Tip: Use JDownloader's File > Backup function to easily backup and restore your entire settings, passwords list, and even your unfinished download files.


Thank you to Massive for getting rid of the bullshit.

Tip: In JDownloader's interface you can check the IP address being used for a downloading file in real-time. This is useful if you are using a VPN to bypass Tor IP blocking from a download host, and want to check if JDownloader is using the VPN IP. Click on the currently-downloading file (the sub-item), and hover the mouse on the modem icon. A popup will appear which will then load the IP.


Auto-crack and extract files that JDownloader can't

Note: The below unpack script is not observed to be working at at Guide 3.0 launch. It will hopefully be fixed in a subsequent update.


On rare occasions, JDownloader can might at downloading a file from the host, or auto-extracting a downloaded file (e.g. improperly-named .001 files).

For those cases, you can set up the following script to auto-crack and extract a multiple downloaded files archives at once, using your existing JDownloader Password List as the cracking dictionary.

To install:

To use:

Go to the folder with your downloaded files in Thunar File Manager, and either right-click or go to File and then Open Terminal Here which opens a Terminal window with the working folder as the current one in Thunar.

In that Terminal do: unpack and it will automatically crack and extract all archives in that directory, assuming you have all correct passwords listed in your JDownloader Password List.

Note: unpack can take a long time, but it should work. If you have an incredibly long password list, it may take too long to be practical. Other password-cracking software may be superior.


Thank you to Massive for getting rid of the bullshit.

Alternative to JDownloader for downloading videos (with more custom options)

For YouTube videos, JDownloader is the easiest way to automatically download a combined video and audio file containing the highest quality video stream (e.g. 1080p with 128 kbit audio). But if you want more manual control, use youtube-dl (a command-line program). Like JDownloader, youtube-dl supports hundreds of video sites including YouTube.

To use:

Note: You may have to use a VPN inside Whonix for youtube-dl to work. YouTube seems to not like some Tor IP addresses.

 



 

Create and Extract Password-Protected Archives like 7-Zip / RAR

Right-click on an archive in Thunar File Manager and select Open With "Archive Manager". Archive Manager will open and prompt you for the password. You can then use the Extract button or open the files directly from inside the archive.

After the first time setting Archive Manager as the default app for a given archive format, simply double-click on that format from then on.

Alternatively, right-click on the archive in Thunar and use the Extract Here or Extract To... menu items.

To create archives, simply right-click on any selection of files and/or folders in Thunar File Manager and select Create Archive... If given the choice of what archive program to use, select Archive Manager. It then gives options for format choice, password setting, encrypting the file names, file splitting, and so on.

Note: Right now there appears to be a long delay when creating archives above a certain size using this method. Please discuss in an official support thread and perhaps we can find a reliable fix.


 



 

Image Viewing

Use XnView Multi Platform.

To install:
Its interface is very customizable and features include fullscreen, slideshow, folder view with thumbnails, convenient image pixel dimensions checking, basic image editing, and more.

To customize:

These settings are a suggestion for turning XnView MP into an excellent everyday image viewer. The options are powerful enough for you to choose exactly how you want it to behave.

Under Tools > Settings...
To apply the changes, restart XNViewMP by closing off all windows.

To use:

With the recommended settings above, images will open in full screen by default. Press Enter or double-click on an image to toggle between fullscreen, full-window, and folder thumbnail views. To instantly close off an image, simply press Esc.

With the keyboard shortcut customizations suggested above, you can zoom in and out, fit image to screen, fit to screen width/height, or zoom to 100% size very easily.

For an instant zoom and pan, single-click and hold the mouse in fullscreen or full-window mode, and drag around to pan.

For slideshow, you can set a keyboard shortcut to activate / stop slideshow. Go to Tools > Settings... > Interface > Shortcuts tab > change Browser mode dropdown box to Viewer mode then set Quick Slideshow to a key like F5.

To customize the slideshow settings (like seconds per image or how to cycle images), go to Tools > Settings... > View > Misc. tab and customize underneath Quick slideshow.

 



 

Video Playback

Use VLC. It comes pre-installed.

Tip: If you want to watch more than one video at a time, go to Tools > Preferences and untick Only use one instance when started from file manager.


 



 

Show Media File Thumbnails in Thunar File Manager
 



 

Inspect Media Files

Want to easily check the resolution or video/audio codec of a video file, or the pixel dimensions of an image? Use MediaInfo.

To install:

In Terminal do: sudo apt install mediainfo-gui then it's ready to use.

To use:

Either open MediaInfo from the Whisker Menu then open the media file you want to inspect, or right-click the file in Thunar and select Open With > Open With "MediaInfo".

Tip: To see the full media info for your file, switch from the default Easy view by going to View > Text or HTML.


 



 

Duplicate File, Image or Video Finder

Files

Use FSlint.

To install:

In Terminal do: sudo apt install fslint

Images

Use Geeqie.
To install:

In Terminal do: sudo apt install geeqie

To use:
Videos

Use Video Duplicate Finder.
To install:
To use:

In the extracted binary folder, find the file VideoDuplicateFinderLinux and open it. Program is self-explanatory.

 



 

Screenshot Tool

Use Screenshot. It comes pre-installed.

To use:

Simply open Screenshot from the Whisker Menu or try your PrintScreen key to invoke the program.

Tip: To manually assign your PrintScreen key or any other hotkey to activate the tool, open Keyboard from the Whisker Menu, go to the Application Shortcuts tab Add a new entry with command xfce4-screenshooter and click OK, and press the hotkey you'd like such as PrintScreen or Alt-P.


 



 

Basic Image Editing

Use Pinta.

To install:
Functions include Draw / Paint, Crop, Rotate, Mirror, Flip, Resize / Shrink. It feels halfway between Microsoft Paint and Adobe Photoshop.

 



 

Serious Image Editing

Use GIMP (GNU Image Manipulation Program).

To install: In Terminal do: sudo apt install gimp

 



 

Batch Convert Images (Excluding Animated GIFs)

Use XnConvert.

To install:
To use:

Open XnConvert from the Whisker Menu and add the images you want to convert in the first Input window. Then you can add Actions in the next tab (e.g. pixel size via Resize, Rotate and much more), and then in Output tab you can set things like JPEG quality (to lower file size) under Format > Settings... before finally clicking Convert to do the bulk action.

 



 

Image Folder Thumbnail / Contact Sheet Creator

Use XnView Multi Platform.

To install:
To use:

Open XnView Multi Platform from the Whisker Menu and navigate to your image folder inside the program. Select all images you want to make a contact sheet from, then in the menu go to Create > Contact sheet... and customize to make it look as nice as you want.

 



 

Screen Recording Tool

Use vokoscreen.

To install:

In Terminal do: sudo apt install vokoscreen then it's ready to use.

It's a very nice GUI app. It can export to a quality MKV, MP4, or GIF file. Options and functionalities include recording audio at same time as video, AKA 'capping'.

Tip: For serious capping (e.g. to record a Skype chat while inside Whonix), try OBS Studio or for other alternatives, take a look here.


 



 

Basic Video Editing

Use HandBrake.

Functions include rotate, crop, trim, change formats, shrink video size (e.g. convert to H.265 / HEVC format), and export video frames to images.

To install:

In Terminal do: sudo apt install handbrake then it's ready to use.

Note: After installing, HandBrake can hijack your default file association for some video file extensions. To reset those associations, open MIME Type Editor from the Whisker Menu, sort by Default Application column and scroll down to the list of HandBrake items and for each item single-click on HandBrake to pull up a menu to select your preferred media player instead.


 



 

Join or Merge Multiple Videos into One File (e.g. Compilation)

The easiest way (to convert files of any video format into one single H.264 file) is actually a command line method.

To install:

In Terminal do: sudo apt install ffmpeg melt

To use:

Do after this example: melt one.avi two.mov three.mpeg four.mp4 five.wmv six.mkv seven.ram eight.webm -consumer avformat:output.mp4 acodec=libmp3lame vcodec=libx264

If anyone knows a more beginner-friendly GUI method for merging videos, please share in an official support thread.

 



 

Add Subtitles or Audio Tracks to Video Without Reencoding

Use MKVToolNix, which will enable you to combine files like MP4, SRT and audio with no quality loss due to no reencoding of the video like if you use HandBrake.

To install:
To use:

Drag or add your video / audio / subtitle files into Input files: window, make any desired adjustments, then click Start muxing and a clean single MKV file will be generated for you.

 



 

Serious Video Editing

Use Kdenlive.

Uses include adding pixelation or censors to cover faces.

To install:

In Terminal do: sudo apt install kdenlive

 



 

Create Animated GIF from Video

To install:

In Terminal do: sudo apt install handbrake ffmpeg

To use:
If someone discovers a good GUI method to convert video to animated GIF (which is better than Gifcurry which was checked on 2019-09-30 and was deemed not good enough), please share.

