~/Tor Browser folder. Find it as the Tor Browser shortcut in Files app side pane.
White background: Text you have to enter into a GUI text box when instructed in a guide.
Black background: Terminal commands. Don't panic! You won't die. It's all OK. Just...BREATHE...
Tip: Something cool or handy to know during an instruction or mini-guide.
Note: Something important to know or be assisted with when following a mini-guide.
Warning: Something serious about security, privacy, anonymity, data loss, or other possible catastrophes. DO NOT IGNORE.
Note: You may need a few USB drives of at least 4 GB each in size. Possibly at least two of them: one to be your new Tails USB, and one to be either a DBAN HDD wiping boot disk, or your SSD manufacturer's bootable disk utility.
Note: Depending on your current computer environment, you may also need an extra 1-2 large hard drives - whether internal or external - to place your new files in and fully make the transition to HiddenVM.
Note: This setup section involves turning off your current operating system and then booting into Tails to set up your new Whonix situation.
You can follow this setup section while creating your new "Hidden Whonix" by choosing from one of the 3 following methods:
- Use this computer to follow the guide while setting up "Hidden Whonix" on a second computer.
- If you only have one computer, you can put this .html file into your new hidden VeraCrypt volume as soon as you create it. Then when you boot into Tails, unlock your VC volume and open this file in Tails' Tor Browser. You'll need to temporarily copy the .html file into the ~/Tor Browser folder. Find it as the Tor Browser shortcut in Files app side pane.
- Less safe, but possible: Print the Guide onto physical paper. (To print out the whole Guide including SSD wiping instructions, click here to view the whole one-page version of this document. Select all and copy, then paste everything into a blank text or word processing file, then print. Remove some areas if you don't need the whole thing.) After use, burn it with a flame immediately for your own safety.
Warning: If you print this document onto paper, be careful of modern printers which can save to their memory all documents sent to the printer. Research your printer model and reset its firmware after printing this sensitive document if necessary.
Warning: The secrecy and privacy of the password you use to unlock your hidden VeraCrypt volume is extremely important and has serious implications for your safety. Never, EVER re-use your VC password in any situation apart from your local situation of unlocking your volume in a safe environment like Tails. Do NOT use it or any password in the same style as it for online accounts, VC volumes unlocked inside Whonix (due to malware JS on sites potentially spying on your keystrokes in Whonix), or anywhere at risk of having software listen in on your password. This password is your most private secret of all.
Note: Here is how to navigate the Guide, depending on your situation:
- If you are coming from Windows or macOS, and want to securely backup your existing files (including an existing Whonix), you will need to have an extra hard drive to perform this section's instructions on. This extra drive is to be a 'backup' drive, and NOT the main new drive you intend to use your daily HiddenVM installation on. Buy a second extra hard drive if you only have one.
- If you are coming from Windows or macOS, but have no files you want to backup, you do not need to create a VC volume until you have reached the Install HiddenVM section. Don't follow the below instructions until you are in Tails and are instructed to come back here. You will only need one extra hard drive in this case.
- If you are coming from a regular Linux OS, you only need one extra hard drive if it can comfortably fit all your current files plus about 50 GB extra. If you want to securely backup your existing files (including an existing Whonix), continue immediately with the instructions in this section. If there is nothing to bring to your
Warning: It may be safe to have a regular operating system on the same hard disk as your "Hidden Whonix", if you split it into multiple partitions and make one of those partitions your VC volume. However, it is more risky, especially if you don't encrypt your regular operating system and its file system is readable by Tails every time you use Whonix. The safer and easier solution is to make one entire disk your single VeraCrypt volume. Even in that case, make sure your regular operating system isn't unencrypted or physically readable when booting into Tails. It is safest to use a different computer entirely for your files.
Note: We recommend you to create your hidden VeraCrypt volume in a drive or partition of at least 110 GB in size, or you will run into problems later. Whonix is designed to automatically expand its VM files to 100 GB per VM, depending on whether you fill up the file system inside them. If you create a hidden VeraCrypt volume of only 50 GB and then expand your Workstation beyond 50 GB, it will run out of space in the VeraCrypt container, crash your Whonix VM, and possibly corrupt all the data inside it irreversibly. To be safe, make your VC volume at least 110 GB in size, regularly backup of your files, and regularly keep an eye on how much space your VMs are expanding to.
Note: To create VC volumes larger than 2TB in size (e.g. a 4 TB external disk), you will need to use a drive that presents itself with a 4096-byte logical sector size, and not just 4K physical sector size. The only reliable way to achieve this in 2020 onward is by buying a '4Kn' drive. These drives are more expensive than normal '512e' drives, but they may be more reliable for long-term use. The more common '512e' type of drive has a 4K physical sector size, but it presents itself to the computer with a 512K logical sector size and this is set at the firmware level which usually cannot be changed. In years past, there were certain devices to make >2 TB non-'4Kn' drives work with VeraCrypt, but those solutions no longer exist.
Tip: If you are extra paranoid or higher in the paranoid sector, you can choose something more heavy duty during VeraCrypt's Encryption Options than the default AES option. Some people think AES is now crackable by NSA, but only you can decide what you believe. Either choose AES(Twofish) as a double encryption option, or even the triple AES(Twofish(Serpent)) for full-scale paranoia. Depending on how good your CPU, SSD and other components are, these extra layers may come at a huge performance cost inside Whonix, affecting the smoothness of video playback or slowing down the speed of creating and extracting archives and file processing like re-encoding videos. You can measure the performance difference on your hardware by using VeraCrypt's Benchmark feature under Tools or during the same wizard step, but real-world testing may be different.