 



 

Shrink Animated GIFs

Use gifsicle (a command-line program).

To install:
To use:

Tip: Reducing size of animated GIFs is quite an art. See this guide for the various ways you can do it. This single-step command can only go so far.


 



 

Create 3D Art

Use Blender.

To install:
 



 

Video Thumbnail / Contact Sheet Creator

Use SMPlayer.

To install:

In Terminal do: sudo apt install smplayer mplayer

To use:

Open SMPlayer from the Whisker Menu and go to Video > Thumbnail Generator....

Note: Depending on your hardware, to get this working you may need to go to Options > Preferences > General and set Multimedia engine: to mplayer (/usr/bin/mplayer), and also possibly in the Video tab, change Output driver: to x11 (slow).


Tip: To do bulk video file thumbnail creation, try Video Contact Sheet *NIX (vcs). Install via either their provided repo or this DEB. For help and usage examples, see their website or ask in a site's Tech forum.


 



 

Image, Video and Document Metadata Stripping Tool

Use mat2 (a command-line program). This can remove metadata from files like image, video, DOCX, and PDF.

To install:
To use:

In Terminal do after this example: mat2 dirty.mp4. It will create a 'cleaned' duplicate of the file ready to use. To verify the dirtiness of any file, do after this example: mat2 -s file.pdf

Note: To further clean and sanitize PDFs, also try qpdf, pdfparanoia, and pdf-redact-tools. But be advised that the PDF format is complicated and provides a minefield of murky ways that someone can insert data to somehow watermark or deanonymize you. If your situation is serious, keep all documents that you share in plain text (TXT) format only.


Tip: To clean an entire folder of files at once (including its subfolders), open Terminal in the folder (right-click in Thunar then Open Terminal Here) and do: mat2 * Then, to remove all dirty files at once, do: find -type f -not -name '*cleaned*' -not -name '*.gif' -delete


 



 

File and Image Uploader

Want to upload multiple large files (to dl.free.fr) or hundreds of images (to directupload.net) all at once, saving you time and effort as an uploader?

Use FIU (File & Image Uploader).
To install:

Tip: When uploading, make sure to untick use account in the Add file(-s) dialog, or the upload may not work.


Tip: Simply click on a finished download in the queue list or press Ctrl-C while selected and its URL is instantly copied to the clipboard. Select multiple ones and do Ctrl-C to copy the list of all download URL at once.


Tip: If you use FIU a lot, be aware that it updates quite regularly similar to JDownloader's own auto-updates which add support for new hosts or apply fixes for handling them. With FIU you have to manually perform the update and you can do it from within the app at Help > Update. It will either allow you to update to a new version if available, or indicate that it's already the latest by saying This is up-to-date version .... You can check when the last update was issued by going to z-o-o-m.eu and compare it with your current version by going to Help > History and seeing the version number at the top of that changelog.


Tip: For more privacy and anonymity, go to Tools > Settings > Misc > Privacy, untick both checkboxes and click OK.


Note: when you minimize FIU it minimizes to the system tray instead of the taskbar. Click on its logo icon to restore the window again. To turn this behavior off permanently, go to Tools and untick Show tray icon.


 



 

Backup Files to the Cloud (e.g. MEGA)

After finally putting your files inside your secure hidden VeraCrypt volume, you might want to back them up to the cloud as a way to not lose them in case of data loss.

MEGA is a great service to use, because they have 50 GB free online storage, a seamless Linux GUI file sync / upload program, and a very strong general attitude of 'fuck you' to LEA. They also claim to use 'advanced end-to-end encryption' whereby only your account password or a locally generated download URL for a file on your account (which is unknown to MEGA by default) can possibly decrypt it on the server. This may make these files very reliable if you never share the link online, but it's probably a good idea to upload your files in a hidden VeraCrypt volume file.

To install:
To use:

Program is self-explanatory. As the default, simply put your file(s) in ~/MEGAsync/ and it will upload to the account.

There is now an official File Manager Integration package as another way of adding files to your Mega account via Thunar.

 



 

Search and Find Files Anywhere Inside Whonix

Use Recoll.

To install:
Open Recoll from the Whisker Menu and initialize its indexing of your Whonix file system, following the wizard guide to your preferences. To use the true power of Recoll in being able to exhaustively search all system or program config files in your entire Whonix (which is great for problem solving for intermediate users learning how to do things in Linux), in Indexing configuration > Top Directories remove ~ and add / (i.e. a single forward slash), under Skipped paths remove media, then in Local parameters tab remove any useful file extensions you want to search from the Ignored endings list, as well as items from Skipped names (like tmp).

Suggested settings:

Go to Preferences > GUI Configuration > Result List tab and set Number of entries in a result page to 100 and change Result list font text size to size 8. Then, turn on real-time auto-indexing of your entire Whonix file system (and to run in the background at startup) via Preferences > Indexing schedule.

Note: To be able to open parent folders of search results in Thunar or a few other file types like PDF, the default setting doesn't work in Recoll. To fix, go to Preferences > GUI configuration > User Interface > Choose editor applications and click on the top Command column title twice to sort it. Look at the items which are not set to Desktop Default. For items incompatible with Xfce such as ones containing dolphin (for opening folders) or evince (for opening PDFs), simply double-click on them in the Command column and then Apply to current selection to reset to Xfce's default choice, or change the commands to Xfce equivalents like thunar


Tip: To filter by a file extension, do ext:mp4 (e.g. do ext:mp4 cum to find any MP4 videos with 'cum' in the title or in its metadata), do filename:fuck to filter to only files with fuck just in the file name (and not elsewhere like folder name), do dir:/this/folder (recursive) or -dir:/that/folder to restrict or exclude specific folders or parent folders from the results. Find more tips by going to Help > User manual.


Tip: If Recoll doesn't work well for you, try Searchmonkey (sudo apt install searchmonkey). It needs to do a manual search of your specified parent directory every time, but it works very reliably.


 



 

Checksum / Hash Tool

Use Quickhash GUI.

To install:

 



 

Clipboard History

Use ClipIt.

To install:
To use:

Open ClipIt from the Whisker Menu and configure it as you like. ClipIt adds itself to startup applications automatically.

 



 

Text File Creating and Editing

Use Mousepad. It comes pre-installed.

To create a text file, right-click on the desktop or in a folder and select Create Document > Empty File.

 



 

Word Processor

Use LibreOffice. It's the cross-platform Linux-compatible equivalent to Microsoft Word. It can open, edit, and convert to and from DOC, DOCX, RTF, and more, including converting them to plain text or PDF.

To install:

In Terminal do: sudo apt install libreoffice

 



 

PDF Viewing

Use Foxit Reader.

To install:

Download the Linux (64-bit) installer tarball from the Foxit website, extract the archive in Thunar File Manager, then open the extracted RUN file and follow the GUI installation wizard.

Tip: To edit PDFs in Whonix, try LibreOffice Draw.


 



 

Email Client

Use Thunderbird.

To install:

In Terminal do: sudo apt install thunderbird

Compatible with any POP or IMAP email and you can install PGP encryption add-ons such as Enigmail.

 



 

Further Tips, Tweaks, and How-To's


Uninstall a Program

For any program that you've installed by doing sudo apt in Terminal, or with a DEB file using GDebi Package Installer, in Terminal do: sudo apt remove <packagename>. But be careful. Read carefully what you're about to remove before you press y. Sometimes it can ask to remove dependencies which are needed by other packages. Choose to keep dependencies if you think they might be needed by other apps or if you are not sure.

Warning: Sometimes APT can mistakenly think that a huge list of packages are no longer needed. This is a bug. As you can see in the below screenshot, it is telling you that you can remove packages including xfce4 which will actually remove Xfce from your Whonix and reduce it to command-line mode only.

NEVER perform sudo apt autoremove unless: 1. you're an advanced user and know what dependencies you're removing, and 2. you do a backup first.


 



 

Make Tor Browser / Firefox Scrolling Less Laggy

Depending on your hardware, Firefox can have an annoying mouse scrolling slowness and lag issue, and you can fix it. Go to Tor Browser Preferences and search scroll to find Use smooth scrolling and untick it. You can also experiment by searching for Performance and unticking Use recommended performance settings followed by unticking Use hardware acceleration when available.

 



 

Make the Taskbar Better

Open Panel from the Whisker Menu, then navigate to the Items tab. Double-click on the Window Buttons item, and customize as you like such as Sorting order: to None, allow drag-and-drop which makes taskbar act more like Windows with ability to re-sort taskbar items manually with the mouse. Untick Show handle to clean it up.

You can also add a lot of familiar controls and functions to Xfce's taskbar. In Panel > Items tab, simply click on the green plus button and you can add items such as in the screenshot above.

Lastly, you can remove default pinned taskbar items by right-clicking on them and selecting Remove and confirming to remove those Launcher items.

 



 

Set a Keyboard Shortcut for 'Show Desktop' (Minimize All)

Open Window Manager from the Whisker Menu and in the Keyboard tab, find the Action near the bottom called Show Desktop. Select it and click on Edit where you can set it to what you'd like, such as Win-D.

 



 

Set a Keyboard Shortcut for 'Shut Down'

VirtualBox itself offers the best solution to do this. It's Customizable via VirtualBox's Preferences > Input > Virtual Machine > ACPI Shutdown item, it's your chosen VirtualBox 'host' key + another key combination of your choice.

To speed up this method of Whonix shutdown, in Whonix open Power Manager from the Whisker Menu and set When power button is pressed: to Shutdown.

 



 

Set a Keyboard Shortcut to Toggle Thunar, Terminal, or Any Other App in Whonix

If you are a Whonix power user, this AutoKey script can make your app switching experience much faster and easier.
To make a toggle for Terminal (e.g. Win-T), in the script code simply substitute Thunar.Thunar with xfce4-terminal.Xfce4-terminal, and the lowercase thunar with xfce4-terminal. For JDownloader (e.g. Win-J), the Window class is sun-awt-X11-XFramePeer.JDownloader.

 



 

Set Keyboard Shortcuts to 'Snap' Windows to the Right / Left / Four Corners

Open Window Manager from the Whisker Menu then go to Keyboard tab and find the series of Action items called Tile window to the... and double-click on each item to set your desired hotkey for it such as Win-⬅ for to the Left.

 



 

Enable Ctrl-Tab Everywhere

To make Ctrl-Tab and Ctrl-Shift-Tab do tab switching in Thunar or other Xfce windows as you might be used to, you can achieve this using AutoKey.
This example provides exclusions for Tor Browser, Firefox ESR, Opera and JDownloader. They are different to the Xfce windows that otherwise need this script. For any other programs which conflict, simply determine their Window class using AutoKey's Window Filter feature and add them as additional elif entries in the script.

 



 

Insert Special Characters and Symbols in Whonix (Like Windows Charmap)

To install:

In Terminal do: sudo apt install kcharselect then it's ready to use.

To use:

Open KCharSelect from the Whisker Menu. GUI is self-explanatory. To easily find a symbol (e.g. ™ or © r ℗), just search its keyword like trade mark or copyright.

 



 

Further Privacy, Security, Anonymity, Social, and File Sharing Tools


I Want My Skype

To install Skype in Whonix:
Sign up for a new account using an anonymous email, and if Skype appears to be blocking Whonix's Tor IP, use the VPN trick like Opera or the other VPN method combined with Firefox ESR.

Mic or webcam functionality has not been tested for this guide. There is probably fake webcam driver software for Linux available that inputs fake video (and/or audio) of your choice, to do the job. If someone works it out, please share in an official support thread.

Tip: To uninstall Skype, in Terminal do: sudo apt remove skypeforlinux


 



 

I Want My BitTorrent

So you want to download some sort of boy movie on torrents like from blizzardkid.net? Use Transmission.

To install:

In Terminal do: sudo apt install transmission then it's ready to use.

Tip: For extra anonymity, go to Transmission > Edit> Preferences> Network and tick Pick a random port every time Transmission is started.


Tip: To have more success torrenting in Whonix, use a non-Tor IP (for both browsing torrent sites and then directly downloading in Transmission). The easiest way is to use a free VPN as instructed earlier. To verify that Transmission is using the non-tor IP address, use TorGuard's Check my Torrent IP service. Download the magnet link and the error message in Transmission will show your IP, which should be the one your VPN specifies (such as one from VPNGate).


Tip: Another option for torrenting inside Whonix may be to use a free online distributed seedbox service like bitport.io, zbigz.com, seedr.cc, transfercloud.io or filestream.me which you can sign up to with an anonymous email. Their seedboxes have have fully opened working ports and are much better placed in the Internet infrastructure for fast torrent downloading. Add a magnet link or .torrent URL on the free account, then when finished you can directly download the torrented file(s) over simple HTTP in your browser (or possibly JDownloader).


 



 

I Want My PGP

PGP is built-in and very easy to use. Open gpa (Gnu Privacy Assistant) from the Whisker Menu. This is your one-stop program to create, view, import and export PGP keys and more. Via Windows > clipboard you have the interface to create PGP blobs from plain-text, decrypt blobs people send you, encrypt and decrypt files, and everything else that PGP can typically do.

Warning: Do not use the same password or style of password for GPG keys in your Whonix as the password you use to unlock your hidden VeraCrypt volume to access your Whonix in the first place. Malware in Whonix - e.g. JavaScript code on an LEA-seized site - could spy on your keystrokes inside Whonix. Don't let them discover your VeraCrypt volume password in this way.


Note: For non-key pair (symmetrical) encryption of any file or data, please use VeraCrypt (and not PGP) which is the safest option for very sensitive data.


 



 

I Want My Freenet

Freenet is known to host Files. It's a useful but aging technology for privacy, secrecy, and anti-censorship on the Internet.

To install:

Follow Freenet's Linux installation instructions here. If connection doesn't work, try referring to these instructions on the Whonix Wiki.

To use:

Always browse Freenet with an alternative browser in Whonix like Firefox ESR. After Freenet is installed, type about:config into Firefox ESR URL bar, press Enter , search for network.proxy.no_proxies_on and set it to 0. Then go to http://127.0.0.1:8888/ to start using Freenet, and be patient (maybe several hours) to let it find peers and start connecting to that particular network. If you have trouble maybe ask on the Whonix forums. If you have success, please share in an official support thread.

Tip: To uninstall Freenet, first run Shutdown Freenet from the Whisker Menu then in Terminal do: java -jar ~/Freenet/Uninstaller/uninstaller.jar


 



 

I Want My I2P

Try the Whonix wiki's I2P instructions and report any success in an official support thread. Alternatively, in Whonix's Tor Browser you can browse I2P using one of these suggested I2P web 'Inproxies'.

Warning: People running I2P web proxies can view everything you do through them. Only use them for basic eepsite browsing / downloading, and expect all login credentials you enter to be stolen or harvested by the proxy operators if they so choose to.


 



 

I Want My IRC

IRC is built-in and easy to use. Open HexChat from the Whisker Menu. Alternatively, use a web client in Tor Browser.

Warning: Live chat is a very easy way for your personality and writing style to be leaked, as you have no time to think about how you're writing and expressing yourself to others. You could be speaking to a law enforcement officer at any time, so please be aware of this potentially significant risk.


 



 

I Want My Usenet

Want to find material on Usenet to share on Tor? Use SABnzbd.

To install:

In Terminal do: sudo apt install sabnzbdplus

To use:

Open SABnzbd+ from the Whisker Menu but click No in the URL prompt for Tor Browser and instead open Firefox ESR from the Whisker Menu, navigate to http://localhost:8080/sabnzbd/ and follow the wizard guide to set up the client to start downloading your binaries.

You will need to find a free Usenet provider that doesn't block Tor IPs (or you can find a VPN IP address like with our VPNGate method instructed earlier. You also may find it hard to find a free provider with long file retention, but there will be some that satisfy all requirements if you search online.

 



 

Various FAQs


Do I Always Need to Turn on Gateway Before Workstation?

No. Gateway just gives Workstation its Internet. You can use Workstation offline like any other VM and just reboot Gateway or Gateway's Tor process to use Internet in Workstation again.

 



 

I'm Scared of Linux. Will I Run into Problems or Even Lose My files Because of It?

No. Don't be afraid of Linux! It is actually more stable and less buggy than Windows these days. Most of what you do in Whonix is not Terminal commands but all GUI, and it's easy to get used to the Terminal if you have a little patience. Be brave to click around in Whonix and try using it like you would Windows. Download a practice Whonix before moving over your files.

Ask questions in an official support thread if you need help. The Terminal in Whonix is the only 'scary' thing that you may not be used to. If you have used Command Prompt in Windows, or Terminal on the Mac, it's very similar to that.

 



 

Am I Missing out on Better Windows / Mac Software by Moving to Whonix?

Yes, but it's nowhere near as bad as you think. It can't be avoided that the interface and software quality of Whonix is not as good as the polished, commercial, billion-dollar ecosystems of Microsoft, Apple and Google. Linux is community-powered and built "by the people, for the people". It will surprise you what cool software and features a bunch of passionate, obsessive, and stubborn computer nerds and freedom fighters can produce. Welcome to Linux!

Note: With PlayOnLinux, an emulator for Windows apps in Linux, it may be possible to run apps like Windows Photoshop inside Whonix. A better option now would be to create a Windows VM on HiddenVM and run it alongside your Whonix, carefully disabling its network access in VirtualBox.