Warning: After you have created your hidden VeraCrypt volume, it is best NEVER to mount your outer volume ever again when you're using your computer. Using the outer volume can overwrite and permanently corrupt your inner hidden volume, even when just reading it without writing files. However, DO remember what your decoy password is - it is what will prevent your jail sentence if LEA seize your hardware. Write it down somewhere so you don't forget, which is safe to do since it will reveal nothing sensitive. If you want to mount the outer volume at any time, only mount it while using the Protect hidden volume when mounting outer volume or Mount volume as read-only feature in the Mount window's Options > button. The time to put in decoy files in the outer volume is during the creation wizard, and never after the wizard completes.
Tip: Make sure your new volume is big enough to hold Whonix in addition to your existing files. For some tips on disk space management, click here.
Tip for those using Mac hardware: At this point in the Guide it's a good idea to create a macOS USB installer before you wipe your Mac's SSD. A macOS installer disk may be needed to perform low-level tasks on your Mac like setting or changing the firmware password or doing an NVRAM / PRAM reset. It may also be needed to update the firmware of your Mac's hardware so that it works better with Linux. To do this you may need to fully install macOS onto a drive temporarily connected to the computer such as internal SSD or external USB, and then upgrade macOS within that system. See more here.
Tip: If you only have one computer, now is when you should copy this .html file into your hidden VeraCrypt volume. Once you boot into Tails, unlock your VC volume and open this file in Tails' Tor Browser to continue through this section. In Tails you will need to copy the .html file into the ~/Tor Browser folder. Find it as the Tor Browser shortcut in Files app side pane.
Tip: When booting into Tails, if you get stuck at a screen like Invalid Partition Table, just keep pressing Enter.
Note: Every time you boot into Tails you must choose an Administration Password via the Tails login screen. This is to be able to use HiddenVM, or perform certain Tails instructions in parts of the guide. It is only a temporary password for each Tails session, can change every time, and does not need to be a complex password if there is no imminent risk of physical seizure.
Warning: It is not recommended to have JavaScript enabled in the outer Tails Tor Browser. To read this guide more safely in Tails, set Tor Browser's SECURITY LEVEL to Safest, then open this .html file.
Warning: Unlike Whonix, Tails can access your real IP address. Malware via JavaScript, downloaded files, zero-day exploits, or security design defects have been known to leak your real IP address. If you have unlocked files in a Tails session, do not do web browsing or use any application in the outer Tails environment unless it is absolutely necessary. You can also reduce risk by using "Hidden Whonix" completely offline, which prevents any temporary IP-leaking malware from 'phoning home' even if it is running in Tails. Most Tails malware will only survive one session due to Tails' powerful amnesic design. More dangerous malware may trick you into entering your Tails admin password, so that it can inject permanent malware files into the Tails USB. Be very skeptical of entering your Tails admin password after you log in. Overall, these risks are very rare, but possible.
Tip: Before you install HiddenVM, it is a good idea to make a second Tails USB. Due to the complexity of running a VM on Tails, on extremely rare occasions Tails can lock up, and needs to be forcibly powered off. This can corrupt your Tails USB stick and make it become non-bootable. To get back into your HiddenVM with more privacy, keep a backup Tails stick to re-create your main Tails USB once more. To make a backup Tails, follow Tails' very quick process for cloning one Tails to another.
ver after pressing Win.) It can unlock much faster than the official VeraCrypt app because it has extra open-source code to better use AES acceleration.
Note: If you came from a Windows or macOS environment and you only have a VeraCrypt volume using exFAT or another non-Linux file system, now is the time to create an ext4 VeraCrypt volume on a different disk that you intend to be your main HiddenVM hard drive.
If you are coming from Linux and have not yet created an ext4 hidden VeraCrypt volume, now is the time to do this. If you already have one due to bringing over some existing files including an existing backed up Whonix, simply mount your existing volume and select it as your HiddenVM installation location below.
To create a VC volume in Tails, refer to the backup instructions.
Tip: HiddenVM allows you to persistently customize your Tails experience via its Extras and Dotfiles feature. You can have it install your own third-party programs each time it launches, and customize any setting in Tails GNOME that you can think of.
Tip: HiddenVM brings such a high level of safety that it is now safe to consider using another guest OS securely torified by a Gateway as an alternative to Whonix Workstation. It might be safe to do capping in Windows if you knew what you were doing.
Tip: If you already have a Whonix VM that you have set up, you don't need to follow all steps in this section. Refer to the handy Mini Migration Guide to Move an Existing Whonix Into HiddenVM, so that you don't have to start all over again.
Note: There is no need to install VirtualBox in Tails. It is already installed if you have launched HiddenVM.
Note: If there is an error saying Failed to import appliance, close off VirtualBox. Open VirtualBox again (find it by pressing the Win key in Tails and searching typing in virt), and importing will work the second time.
Tip: Keep a copy of the OVA Whonix file in case you need to start again or you ruined your current Whonix for some reason.
Tip: For the 100% paranoid, you can turn off VM 'Preview' in VirtualBox, to further prevent leakage of Whonix imagery to possible malware present in Tails. The risk is almost zero. Before you turn Whonix VM on, do the following: Single-click on any single VM in VirtualBox, right-click anywhere inside the main pane on the right-hand area of the program (underneath New, Settings, Discard, Start), and make sure the Preview menu item is unticked.
Tip: If you are comfortable enough with terminal, you can put the Gateway VM in CLI mode to free up over 1 GB of memory for Workstation VM. In Tails, memory is a precious resource.
Gateway only provides Internet for Workstation. Just a few basic commands are needed to maintain it. After you power on Gateway, you don't need to log into its terminal window for its Tor process to connect in the background. If you want to log in, the username is user and password changeme.
You will still have to periodically apply updates or check Gateway's Tor status when troubleshooting. The most common commands are: whonixcheck (then you read its output), sudo apt update && sudo apt full-upgrade if whonixcheck instructs you to, and if the Tor connection is not working just close off Gateway by doing sudo poweroff then start the VM again, no need to turn off Whonix-Workstation-XFCE during this process.
To set Gateway to CLI mode, in VirtualBox right-click on the Whonix-Gateway-XFCE VM and select Settings... and go to System. Change the Base memory down to 256 MB, then click OK.
However, do note that in order to perform system upgrades inside Gateway, you will need to temporarily assign the VM its default 1280 MB of RAM each time you do those updates.
You can also experiment with lowering the video memory to 16 MB.
Note: Power down Whonix-Workstation-XFCE before performing the steps under this entire 'Optimize Your VM' section.
Warning: Unless you know what you are doing, do not change any VM settings for your Whonix VMs apart from what's instructed in this guide. It could change settings in ways that completely deanonymize you.
Note: For Mac hardware, if you have a firmware password turned on you must temporarily turn it off in order to reset the NVRAM.
Tip: Ignore any warning messages if you set it past the orange levels. For top performance, set to full orange maxed out.
sudo -u clearnet vboxmanage modifyvm "Whonix-Workstation-XFCE" --vram 256 then confirm that it changed in the VirtualBox window.
sudo -u clearnet vboxmanage modifyvm "Whonix-Gateway-XFCE" --bioslogodisplaytime 1
"Whonix-Workstation-XFCE".
sudo sed -i 's+OUT=5+OUT=0+g' /etc/default/grub && sudo update-grub
Note: With Tails as the host OS and minimal use of Tails while using "Hidden Whonix", shared clipboard is extremely low risk. It is only worth disabling if you are 100% paranoid, or you do regular browsing in outer Tails Tor at the same time as Whonix (which is a very bad idea).
Tip: If a VM on Tails boots into a blank / black screen, try toggling full-screen on and off by pressing [Host Key]-F. It could be a temporary bug depending on your hardware.
Tip: If a VM starts to freeze up in Tails, immediately move out of the VM and into your outer Tails environment by pressing the [Host Key] and then Alt-Tab etc. Quickly do the following in Tails to force quit the VM: sudo -u clearnet gnome-system-monitor Then find the VirtualBoxVM item in the list pertaining to your frozen VM. (Hover mouse over its Process Name to see the VM name.) Click on the item and then End Process. You can now re-launch the VM from VirtualBox.
The cause of this issue may be having too little RAM in your computer or too much RAM being allocated to the VM. The inconvenience and reduction in stability due to the RAM-only environment of Tails is worth the massive security increase in leaving no forensic trace. To make your experience better, try to have as much RAM as possible.
sudo apt update && sudo apt full-upgrade sudo apt install xfce4-goodies gvfs gvfs-backends gvfs-fuse eject file-roller rar unrar unar tar zip unzip unace arj p7zip p7zip-full p7zip-rar liblzma-dev libwxgtk3.0-dev bzip2 gzip pulseaudio git gdebi software-properties-common exfat-fuse exfat-utils jq netcat xterm xdotool fonts-roboto firefox-esr -ysudo mv /usr/bin/gdebi-gtk{,.bak} && echo -e '#!/bin/bash\npkexec /usr/share/gdebi/gdebi-gtk "$@"' | sudo tee /usr/bin/gdebi-gtk && sudo chmod +x /usr/bin/gdebi-gtk && sudo cp /usr/share/polkit-1/actions/com.ubuntu.pkexec.gdebi-gtk.policy{,.bak} && sudo sed -i -e 's#/usr/bin/gdebi-gtk#/usr/share/gdebi/gdebi-gtk#g' -e 's#_active>auth_admin#_active>yes#g' /usr/share/polkit-1/actions/com.ubuntu.pkexec.gdebi-gtk.policy
sudo cp /usr/share/polkit-1/actions/org.freedesktop.UDisks2.policy{,.bak} && sudo sed -i -e 's#_active>auth_admin_keep#_active>yes#g' -e 's#_active>auth_admin#_active>yes#g' /usr/share/polkit-1/actions/org.freedesktop.UDisks2.policy
Warning: The above Terminal commands are a workaround for a longstanding bug affecting Whonix. While we wait for the bug to be fixed, this is the smoothest fix for your Whonix. Please be aware that this step turns off password authorization for the installation of .deb files in your Whonix OS and the manual GUI mounting of external drives, which brings a potential security risk, but with low a likelihood. This is not ideal, but for now it's the smoothest solution.