 



 

Do I Have to Worry About App Updates? How Does That Work in Linux?

In Debian, it's very elegant. By default, Whonix's 'app store' is something called the Debian 'Stable' repository. All programs installed via sudo apt install as well as the default included programs are automatically updated each time you do sudo apt update && sudo apt full-upgrade. Some of the versions issued by the 'Stable' repo are sometimes very old, but the benefit is that whenever updates do come, they are automatic.

To use newer versions and still get automatic updates, you can use the 'backports' feature. It is quite a stable way of getting slightly newer versions.

But for more cutting edge versions of packages, you can try directly downloading DEB files from either the Debian 'testing' repo, or the developer's website directly. Sometimes it can't work because it is too new for Whonix's Debian version, but when it does, you may prefer it for some apps you work with very often. However you need to check for updates completely manually with this method.

Lastly, the best option for automatically being updated to the very latest version of a package is to add its third-party repository to your APT sources. Some examples of this are instructed in the guide, e.g. Recoll.

 



 

How Do I Update Whonix When They Release a New Version at whonix.org?

About once every 12-24 months, Whonix releases a new version with a new OVA template VM file containing an updated version of Debian Linux that brings many improvements, security features or performance upgrades. It's always very much recommended.

The best way to know what to do is to check an official support thread for this guide to discuss any new release from Whonix.

It's best to install a new OVA for each new major Whonix releases, then manually and securely move your old Workstation files and preferences to the new VM (like your Tor Browser Firefox profile and GPG keys), all inside your hidden VeraCrypt volume by using a temporary Virtual Hard Disk VDI file as instructed in the expanding storage how-to.

For the current instructions for upgrading from Whonix 14 to 15, see here.

 



 

I'm Running Out of Space. What Can I Do?

Manage space in your main VeraCrypt volume

- By default, Workstation VM has a 100 GB limit and is configured with Dynamically allocated storage. This means that the Workstation VMDK file expands inside your VC volume as you fill space in your Whonix, with a hard limit of 100 GB.

- When determining your free space in Tails, don't use the Disks app. Use the Files app: right-click in any folder in the VC volume and select Properties to see the accurate value.

- There may be deleted files in your VC volume which were not actually deleted but went into the trash folder, located in a hidden folder .Trash-1000 on the volume. Free up this space in your volume by checking and emptying the Trash in Tails Files app.

Manage space inside your Whonix

- To check your free space inside Whonix, open Thunar File Manager and the free space is displayed in the bottom status bar by default. To see a percentage calculation, hover the mouse over File System under Devices in the Side Pane.

- You can regularly empty the Trash by right-clicking on Trash in Thunar's Side Pane, then selecting Empty Trash.

Expand Whonix storage using free space in your main VeraCrypt volume

With VirtualBox, you can add an extra Virtual Hard Disk to any VM, and it's generated as a large VDI file in your hidden VeraCrypt volume next to your main VM files. Once set up, this is the most high-performing, convenient, and safe way to expand your Whonix storage.

To set up:

First install KDE Partition Manager in your Whonix-Workstation-XFCE. To install, in Terminal do: sudo apt install partitionmanager && sudo sed -i 's+Exec=partitionmanager+Exec=pkexec partitionmanager+g' /usr/share/applications/org.kde.partitionmanager.desktop

Note: Due to a current bug in Whonix 15, to set up KDE Partition Manager, you then need to do this second step:

  • 1. In Terminal do: sudoedit /usr/share/polkit-1/actions/com.ubuntu.pkexec.partitionmanager.policy

    2. Enter changeme into the password prompt, then an empty file in Mousepad will open. Copy the below text into the file, save it, and close it off:

    <?xml version="1.0" encoding="UTF-8"?>
    <!DOCTYPE policyconfig PUBLIC
      "-//freedesktop//DTD PolicyKit Policy Configuration 1.0//EN"
      "http://www.freedesktop.org/standards/PolicyKit/1/policyconfig.dtd">
    <policyconfig>
    
      <action id="com.ubuntu.pkexec.partitionmanager">
        <message>Authentication is required to run KDE Partition Manager</message>
        <icon_name>partitionmanager</icon_name>
        <defaults>
          <allow_any>auth_admin</allow_any>
          <allow_inactive>auth_admin</allow_inactive>
          <allow_active>yes</allow_active>
        </defaults>
        <annotate key="org.freedesktop.policykit.exec.path">/usr/bin/partitionmanager</annotate>
        <annotate key="org.freedesktop.policykit.exec.allow_gui">true</annotate>
      </action>
    
    </policyconfig>
    


Now power off your Workstation VM, copy the following text to read in Tails text file if necessary, and do the following in Tails VirtualBox:

Single-click the Whonix-Workstation-XFCE VM in VirtualBox and go to Settings > Storage. In the Storage Devices pane, in the Controller: line click on the hard disk button the the end of the line (a mouse hover says Adds hard disk.) and select Create new disk. Click Next, select Fixed size then Next, choose the size of the virtual drive as well as a custom name you want, then Create. Then click Choose and OK, and it will attach itself to your Whonix-Workstation-XFCE.

Power on your Workstation VM, and in it open KDE Partition Manager.

Under Devices, right-click on the VBOX HARDDISK item pertaining to the one you just created in VirtualBox (e.g. it may be /dev/sdb/) and select New Partition Table, then Create New Partition Table. Right-click on the large unallocated box and select New, then set File system: to exfat and click OK. Now click on the Apply button in the top left-hand corner right under File, then Apply Pending Operations, then close everything off by clicking OK and exiting the program.

To use:

Congratulations! Your Virtual Hard Disk is now ready to use. See it in Thunar File Manager listed as a hard drive under Devices named something like 50 GB Volume. Click on it and enter changeme if asked, and it's now mounted for you to use like any other folder in Whonix for that session.

Tip: If you do this as your principal method of Whonix storage expansion, you might want to set it to auto-mount at each Whonix startup and also mount to a specific folder location in Whonix. (Also, under this method, you should choose the arguably superior ext4 file system instead of exfat which is the more n00b-friendly option right now due to some GUI bugs.) In this example, it's a folder called called MyFiles under Home at the same level as Downloads and Desktop. In Terminal, do after the following example:

echo -e /dev/sdb1 /home/user/MyFiles ext4 defaults 0 0 | sudo tee -a /etc/fstab && mkdir /home/user/MyFiles && sudo mount -a && sudo chmod 777 /home/user/MyFiles

If you want to have spaces in the folder name of your mount path, you have to put the delimiter \040 for each space in the first instance of it in the Terminal command above, e.g. echo -e /dev/sdb1 /home/user/My\040Files for /home/user/My Files.


Note: Auto-mounting your Virtual Hard Disk in Whonix using the above tip has a caveat. If you somehow power on Whonix-Workstation-XFCE without it being able to access the VDI file (e.g. the storage media containing the file is not connected, you've deleted the file, or you've specifically detached it from the VM via VirtualBox settings), Whonix's internal Linux tries to mount the missing drive and fails, resulting in a command line-only troubleshooting 'emergency mode'. Luckily no data is lost, but to fix your Whonix you need to log into the emergency mode as root as suggested (input the usual changeme password), do nano /etc/fstab then use your arrow keys and backspace to remove the entire line that starts with /dev/sdb/ then save the file by pressing Ctrl-O then Enter then close off nano by pressing Ctrl-X, do reboot and it's fixed.


Thank you to fuax for getting rid of the bullshit.

Expand Whonix storage using space on external VeraCrypt volumes

Put your excess Files on external drives (in secure hidden VeraCrypt volumes) and access them from inside your Whonix. To do this, refer to the earlier mini-guides, Use External Drives with Whonix or Use VeraCrypt Inside Whonix.

Warning: NEVER use the Gateway VM for file storage. That VM can see your real IP address and therefore associate it to any data you place inside its local file system. Read more here.


Attach an existing Virtual Hard Disk file to a VM without errors

Usually you can attach an existing Virtual Hard Disk (e.g. VDI) file to a new VM by simply adding it in its VM settings like in the instructions above.

However, if you change the file name or location of the Virtual Hard Disk file, such as when moving from an old Whonix to a HiddenVM Whonix, there can be VirtualBox errors.

To easily fix that, do the following:
Now you will be able to attach the file to any VM.

 



 

My Workstation Internet Has Stopped Working. What Do I Do?

If this happens, the easiest thing each time is to power off Whonix-Gateway-XFCE, then turn on again. Leave Whonix-Workstation-XFCE open and within about 30 seconds of Gateway's new session, Workstation should have Internet again.

 



 

My Whonix Is Starting to Slow Down. What Can I Do?

- Change Whonix-Gateway-XFCE to CLI mode as instructed here, as well as following all other recommendations in the Setup section.

- What is your hard drive setup? If Whonix is on an external USB, consider moving it to an internal motherboard-connected SSD, or at least a fast USB 3.0 drive. If using an old HDD, change to SSD, which gives a huge speed improvement.

- Upgrade your computer's CPU, RAM, and video card if possible.

- Is your Whonix the latest version? Check the Whonix website to stay updated. Also update packages in both your Whonix VMs.

- Check the list of startup services in Workstation's Linux system. Maybe you have downloaded a few apps you no longer use and they are launching services in the background without you realizing. To remove them from system startup, open Session and Startup from the Whisker Menu, go to Application Autostart tab and delete items you don't need anymore. For more advanced users who know what they're doing, check /etc/init.d/ (and delete items in Terminal after this example: sudo update-rc.d -f <service_name> remove), and also /etc/systemd/system/ (delete in Terminal after this example: sudo systemctl disable <your_service>). Be careful with these commands and make a full backup of your VM files beforehand just in case.

- Check that you haven't installed too many add-ons in your Whonix Tor Browser that you don't use anymore. They really slow Firefox down.

- Did you encrypt your hidden VeraCrypt volume with the super secure triple encryption AES(Twofish(Serpent) option, or double encryption like AES(Twofish)? If so, change it to simple AES which should be secure enough and will free up more processing power for everything else.

- Physically clean out your computer in case it is dusty (e.g. the fans). It can make the machine run hot and slower than it should.

 



 

What Is a 'tar.gz' / 'tar.bz2' File and How Do I 'Install' It?

Also called 'tarballs', tar.gz or tar.bz2 files are not necessarily installer files. It's just another compression and/or archive format like RAR, 7-ZIP, or ZIP. A '.tar' file is a basic archive container without any compression, and the '.gz' or '.bz2' is the extra layer that compresses it. You rarely find plain .tar files, and usually find compressed tar.gz / tar.bz2 files.

App developers often provide tarballs to distribute their source code, an executable script to easily install their program, a ready-to-use portable binary executable of the program, or other installation files like a .deb or a whole bunch of Linux architecture / distro installers.

To open a .tar.gz or .tar.bz2 file in Whonix, right-click on the file in Thunar then select Extract Here.

If you're a beginner, try to install programs only from Whonix's Debian repo via the easy Terminal sudo apt install <packagename> method, or find a 64-bit .deb file to install it by double-clicking on it (opening with GDebi Package Installer) as the second best method.

 



 

Thunar Tips / FAQs

How do I add folders to the left-hand pane as shortcuts?

To add a folder to the Places list in the in the Side Pane, right-click on any folder in Thunar and select Send To > Side Pane (Create Shortcut).

Can I have newly-opened folders to open as new tabs in the already-open Thunar instead of creating multiple windows all the time?

Yes. In Thunar File Manager select Edit > Preferences > Behavior and tick open new thunar instances as tabs.

 



 

OUTRO


Reminders and Recommendations for Safe Practice


Never Share Your Whonix Computer

Do not share your Whonix computer with anyone who you don't want to find out about your files.

Do not mount your Whonix on a computer whose hardware you are not in full control of.

If you do share the computer with someone you don't think would be suspicious, make sure that their OS is encrypted and cannot be accidentally seen by Tails when you use "Hidden Whonix".

 



 

Regularly Backup Your Whonix

With computers, anything can go wrong that can result in sudden catastrophic loss of all your data and with no easy way to recover it. Files that can get corrupted include the VirtualBox VMs (i.e. the VMDK or VDI files) inside your VeraCrypt volume, or the entire VeraCrypt volume itself. The Tails USB can also become corrupted if you ran out of memory and had to force the computer off in a non-ideal way. These times are rare, but it can happen.

To backup your Whonix in Tails:

Note: The transfer process between two highly secure VeraCrypt volumes like this can take hours depending on the speed of your USB / hard drive / CPU, but it's worth it for the safety it provides. Invest in a large USB drive, and back up your Whonix on a regular basis. You'll be thankful later.


 



 

Only Use Your Whonix for Online Activity

Don't do anything related to your RL in your "Hidden Whonix". Malware or spyware inside your Whonix such as in the Tor Browser may mean that you are super anonymous, but you're being watched.

Another way to dangerously connect your identities is moving a previously-viewed file into Whonix and then opening it in Whonix. A local .html file could load remote Internet resources like images when you open it in the default OS browser. A PDF file would have hyperlinks in it which when clicked on send 'HTTP referrer' info over the Internet that links the PDF your IP address. If such files are obscure or unique enough, you have possibly linked your identities as clearly as if you Googled your real name both outside of Whonix and then inside Whonix in the same minute.

Think carefully about separating your identities, including their associated files, data, and habits. If you have this attitude, you will naturally realize when you shouldn't do something, or you will at least be mindful of the risk.

 



 

Use Whonix Gateway as Minimally as Possible

As the Whonix project advises, never use the Gateway VM for actual Internet browsing or anything other than the bare minimum functions to do the Tor connecting or to apply its maintenance or security updates. It is not bullet proof against IP address leakage like Workstation is, so you should never do anything incriminating inside it.

 



 

Be Aware of Browser Fingerprinting

The one disadvantage of enabling JavaScript or other plugins inside Whonix is that although you are completely safe from IP address leakage, a different set of tools to 'track' you become available, all of which rely on JavaScript.

Even if you turn JS off, your writing style can identify you anyway. Simple linguistic analysis can identify your regional origin based on idioms, grammar or spelling choices that you didn't realize were normal only to your area and not elsewhere in the world. Big data and machine learning at Google and NSA are working hard to give every individual a signature based on text data alone. We should now accept that such entities (and, increasingly, lower-level LEA) know who is who online.

With this in mind, VeraCrypt's deniable encryption as instructed in this guide is important for every file sharer. They may track you down to your IP address or RL identity, but if your HDD shows nothing, you are innocent in court. Only file producers or file site admins need to do more things than what's recommended in the main guide, where police might hide outside your house and try to seize your computer while it's still on and unencrypted (i.e. they ambush you).

 



 

Safety Precaution for File Sharing

Hidden files in any OS - even on Linux, e.g. .directory files - can contain scary metadata revealing private or deanonymizing data like system username, timestamps revealing clues about your timezone, or other data. Before you ZIP that image folder up for a site, please check that no personal metadata is hiding in there that shouldn't.

To be safer, you should always be viewing hidden files by default in Whonix. In Thunar File Manager, tick View > Show Hidden Files by default to make sure you don't accidentally upload privacy-compromising hidden files. Use software like mat2 to sanitize your images, videos, which can contain GPS data or other identifiers from your smartphone or camera model.

 



 

Concluding Thoughts


All file sharers should make the effort to adopt "Hidden Whonix" for all the reasons outlined in the INTRO.

You will get used to the quirks, limitations and unique possibilities that Whonix on Tails has. You will come to love the feeling of security and safety in your encrypted little world, a feeling of relaxation in the back of your mind when downloading or sharing files!

Never let this safety be an excuse to start practicing bad security habits, just because you're in Whonix. Instead, Whonix is a way to enrich both the safety and possibility of what you can do online.

We should all use Whonix to increase the safety of the entire paranoid community. The safer one of us is, the safer all of us are.

So come try it out and stay safe!

 



 
 

Changelog and News


Changelog

This is a record of improvements or milestones of the guide. It does not always mention everything, but sometimes only big things.