Note: If you do not follow all of the above steps in this section, many of the mini-guides or instructions in this entire Guide will not work. This post-install step is for making all how-to's more streamlined. Advanced users can avoid installing some of the packages if they know what they're doing.
sudo sed -i 's+#DefaultTimeoutStopSec=90s+DefaultTimeoutStopSec=10s+g' /etc/systemd/system.conf && sudo systemctl daemon-reload
Tip: There are further improvements you can make to Xfce in 'Further Tips, Tweaks, and How-To's' section, such as Make the Taskbar Better.
Note: A newer version of Xfce version (4.14) has now been released and it will finally bring proper display of fonts on HiDPI displays to make it as crisp as your Tails would look. But until Whonix 16, Xfce 4.14 probably won't be available.
Warning: If you are particularly concerned about browser fingerprinting, you need to do things very differently in your Whonix Tor Browser. You should disable JavaScript entirely in your Tor Browser by setting its SECURITY LEVEL to Safest. Visit http://panopticlick.eff.org to test your fingerprinting uniqueness if that is a metric that matters for your particular needs. Do consider that on a deeper level, completely disabling JavaScript can make you unique in a different way. It depends who you are trying to be more anonymous from. Sometimes you have to choose, or not do any Internet browsing at all. To most sharers, due to Whonix's robust anti IP leakage design, fingerprinting shouldn't be a concern. You might be 100% unique as a person being tracked by LEA, but you're still an anonymous unique person because your real IP is extremely hard to unmask.
changeme when asked, and finally click close, then it's ready to use.
ksuperkey && echo -e "[Desktop Entry]\nName=ksuperkey\nExec=ksuperkey\nType=Application\nMimeType=text/plain;\n" | sudo tee /etc/xdg/autostart/ksuperkey.desktop
4. Next, you can configure the Whisker Menu to be toggled by the single Win key. Open Keyboard from the Whisker Menu. In Application shortcuts tab, first remove the existing item called xfce4-popup-applicationsmenu, then add a new item with command xfce4-popup-whiskermenu and assigning it Alt-F1.sudo apt install fonts-unfonts-core fonts-ipafont-mincho fonts-arphic-ukai fonts-thai-tlwg fonts-indicsudo commands), by default in Whonix it's changemeNote: There's no serious security need to change Whonix's default Terminal password, but if you're paranoid about malware inside Whonix, customizing it may give you some security benefit.
y and press Enter."/you/can/put/quotations/around/the file path/like this.mp4". Another way to more easily work with a file: go to the folder in Thunar File Manager, right-click or go to File and then Open Terminal Here which opens a Terminal window with the working folder as the current one in Thunar. Now you can do commands as simple as mat2 -s filename.mp4 instead of mat2 -s "/long/cumbersome/path to/filename.mp4"Tip: After importing your original files into Whonix, you should clean them from any metadata attached to your previous OS. Firstly toggle to show hidden files to reveal compromising data files you should delete, then use the metadata stripping tool to clean your media files.
Note: Since v3.0 of the Guide, this section no longer involves installing the VirtualBox Extension Pack, which is a closed-source binary blob unlike the VirtualBox program itself. Now that we have Tails, the new method below is a much safer one. Tails is both open-source and amnesic. That makes it very low-risk for Tails to directly 'see' your files.
However, inside your VC volumes it would still be safer to store your files in Virtual Hard Disk VDI files which you can attach to your Whonix VM. This would ensure that even Tails cannot easily see your files. To do this, combine the instructions below with the VDI method instructed in the expanding storage section.
Note: In order for this to work, your external VC volumes must have an ext4 (or other ext*) file system. If it is another type like exFAT, you must use backup media to move it to another drive and then re-create your VC volume in Tails as ext4. To do this, refer to the backup instructions.
echo -e UUID=EXTERNAL-DRIVE-VERA-CRYPT-UUID /media/amnesia/HIDDENVM-MAIN-VERA-CRYPT-UUID/HiddenVM/ExpansionDrive1 ext4 defaults 0 2 | sudo tee -a /etc/fstab
Warning: JavaScript malware on an LEA-seized site could spy on your Whonix keystrokes. This is another warning to NEVER type in Whonix the same password or password style that you use to unlock a VC volume that is in your 'direct' physical possession and that can be 'directly' unlocked with that password. It would be safer and 'indirect' if it were a volume within a different volume with a different password that is never typed in your Whonix. It would be safer to unlock a direct VC volume in the Tails host.
changeme when asked, then finally clicking Close.Tip: When using VeraCrypt for personal cloud storage backup, to save space or upload / download time, you can first compress your files with 7-Zip compression (no archive password needed), then put the .7z file(s) into the hidden VeraCrypt volume file.