2020-07-04:
    - Launch of Guide v3.0. Tails is now the mandatory host OS. HiddenVM is the tool that allows us to run Whonix on Tails. This is the biggest upgrade in safety since the launch of the original Guide. BIG moment!
2020-07-02:
    - In multiple locations in the guide, added important tip to never re-use your VC volume password anywhere else.
2020-06-30:
    - New instructions for using external drives with Whonix. Now simpler and safer method thanks to Tails.
2020-06-23:
    - Added tip for how to make VeraCrypt volumes larger than 2TB in size. - Added ADVANCED TIP for how to move files between whonix and RL worlds more safely.
2019-10-18:
    - Added a how-to under 'Performance Optimizations' for speeding up VM boot time (remove splash and boot screens). - Introduced new sharper font for 'Improve Whonix Appearance'. - Added 'Prevent long shutdown' to a new 'Random Whonix Bugfixes' section.
2019-10-13:
    - Launch of v2.5 of the guide. Updated for Whonix 15, new screenshots, and more. - Dropped support for macOS as a host OS.
2019-05-26:
    - Added a how-to 'Disable JavaScript on specific sites' in 'Post-Install Steps'
2019-04-22:
    - Added instructions for turning off advertisements in JDownloader.
2019-04-19:
    - Updated Setup instructions to reflect the Whonix Project's change of now offering the dual VMs in a single OVA file. - Added Foxit Reader in the guide as an excellent PDF reader default for Whonix.
2019-04-07:
    - Updated the default recommended 'Image Viewing' program to XnView MP with provided customizations.
2019-03-01:
    - Bugfix in VirtualBox host OS install instructions. - Now recommending to disable 3D / 2D acceleration for Workstation due to security advice. Thanks Old Lurker!
2019-02-01:
    - Updated the 'unpack' script (in JDownloader section) to not create an extra subdir for extracted files. Neater IMO. - Added cool tip about JDownloader's backup/restore function in its mini-guide. Thanks Jamie_Boy! - Added MediaInfo mini-guide for inspecting any media file.
2019-01-19:
    - Added a critical security step to the SETUP section, 'Turn off VM 'Preview' in VirtualBox'. - Added instructions to Post-install Steps to enable languages like Korean to display properly in Whonix.
2019-01-12:
    - Image Viewer how-to improved with plugins add-on.
2019-01-04:
    - New Year's gift! Guide updated to v2.1 for Whonix 14 Xfce! Too many improvements to list. HUGE UPDATE. NOW WAY FASTER.
2018-12-25:
    - Christmas surprise! Guide now updated to v2.0, Whonix 14! Sorry, too many improvements and too little time to list them here. Just enjoy!
2018-07-31:
    - Added how to set a hotkey to toggle Dolphin/Terminal/any app in Whonix in the 'Further Tips' section.
2018-06-15:
    - Added the 'Virtual Hard Disk' how-to for expanding your Whonix storage.
2018-06-11:
    - Added how to back up your Whonix under 'Regularly Backup Your Whonix'.
2018-06-10:
    - Added how-to rotate videos (HandBrake, now 'Basic Video Editing').
2018-06-09:
    - Added tip for how to check the IP address in JDownloader. - Added a mini-guide for 'Basic Image Editing'.
2018-06-08:
    - Added a tip for how to fix jerky video playback in VLC.
2018-06-07:
    - Added a suggestion tip for Mac hardware users to create a macOS bootable USB installer disk in 'SETUP'.
2018-05-31:
    - Added a post-install step to disable 'non-free' check (an annoying default pop-up).
2018-05-27:
    - Added a mini-guide for combining a video + subs into single MKV without reencoding.
2018-05-23:
    - Updated, cleaned up and finalized the SSD wiping section under 'SETUP'. It's now no longer a nightmare.
2018-03-13:
    - Added PeaUtils, a GUI tool for checksum/hash and join/split file.
2018-03-12:
    - Noted a current limitation of the archive file auto-crack and extract script.
2018-03-11:
    - Updated the method for creating archives to be much easier and now on-par with Windows. - Added a tip for how to view massive photo folders or collections in Whonix.
2018-03-06:
    - Added privacy tip to FIU mini-guide. - Added tip about how to update FIU easily from within the app.
2018-03-04:
    - Added a script to auto-crack and extract files when JDownloader's workflow fails.
2018-03-02:
    - Made installing VirtualBox Extension Pack as a default instruction in the setup steps.
2018-03-01:
    - Added extra detail for how to protect hidden VeraCrypt volume when outer volume is mounted. - Added a tip for how to make GIMP actually nice to use (like Photoshop). - Made hint about Opera hijacking the default browser status and how to fix it.
2018-02-23:
    - Made the VPN method much better in the 'Unblock Sites That Block Tor IPs' mini-guide.
2018-02-22:
    - Added 'xterm' to post-install steps. - Clarified the 'The Internet has stopped working' FAQ adding details about what it can look like.
2018-02-21:
    - Improved and clarified instructions in the Setup section. - Added keyboard shortcut how-to for 'Shut down' (two options).
2018-02-20:
    - Added browser add-ons tip to 'My Whonix is starting to slow down' FAQ.
2018-02-19:
    - Launch.

News

June 2020: v3.0 Guide launched, move to the HiddenVM method: A new era of safety for all users

Version 3.0 of this Guide is the biggest increase in safety and security since the launch of the original Guide on some fucked site probably.

Not much was changed in the how-to's for how to do things inside the Whonix VM. Most changes are in the shift in host OS to Tails, and you getting used to Tails as a different feel for how your computer runs.

Some default security recommendations have even gone because Tails is a fundamentally higher level of security to a normal static Linux host OS. For now, almost all former security precautions remain as tips remain for 100% paranoid users.

Everything in the Guide has been tested on the latest Whonix-XFCE-15.0.1.3.4.ova published by the Whonix project at the time of 3.0 publishing. Hopefully it is bug-free enough for you to try out without too much trouble.

To upgrade a Whonix 14 Xfce to a Whonix 15, see here.

To move an existing Whonix into HiddenVM, see here.

Spread the word

If you are passionate about promoting this project, why not put a link to the guide in your forum profile signature? Go to your signature edit box and use something like this:

[b][size=100][bgcolor=#563D7C][color=#166FA6][/color][color=#F7F7F7]"Hidden Whonix" Guide. Stop using Windows. Start being safe.[/color][color=#C13B5B][/color][/bgcolor][/size][/b]

 



 

How to Securely Wipe Your SSD / HDD


Note: This is when you should confirm that Tails works on your computer. Some hardware can be problematic such as newer Apple computers. Create a Tails USB, and test it out. If you're having problems, let us know in an official support thread and we will try to improve the guide with more pointers. If it just doesn't work, you may have to buy another computer to move to "Hidden Whonix".


Are you migrating from Windows, macOS, or another Linux setup to "Hidden Whonix"?

Before you do, and after you've backed up any existing files securely into a hidden VeraCrypt volume, you should wipe your hard drives thoroughly.

Note: This is a very detailed set of instructions that will satisfy the most paranoid user possible. The only thing more secure than these steps - and you should actually consider it - is to physically destroy an existing SSD that has had unencrypted files on it.

You don't have to try all these steps. Decide what you'd like to do. All steps are included so that even the highest-level targets can refer to this. What you should do depends how paranoid you are, how much time you have, and how much money you have.


Tip: How do I boot from a USB? On most PCs, at bootup you repeatedly press either F12, F2 or Del to choose to boot from a USB Hard Disk. If that doesn't work, research online or find out by exploring your BIOS. On Mac hardware, hold down the alt key at bootup.


If your disk is an older-style spinning HDD (and not an SSD), do your disk wiping with DBAN. In your current operating system, Download the ISO from SourceForge, download and use balenaEtcher to flash the ISO to a USB. Then boot from the DBAN USB. Follow DBAN's wizard by simply pressing Enter for the default option, which is secure enough for most people's needs, or choose other options if you are really paranoid. Congrats, your HDD is now ready to put "Hidden Whonix" on it, so continue following the guide.

But if your disk is an SSD, secure data erasure is more complicated, but quicker to perform. Continue below to perform all of the next steps on your SSD, which together will satisfy 99% of users.

Warning: The following secure erase commands must be performed while the SSD is directly connected to the motherboard via internal cable such as SATA or PATA (IDE), otherwise the commands may permanently break the drive. If you want to securely wipe an SSD from an external enclosure, you must take it out and connect to your computer directly via SATA/IDE cable (instead of through USB / Firewire / SAS / SCSI / RAID card). Try the commands on a USB thumb drive (or USB-connected large external drive) but do so at your own risk, with possibly less risk by using the very latest version of hdparm.


First, locate your SSD manufacturer's official utility provided for procedures like updating firmware, data erasure and disk maintenance. It may take some effort to determine the actual manufacturer of your SSD inside the drive (which can be different from the brand displayed on the label), such as through physical inspection of the SSD or detailed device driver lookups in your current host OS.

Once you determine the real manufacturer, download the official 'live CD' (or USB) ISO provided on the manufacturer's website. Download and use balenaEtcher to flash the ISO to a USB, and boot from that USB.

Note: With many SSD models, the only way to create a bootable utility disk is via a Windows utility. So if you're not already coming from the Windows environment, you may have to install Windows just for this process, or in the case of a Mac, install a temporary Windows in VirtualBox or Parallels (or Boot Camp). Additionally, for Mac SSDs, there can be no official manufacturer utility compatible with the drive, depending on the SSD model.


Booting from your SSD's official utility, first update the firmware of your SSD if possible. This helps you gain the highest chances of actual data erasure in the steps below.

Then: perform every tool you see that seems related to data wiping or resetting, including 'sanitize', 'crypto scramble', or 'secure erase' tools. Unlike DBAN's process for magnetic HDDs which can take hours, most of these steps will be quick, and they are important to perform. With some models, only the official manufacturer utility can do it properly because they have the most knowledge of the inner workings of their particular model's firmware implementation of the ATA Security commands.