Tip: Sometimes all you have to do is select New Tor Circuit for this Site. Either find the menu item in top right-hand corner of Tor Browser, or press Ctrl-Shift-L on the page.
changeme when asked. During install, click on ‣ Terminal, then click inside the blue box area, then press Enter. When it's finished click close, then it's ready to use.Tip: Opera may hijack the default browser setting in Whonix (for when you click on a hyperlink from a non-browser program). To reset it back to Tor Browser you may have to do either or both of the following:
sudo update-alternatives --install /usr/bin/x-www-browser x-www-browser /usr/bin/torbrowser 200Note: Although you install Opera via a standalone DEB file, Opera intelligently adds its own repo to your Whonix APT so that it can update itself automatically going forward.
echo -e "[Desktop Entry]\nName=OpenVPN OVPN\nExec=xfce4-terminal -e \"bash -c 'echo changeme | sudo -S openvpn %F;$SHELL'\"\nType=Application\nMimeType=text/plain;\n" | sudo tee /usr/share/applications/openvpn-ovpn.desktopecho -e '#!/bin/bash\nxdg-open "$1"' | sudo tee /bin/openvpn-ovpn && sudo chmod +x /bin/openvpn-ovpnsudo killall openvpn)~/jd2/libs. Restart JDownloader if it's open, and now it's ready to use.Premium Alert - untick allSpecial Deals - untickBanner - untickoboom - untickDonate - set to Hidden (Automode)GraphicalUserInfaceSettings: Donate Button State - set to Hidden (Automode)
Tip: JDownloader saves all previously entered archive passwords for future auto-cracking and extracting, via its Password List feature in Settings. So once you build up your password list in JDownloader, downloading from frequent file uploaders becomes extremely painless. To add a list of file passwords you may already have collated elsewhere, go to JDownloader Settings > Archive Extractor, scroll down to Password List and paste them there.
Tip: Use JDownloader's File > Backup function to easily backup and restore your entire settings, passwords list, and even your unfinished download files.
Tip: In JDownloader's interface you can check the IP address being used for a downloading file in real-time. This is useful if you are using a VPN to bypass Tor IP blocking from a download host, and want to check if JDownloader is using the VPN IP. Click on the currently-downloading file (the sub-item), and hover the mouse on the modem icon. A popup will appear which will then load the IP.
Note: The below unpack script is not observed to be working at at Guide 3.0 launch. It will hopefully be fixed in a subsequent update.
sed -i -e "\$aPATH\=\/home\/user\/bin\:\$PATH" .bashrc && source .bashrc && mkdir -p /home/user/bin && cd /home/user/bin && touch unpack && sudo chmod +x unpack && mousepad unpack and a Mousepad empty text file window will open.#! /usr/bin/python
import sys, os, re, subprocess, argparse, json
from multiprocessing.pool import ThreadPool, cpu_count
from time import time
class Unpack:
input_path = '.'
pass_path = '/home/user/jd2/cfg/org.jdownloader.extensions.extraction.ExtractionExtension.passwordlist.json'
output_path = './'
trash_path = './trash/'
delete = False
CRED = '\033[91m'
CGRE = '\033[92m'
CEND = '\033[0m'
description = '''\
Extract password protected archives ending with .rar, .7z, and .zip
(case insensitive). Handles rar and 7z archives split into multiple
parts without tweaks. If no input archives are specified, the script
will try to extract all archives found under the current path while
ignoring other files. Passwords must be specified in a line separated
file, with one password per line and no extra whitespace. Overwrites
files with the same name as those in the archives.'''
i_help = 'Specify path for input archives (default "' + input_path + '")'
p_help = 'Specify path for password file (default "' + pass_path + '")'
o_help = 'Specify path for extracted files (default "' + output_path + '")'
t_help = 'Specify path for extracted archives (default "' + trash_path + '")'
r_help = 'Deletes extracted archives after successful extraction (overrides -t)'
archives = {'7z' : set(), 'rar' : set()}
filtered = {'7z' : set(), 'rar' : set()}
parts_of = dict()
passwords = set()
def __init__(self):
self.parser = argparse.ArgumentParser(prog='unpack', description=self.description)
self.parser.add_argument('-i', nargs='+', help=self.i_help)
self.parser.add_argument('-p', nargs=1, help=self.p_help)
self.parser.add_argument('-o', nargs=1, help=self.o_help)
self.parser.add_argument('-t', nargs=1, help=self.t_help)
self.parser.add_argument('-r', action='store_true', help=self.r_help)
self.args = self.parser.parse_args()
self.delete = self.args.r
self.__build_archive_dicts()
self.__build_password_set()
self.__set_output_path()
self.__set_trash_path()
self.FNULL = open(os.devnull, 'w')
self.threadpool = ThreadPool(processes=cpu_count())
def __set_trash_path(self):
if self.delete and self.args.t:
print '[Warning] Ignoring -t option (-r option used)'
return
if self.args.t:
self.trash_path = self.args.t[0]
if os.path.isfile(self.trash_path):
print "[Error] Is a file: '" + self.trash_path + "' (trash directory)"
sys.exit()
def __set_output_path(self):
if self.args.o:
self.output_path = self.args.o[0]
if os.path.isfile(self.output_path):