Next are similar data wiping steps as the above, but this time, with fully open-source software which we can therefore trust a lot more.

Boot into your Tails USB and come back here to continue instructions. (For how to install Tails and read this guide safely inside it, see instructions here.)

Then: install the latest version of hdparm in Tails. Open Root Terminal in Tails, and do: apt update && apt install gdebi -y. Then download hdparm's Debian testing version here. Open the containing folder of the DEB file, right-click on it and select Open With Another Application. Select GDebi Package Installer. Click the blue Select button. It will guide you to install it.

Then in Tails Root Terminal do: fdisk -l | grep "Disk /dev/sd" to carefully determine which disk in the list is the one you want to wipe, by checking their disk size. The examples below are for sda, but yours may be different.

Optionally: if paranoid, do after this example to perform a basic software-level disk overwrite, which is worth doing just once, even on an SSD: dd if=/dev/urandom of=/dev/sda bs=1M. Wait for the screen to return from the flashing cursor to the normal prompt, and beware that this optional step could take hours (e.g. 9 hours for a 2 TB disk). It depends on the size of the SSD.

Then: first try hdparm's SANITIZE commands. Try the following three commands, and if after the first one hdparm says SANITIZE feature set is not supported, continue to the next set of commands because these three ones won't work:

hdparm --yes-i-know-what-i-am-doing --sanitize-crypto-scramble /dev/sda

hdparm --yes-i-know-what-i-am-doing --sanitize-block-erase /dev/sda

hdparm --yes-i-know-what-i-am-doing --sanitize-overwrite --pattern=/dev/urandom /dev/sda

Help: Someone with a SANITIZE command-compatible SSD needs to verify if that third command works! Can you help? Report your results in an official support thread.

Below are some more widely-compatible hdparm ATA Security commands.

Do after this example: hdparm -I /dev/sda | grep frozen

If its output says not frozen, continue to the next step. If it only shows frozen, you need to unfreeze the SSD drive. Press the Win key and search for Settings and open the Settings app. Select the Power item in the sidebar menu, and set When the Power Button is pressed to Suspend. Then short press the power button to suspend the computer. Wait about 20 seconds when it has entered the suspend state, then short press power button again. Now go back to Tails Root Terminal and do the above command again. If it says not frozen you can proceed to the next step.

Tip: If you are still having trouble unfreezing the drive for hdparm, try some further methods posted online here and here. Further methods include hot re-plugging an SSD drive via either its SATA and/or power cable while Linux Mint is running. Also, you may need to enable AHCI in your computer's BIOS for it to work, read here.


Now, do after this example: hdparm --user-master u --security-mode m --security-set-pass 'temppassword' /dev/sda && hdparm -I /dev/sda and make sure the output shows enabled near the top, without a not before it.

Next: in the same output, if it shows supported: enhanced erase, do after this example:

hdparm --user-master u --security-mode m --security-erase-enhanced 'temppassword' /dev/sda

But if it shows a not before supported: enhanced erase, do after this example:

hdparm --user-master u --security-mode m --security-erase 'temppassword' /dev/sda

For the commands above, it could take some time if it is a large drive but you can find an estimate of how long either command will take by first doing hdparm -I /dev/sda and reading the output where it will say something like 9min for SECURITY ERASE UNIT. During command operation, wait for the Terminal to return to the normal command prompt, which is how you will know the process is done.

Congratulations. This completes the most exhaustive set of steps possible to wipe an SSD using software. Your SSD is now safe to install Whonix on it. Continue to the next step in the Guide.

Note: For further reference and information about all the above SSD wiping procedures, visit these four links.


Warning: If you have file data that was at any stage unencrypted on an SSD (not a magnetic HDD), then be aware that there are small possibilities that data traces can still be present in hard-to-erase areas in the SSD cells. This is extremely unlikely, but technically possible. There is no open-source software method or inexpensive at-home forensic procedure to verify for 100% sure that your data is irretrievable after performing the above steps. This concern is only applicable for users at the highest level, i.e. 10/10 paranoia. If you cannot afford to trust any form of data security outside the mathematics of open-source cryptography (and note that this concern also applies to HDDs), then you will have to physically destroy the disk, buy a brand new disk, and consider this an expensive education in file data safety.


 



 

How to Shrink or Optimize an Animated GIF in Whonix


This guide shows how to make an image like the one below demonstrating how to use the Terminal.


It's possible to make some very sexy GIFs - especially clips that perfectly loop! AGIF can be a low file size if it's of avatar-size (or signature size) and if the loop is also under 1-2 seconds or 50 frames. It's possible to make an effective GIF without clogging up users' page loading.

Note: The animated GIF format was NOT invented for GIFs like the example above. It was meant for 3D vector-based animations in loop format like the 'live' logo images from websites in the 90's - not for photo-realistic, JPEG-type stuff like today's GIF memes. It took a long time to produce the example above - it's a miracle GIF - and it's still 3.5 MB, i.e. too big!

The actual image format of each frame in an animated GIF is lossless PNG. That's why file size reduction is difficult. Without the compression and lossy possibilities like JPEG, you have to save space in other weird ways like limiting color range (from 256 down to 64 or even 32), and generally being creative with your design.


Here's seven steps using Linux command line tools

If a package below like gifsicle is not installed, install it via: sudo apt install <packagename>.
Other tips and notes

- It's much more time consuming, but you can specify custom time gaps between each frame instead of the same between every frame. So instead of having 10 repeated frames for where a GIF pauses for one second if it's a 10 FPS GIF, just have one frame pausing for 1 second, cutting out 9 unnecessary frames out of the picture. Cutting frames out makes a big difference. You can even do this in GIMP and craft a whole animation between frames like as in Photoshop. AGIF file size is not so much about loop length, as number of frames, no. of colors per frame, pixel size per frame, and a few other ideas.

- To emulate your source GIF accurately you must know the gaps per frame value of the original GIF ('10' is 100/10 aka 10 frames per second equivalent), and it must have a constant 'frame rate' in order to be easily emulated as such. Some GIFs can have different value between different frames such as an already-optimized GIF.

- To combine a folder of image frames straight to animated GIF: convert -delay 10 -loop 0 *.jpg output.gif and for a longer / shorter pause between every frame, increase / decrease the delay number accordingly. This method makes far too big a GIF so instead I've instructed the mp4 intermediate step above.

 



 

Security, Privacy, and Anonymity ADVANCED TIPS


Note: These tips are based on the assumption the you already are using Whonix in Tails as per this guide and already taking into consideration every other tip and suggestion offered in the main Guide. These are only extra tips after all that.


- Password-protect your BIOS / UEFI or Mac firmware. Securing your BIOS / UEFI or Mac firmware gives strong protections against attacks like Internet-planted UEFI rootkits or Evil Maid-planted bootloaders or hidden devices impersonating your own, which can secretly capture your PC login passwords and all your data. If you are a high-value target, these attacks are more likely to be used by LEA to maximize their success of prosecution if they think you use plausible deniability and seizure-proof encryption. If you set a BIOS/firmware password and then they try to tamper with your BIOS, your BIOS password may reset and you will know you are being targeted. LEA however can plant many types of physical spying devices or hidden hardware keyloggers in your computing environment if they are directly targeting you for prosecution, so the usefulness of this is mostly to prevent dangerous malware delivered remotely. Use this reference if you are interested in this tip.

- Give your SSD its own extra access password without slowing it down. As a precaution against some attacks (like pre-FDE malware 'bootkits' in the bootloader area that can capture your host OS password) or LEA forensics upon SSD seizure, after wiping your SSD you can give it its own password which must be entered for any operating system to be able to then write to the drive. This 'ATA security' technology is called 'self-encrypting drive' or 'SED', and it uses AES-256 encryption at the SSD hardware level. It does not protect against key disclosure laws, but provides meaningful protection against advanced malware that could be placed on LEA-hijacked sites or in other attack situations. To set up, first unfreeze the drive via the SSD wiping instructions elsewhere in this document, then do after this example: hdparm --user-master u --security-mode m --security-set-pass 'mySEDpassword' /dev/sda. To use, at the beginning of each session to access your files, in Tails' Root Terminal do after this example: hdparm --security-unlock 'mySEDpassword' /dev/sda && partprobe. Tails can then access your hard drive as normal. The SED will remain unlocked through any other Tails reboots until you fully power off. To remove this feature and return the SED to work like a normal HDD again, unfreeze the drive once more then do after this example: hdparm --security-disable 'mySEDpassword' /dev/sda. Read these pages for reference and more info.

- Lock down your Whonix computer's hardware sensors to avoid malware exploiting them. Don't trust software alone to disable your computer's in-built webcam, microphone, audio speakers, radios like Bluetooth or WiFi, etc. Take apart your computer and physically remove unwanted sensors. Malware or default Tails settings could activate them without you knowing.