print "[Error] Is a file: '" + self.output_path + "' (output directory)"
sys.exit()
def __build_password_set(self):
if self.args.p:
self.pass_path = self.args.p[0]
try:
with open(os.path.expanduser(self.pass_path), 'r') as f:
f_content = f.read()
try:
self.passwords = set(json.loads(f_content))
except:
self.passwords = set(f_content.strip().split('\n'))
except Exception as e:
print e, '(password file)'
sys.exit()
def __build_archive_dicts(self):
paths = set(os.listdir(self.input_path) if not self.args.i else list(self.args.i))
files = set(filter(os.path.isfile, paths))
self.archives['7z'] = set(self.filter(r'(?i)(\.7z|\.zip|\.\d+)$', files))
self.archives['rar'] = set(self.filter(r'(?i)\.rar$', files))
self.filtered['7z'] = set(self.filter(r'(?i)(\.7z|\.zip|\.0*1)$', self.archives['7z']))
self.filtered['rar'] = set(self.filter_not(r'(?i)part(?!0*1\.)\d+\.rar$', self.archives['rar']))
self.__build_parts_of_dict('7z', r'\.\d+$', r'\.\d+')
self.__build_parts_of_dict('rar', r'(?i)\.part\d+(?=\.rar$)', r'\.[Pp][Aa][Rr][Tt]\d+')
for path in files - (self.archives['7z'] | self.archives['rar']):
print '[Warning] Not an archive:', path, '(wrong extension)'
def __build_parts_of_dict(self, extension, pattern, repl):
for archive in self.filtered[extension]:
regex = r'^' + re.escape(re.sub(pattern, '//', archive)).replace('\/\/', repl) + r'$'
parts = sorted(self.filter(regex, self.archives[extension]))
self.parts_of[archive] = filter(lambda p: len(p) == len(archive), parts)
def __find_password(self, archive):
start = time()
args = ['unrar', 't', '-o+'] if archive in self.archives['rar'] else ['7z', 't', '-aoa']
for password in self.passwords:
rc = subprocess.call(args + ['-p'+password, '--', archive], stdout=self.FNULL, stderr=self.FNULL)
if rc == 0:
return archive, password
return archive, None
def __unpack(self, archive, password):
args = ['7z', 'x', '-aoa', '-p'+password, '-o'+self.output_path, '--', archive]
if archive in self.archives['rar']:
args = ['unrar', 'x', '-o+', '-p'+password, '--', archive, self.output_path]
rc = subprocess.call(args, stdout=self.FNULL, stderr=self.FNULL)
return rc
def __make_dir(self, directory):
if not os.path.exists(os.path.dirname(directory)):
try:
os.makedirs(os.path.dirname(directory))
except OSError as e:
if e.errno != errno.EEXIST:
raise
def __trash(self, targets):
if self.delete:
return subprocess.call(['rm'] + targets)
else:
self.__make_dir(self.trash_path)
return subprocess.call(['mv'] + targets + [self.trash_path])
def unpack(self):
for archive, password in self.threadpool.imap_unordered(self.__find_password, self.parts_of):
if password != None:
print '[Extracting] ' + archive,
rc = self.__unpack(archive, password)
if rc == 0:
print self.CGRE + 'SUCCEEDED' + self.CEND
rc = self.__trash(self.parts_of[archive])
else:
print self.CRED + 'FAILED' + self.CEND
else:
print '[Warning] No password for: ' + archive + self.CRED + ' FAILED' + self.CEND
print '[Done]'
def filter(self, regex, sequence):
return filter(lambda x: re.findall(regex, x), sequence)
def filter_not(self, regex, sequence):
return filter(lambda x: not re.findall(regex, x), sequence)
start = time()
unpack = Unpack()
unpack.unpack()
print time()-start unpack and it will automatically crack and extract all archives in that directory, assuming you have all correct passwords listed in your JDownloader Password List.Note: unpack can take a long time, but it should work. If you have an incredibly long password list, it may take too long to be practical. Other password-cracking software may be superior.
Note: You may have to use a VPN inside Whonix for youtube-dl to work. YouTube seems to not like some Tor IP addresses.
youtube-dl --list-formats https://www.youtube.com/watch?v=ESD3mlgpSwM youtube-dl -f 22 https://www.youtube.com/watch?v=ESD3mlgpSwM /home/user), above Downloads.Note: Right now there appears to be a long delay when creating archives above a certain size using this method. Please discuss in an official support thread and perhaps we can find a reliable fix.
changeme when asked, then finally clicking Close.Tip: If you want to watch more than one video at a time, go to Tools > Preferences and untick Only use one instance when started from file manager.
sudo apt install tumbler tumbler-plugins-extra libtumbler-1-dev ffmpegthumbs ffmpegthumbnailer ffmpegthumbnailer-dbg libffmpegthumbnailer4v5 libffmpegthumbnailer-dev ooo-thumbnailer && thunar -qsudo apt install mediainfo-gui then it's ready to use.Tip: To see the full media info for your file, switch from the default Easy view by going to View > Text or HTML.
sudo apt install fslintsudo apt install geeqiesudo apt install ffmpeg libgdiplusTip: To manually assign your PrintScreen key or any other hotkey to activate the tool, open Keyboard from the Whisker Menu, go to the Application Shortcuts tab Add a new entry with command xfce4-screenshooter and click OK, and press the hotkey you'd like such as PrintScreen or Alt-P.
changeme when asked, then finally clicking Close, then it's ready to use.sudo apt install gimpchangeme when asked, then finally clicking Close.changeme when asked, then finally clicking Close.sudo apt install vokoscreen then it's ready to use.