- Avoid ultrasound cross-device ad tracking / deanonymization between your phone and/or multiple computers. This one is scary. Passive ad tracking on your smartphone (like the Facebook app) using sensors (like your mic and probably other sensors like visual infrared dot projectors, Face ID) can powerfully link your online activity to your RL smartphone. Your keyboard makes sounds which can leak which keys you are typing via audio analysis of their sounds. Your monitor's screen emits ultrasound frequencies that can be 'filmed' through ultrasound audio analysis (from your phone). This could happen in the other direction, e.g. Linux malware planted by LEA on online sites (browsed in your Whonix) could be coded to listen via the microphone to capture audio from your computer's surrounding physical environment, to deanonymize you as a Tor user. To mitigate this, disable ads via ad-blockers (and a more powerful, effective, and safe to do this is via your hosts file using this list). Disable the microphone in Tails and any VMs by default. Turn the speaker sound off as much as possible when not in use (full mute). Use headphones instead of speakers when possible. Turn off smartphones when browsing sites or consuming content. Use a safer de-Googled Android phone without GApps on it. Avoid home speakers like Amazon Echo, Google Home, Apple HomePod etc.

- Got an old Android phone? Install Snowden's Haven app for intrusion detection and monitoring when you're away from your devices. Or buy a cheap $50 used Android online, making sure it has enough sensors to be useful for Snowden's app performing surveillance when you're away. This could let you know if LEA have planted powerful malware, hardware keyloggers or other spying devices on your computer or in your vicinity while you're away, or just others that you think may be suspicious of your devices and are trying to break into it - or generally snoop in your area while you're away.

- Make your online site account password 'styles' unique, and not like how you do elsewhere. A site could get hacked and your user account password is leaked in plaintext form. If there is anything in your account password that shows a certain 'personality', style, or similar syntax pattern to your RL passwords (or perhaps an old Yahoo! account, which now has millions of leaked passwords), that can be cross-referenced with other leaked databases by LEA who could thus identify you.

- Be careful in moving any files, images or videos between whonix and RL worlds. LEA can embed steganographic tracking code into media files. This is hidden information that you cannot detect with the naked eye or rely on detecting through with steganography detection software. These watermarks implanted by LEA in images could be used to track the spread of files online and who is associated with them. Because this is technically possible we should assume that LEA are doing this. NEVER transfer a file that you found on a site to RL computers or RL online accounts, even if it is legal content. Instead, you can transfer it with a degree of deniability by posting the file while in Whonix onto a Clearnet site which is easily accessible in public, which means anyone could have grabbed the file instead of you. Later, you can download it from the Clearnet site in a RL setting with plausible deniability of being the original uploader. If you move a file directly from your Whonix to a RL computer - or vice versa - it could contribute to you being deanonymized.

- Don't use the same password or password style across different parts of your computing. There are various ways in which your Whonix activity - such as a password you type in your keystrokes - is not as private as you think. Sites might be taken over by LEA and implant JavaScript malware which starts listening in - e.g. a keylogger inside Whonix. Don't use the same password for what you use to unlock your BIOS, SED, or Tails environment, as passwords you use in any situation in your Whonix such as PGP passwords or online accounts. As warned in the guide, the worst one of all is duplicating the password or password style of what you use to unlock your main hidden VC volume. Have a different set of passwords and password styles for every particular environment you're in.

- Learn to 'panic shut down' Tails in the proper way. In responding to the situation in which LEA may raid you while you are using the computer your VC volume unlocked, only shut down Tails by physically pulling out the USB stick, or via the software menu in top right-hand corner. These methods securely erase the RAM by writing data to it before very quickly shutting down the OS. Do not long-press the machine's power button or kill the power as your method, which is susceptible to cold boot attacks that LEA could use.

 



 

Mini Migration Guide to Move to a New Workstation VM


Tip: For a few reasons, it's suggested to upgrade major Whonix versions (such as 13 to 14, 14 to 15, etc.) by importing a new OVA instead of upgrading in-place your existing Workstation VM. Even if the risk is rare, it's a chance to discard any malware in the VM. It may speed it up if you have unused programs that are clogging up your autostart and shutdown scripts. It may also be necessary if the Whonix project advises it.


This mini migration guide is for migrating any Xfce Whonix Workstation version to the current version offered by Whonix project, e.g. from Whonix 14 Xfce to 15, or from 15 to 15.

Before you begin

- Backup your current Workstation VM into an external hidden VeraCrypt volume. Have a complete clone of your existing, working VM, so that you can go back to it if something goes wrong.

- Make sure you have enough space in your main hidden VeraCrypt volume to temporarily have extra space while copying files over into the new VM. If you accidentally fill up your last free byte in the volume when generating new Whonix files, major problems can occur and you have to start again from your backup.

Four migration steps

Step 1: Install the new VM next to your current one

- Follow the Guide v3.0 from the beginning up until "Install HiddenVM" section, to install the new Workstation VM.

- To access your old Workstation in HiddenVM, refer to this migration guide.

Tip: To enable Internet on multiple Gateway / Workstation pairs at the same time, in VirtualBox go to Gateway VM's Settings > Network > Adapter 2 and change Name: from Whonix to Whonix2 then click OK, then Workstation VM's Settings > Network > Adapter 1 and change Name: from Whonix to Whonix2. Then restart all VMs if necessary.


Step 2: Move your Files from the old VM to the new VM

There's multiple ways you can do this:

- Set up an identical Shared Folder in both VMs to easily move files between them using that folder as an intermediary. Shared Folder instructions here.

- Create a temporary Virtual Hard Disk file (VDI file) in VirtualBox attached to the old VM. Refer to storage expansion guide for instructions. After move all files into the VDI file, attach it to the new VM to import.

Step 3: Re-install programs in the new VM to emulate your old VM

Simply refer to the Guide to install new programs and set up your new VM as you like it.

Tip: To see a list of every package you have installed in your old VM via APT or DEB file, do this in its Terminal: apt-mark showmanual | sort | grep -v -F -f <(apt show $(apt-mark showmanual) 2> /dev/null | grep -e ^Depends -e ^Pre-Depends | sed 's/^Depends: //; s/^Pre-Depends: //; s/(.*)//g; s/:any//g' | tr -d ',|' | tr ' ' '\n' | grep -v ^$ | sort -u)


Step 4: Copy your program settings to the new VM

First, fully update your old VM by doing in Terminal: sudo apt update && sudo apt full-upgrade. Try to ensure there are no more updates reported to perform by repeating that command again. To potentially fix a kernel update error, do: sudo dpkg --configure -a

Now, you can copy over your program settings and files after they've been installed in Step 3. Here are some examples of how: Other things to consider:
Finally

Keep a copy of your old VM for a while, in case you forget to copy over something important.

CONGRATULATIONS. YOU'RE IN YOUR NEW WHONIX OVA. ENJOY!

 



 

Mini Migration Guide to Move an Existing Whonix Into HiddenVM


Before you begin

- Update your current Whonix's VirtualBox version to the very latest official stable version as shown on the virtualbox.org website. HiddenVM always uses the latest version and just in case VirtualBox changes the way config files are structured between versions, have them matched up for a smooth import. The easiest way to update to the latest is to download the official installer file from the virtualbox.org website that pertains to your current operating system.

- Test Tails to make sure it works on your hardware. You could even practice completely installing "Hidden Whonix" from scratch by following the main guide as a new Whonix user. At least make sure Tails run, so that you don't accidentally waste your time.

Three migration steps

Step 1: Backup the existing Whonix to an external VC volume

- How to backup: In your current host OS where you use your Whonix VirtualBox, create a hidden VeraCrypt volume in the correct way using these instructions. If coming from Linux, you might only need one extra hard drive. If coming from Windows/macOS, you will need two extra hard drives. After your VC volume is created, mount it and move your Whonix files into the volume.

- What to backup: All of your VM files for both Whonix-Gateway-XFCE and Whonix-Workstation-XFCE including their .vdi hard drive files, .vbox config files, and any Virtual Hard Disk expansion files that may be attached to them. Locate your VirtualBox VMs folder containing the subfolders for both Whonix VMs and copy the entire thing into your VC volume.

Step 2: Install HiddenVM

- Follow the new Guide from the beginning up until "Install HiddenVM" section.

- Take note of any new security advice in the Guide since v2.5. Tails as a host OS brings a lot changes. Some suggestions are now automatically safer and therefore more convenient. Other things to read are tips for how to make a VM on Tails a smoother experience.

Step 3: Import existing Whonix files into HiddenVM

Once you have installed HiddenVM and its VirtualBox window pops up for the first time, it's time to manually import your backed up Whonix into this new VirtualBox: CONGRATULATIONS. YOU'RE IN HIDDENVM. ENJOY!