Tip: For serious capping (e.g. to record a Skype chat while inside Whonix), try OBS Studio or for other alternatives, take a look here.
sudo apt install handbrake then it's ready to use. Note: After installing, HandBrake can hijack your default file association for some video file extensions. To reset those associations, open MIME Type Editor from the Whisker Menu, sort by Default Application column and scroll down to the list of HandBrake items and for each item single-click on HandBrake to pull up a menu to select your preferred media player instead.
sudo apt install ffmpeg meltmelt one.avi two.mov three.mpeg four.mp4 five.wmv six.mkv seven.ram eight.webm -consumer avformat:output.mp4 acodec=libmp3lame vcodec=libx264wget -q -O command that's instructed near the top, then come back here.sudo add-apt-repository 'deb https://mkvtoolnix.download/debian/ buster main' sudo apt update && sudo apt install mkvtoolnix mkvtoolnix-gui then it's ready to use. Find it as MKVToolNix GUI in the Whisker Menu.sudo apt install kdenlivesudo apt install handbrake ffmpegffmpeg -i trim.m4v result.gif -hide_bannerchangeme when asked, then finally clicking Close, then it's ready to use.gifsicle -O3 original.gif -o optimized.gif (which sets the optimization algorithms on strongest setting) or gifsicle --scale 0.5x0.5 original.gif -o resized.gif (to resize pixels to half size). Tip: Reducing size of animated GIFs is quite an art. See this guide for the various ways you can do it. This single-step command can only go so far.
sudo apt install smplayer mplayerNote: Depending on your hardware, to get this working you may need to go to Options > Preferences > General and set Multimedia engine: to mplayer (/usr/bin/mplayer), and also possibly in the Video tab, change Output driver: to x11 (slow).
Tip: To do bulk video file thumbnail creation, try Video Contact Sheet *NIX (vcs). Install via either their provided repo or this DEB. For help and usage examples, see their website or ask in a site's Tech forum.
changeme when asked, then finally clicking Close, then it's ready to use.mat2 dirty.mp4. It will create a 'cleaned' duplicate of the file ready to use. To verify the dirtiness of any file, do after this example: mat2 -s file.pdfNote: To further clean and sanitize PDFs, also try qpdf, pdfparanoia, and pdf-redact-tools. But be advised that the PDF format is complicated and provides a minefield of murky ways that someone can insert data to somehow watermark or deanonymize you. If your situation is serious, keep all documents that you share in plain text (TXT) format only.
Tip: To clean an entire folder of files at once (including its subfolders), open Terminal in the folder (right-click in Thunar then Open Terminal Here) and do: mat2 * Then, to remove all dirty files at once, do: find -type f -not -name '*cleaned*' -not -name '*.gif' -delete
sudo dpkg --add-architecture i386 && sudo apt update && sudo apt install wine wine32 playonlinux FIU, then click Next three more times. Click on the Browse button and point to your downloaded FileUploader.exe, click Next and go through FIU's first-run popups, then close FIU.Tip: When uploading, make sure to untick use account in the Add file(-s) dialog, or the upload may not work.
Tip: Simply click on a finished download in the queue list or press Ctrl-C while selected and its URL is instantly copied to the clipboard. Select multiple ones and do Ctrl-C to copy the list of all download URL at once.
Tip: If you use FIU a lot, be aware that it updates quite regularly similar to JDownloader's own auto-updates which add support for new hosts or apply fixes for handling them. With FIU you have to manually perform the update and you can do it from within the app at Help > Update. It will either allow you to update to a new version if available, or indicate that it's already the latest by saying This is up-to-date version .... You can check when the last update was issued by going to z-o-o-m.eu and compare it with your current version by going to Help > History and seeing the version number at the top of that changelog.
Tip: For more privacy and anonymity, go to Tools > Settings > Misc > Privacy, untick both checkboxes and click OK.
Note: when you minimize FIU it minimizes to the system tray instead of the taskbar. Click on its logo icon to restore the window again. To turn this behavior off permanently, go to Tools and untick Show tray icon.
changeme when asked, then finally clicking Close.~/MEGAsync/ and it will upload to the account.gpg --keyserver and gpg --export commands instructed near the top, then come back here.echo -e "deb http://www.lesbonscomptes.com/recoll/debian/ buster main\ndeb-src http://www.lesbonscomptes.com/recoll/debian/ buster main" | sudo tee /etc/apt/sources.list.d/recoll.list sudo apt update && sudo apt install recoll python-recoll python3-recoll python-lzma python-rarfile antiword libimage-info-perl python3-mutagen python-mutagen python-mutagen-doc python-chm unrtf untex xsltproc poppler-utils wv libwv-dev then it's ready to use.Note: To be able to open parent folders of search results in Thunar or a few other file types like PDF, the default setting doesn't work in Recoll. To fix, go to Preferences > GUI configuration > User Interface > Choose editor applications and click on the top Command column title twice to sort it. Look at the items which are not set to Desktop Default. For items incompatible with Xfce such as ones containing dolphin (for opening folders) or evince (for opening PDFs), simply double-click on them in the Command column and then Apply to current selection to reset to Xfce's default choice, or change the commands to Xfce equivalents like thunar
Tip: To filter by a file extension, do ext:mp4 (e.g. do ext:mp4 cum to find any MP4 videos with 'cum' in the title or in its metadata), do filename:fuck to filter to only files with fuck just in the file name (and not elsewhere like folder name), do dir:/this/folder (recursive) or -dir:/that/folder to restrict or exclude specific folders or parent folders from the results. Find more tips by going to Help > User manual.
Tip: If Recoll doesn't work well for you, try Searchmonkey (sudo apt install searchmonkey). It needs to do a manual search of your specified parent directory every time, but it works very reliably.
changeme when asked, then finally clicking Close.changeme when asked, then finally clicking Close.
sudo apt install libreofficeTip: To edit PDFs in Whonix, try LibreOffice Draw.
sudo apt install thunderbirdsudo apt in Terminal, or with a DEB file using GDebi Package Installer, in Terminal do: sudo apt remove <packagename>. But be careful. Read carefully what you're about to remove before you press y. Sometimes it can ask to remove dependencies which are needed by other packages. Choose to keep dependencies if you think they might be needed by other apps or if you are not sure.Warning: Sometimes APT can mistakenly think that a huge list of packages are no longer needed. This is a bug. As you can see in the below screenshot, it is telling you that you can remove packages including xfce4 which will actually remove Xfce from your Whonix and reduce it to command-line mode only.
NEVER perform sudo apt autoremove unless: 1. you're an advanced user and know what dependencies you're removing, and 2. you do a backup first.
scroll to find Use smooth scrolling and untick it. You can also experiment by searching for Performance and unticking Use recommended performance settings followed by unticking Use hardware acceleration when available.sudo apt install autokey-common autokey-gtk then it's ready to use.#AutoKey script to toggle any app like Thunar.
import subprocess
command = 'wmctrl -lx'
output = system.exec_command(command, getOutput=True)
if 'Thunar.Thunar' in output:
winClass = window.get_active_class()
if winClass == 'Thunar.Thunar':
system.exec_command("xdotool windowminimize $(xdotool getactivewindow)")
else:
system.exec_command("wmctrl -x -a Thunar.Thunar")
else:
system.exec_command("thunar")
#end scriptautokey in all three text boxes then click OK.if window.get_active_class() == 'Navigator.Tor Browser':
keyboard.send_keys("<ctrl>+<tab>")
elif window.get_active_class() == 'Navigator.Firefox-esr':
keyboard.send_keys("<ctrl>+<tab>")
elif window.get_active_class() == 'Opera.Opera':
keyboard.send_keys("<ctrl>+<tab>")
elif window.get_active_class() == 'chromium.Chromium':
keyboard.send_keys("<ctrl>+<tab>")
elif window.get_active_class() == 'sun-awt-X11-XFramePeer.JDownloader':
keyboard.send_keys("<ctrl>+<tab>")
else:
keyboard.send_keys("<ctrl>+<alt>+<page_down>")if window.get_active_class() == 'Navigator.Tor Browser':
keyboard.send_keys("<ctrl>+<shift>+<tab>")
elif window.get_active_class() == 'Navigator.Firefox-esr':
keyboard.send_keys("<ctrl>+<shift>+<tab>")
elif window.get_active_class() == 'Opera.Opera':
keyboard.send_keys("<ctrl>+<shift>+<tab>")
elif window.get_active_class() == 'chromium.Chromium':
keyboard.send_keys("<ctrl>+<shift>+<tab>")
elif window.get_active_class() == 'sun-awt-X11-XFramePeer.JDownloader':
keyboard.send_keys("<ctrl>+<shift>+<tab>")
else:
keyboard.send_keys("<ctrl>+<alt>+<page_up>")elif entries in the script.sudo apt install kcharselect then it's ready to use.changeme when asked, then finally clicking Close.Tip: To uninstall Skype, in Terminal do: sudo apt remove skypeforlinux
sudo apt install transmission then it's ready to use. Tip: For extra anonymity, go to Transmission > Edit> Preferences> Network and tick Pick a random port every time Transmission is started.
Tip: To have more success torrenting in Whonix, use a non-Tor IP (for both browsing torrent sites and then directly downloading in Transmission). The easiest way is to use a free VPN as instructed earlier. To verify that Transmission is using the non-tor IP address, use TorGuard's Check my Torrent IP service. Download the magnet link and the error message in Transmission will show your IP, which should be the one your VPN specifies (such as one from VPNGate).
Tip: Another option for torrenting inside Whonix may be to use a free online distributed seedbox service like bitport.io, zbigz.com, seedr.cc, transfercloud.io or filestream.me which you can sign up to with an anonymous email. Their seedboxes have have fully opened working ports and are much better placed in the Internet infrastructure for fast torrent downloading. Add a magnet link or .torrent URL on the free account, then when finished you can directly download the torrented file(s) over simple HTTP in your browser (or possibly JDownloader).
Warning: Do not use the same password or style of password for GPG keys in your Whonix as the password you use to unlock your hidden VeraCrypt volume to access your Whonix in the first place. Malware in Whonix - e.g. JavaScript code on an LEA-seized site - could spy on your keystrokes inside Whonix. Don't let them discover your VeraCrypt volume password in this way.
Note: For non-key pair (symmetrical) encryption of any file or data, please use VeraCrypt (and not PGP) which is the safest option for very sensitive data.
about:config into Firefox ESR URL bar, press Enter , search for network.proxy.no_proxies_on and set it to 0. Then go to http://127.0.0.1:8888/ to start using Freenet, and be patient (maybe several hours) to let it find peers and start connecting to that particular network. If you have trouble maybe ask on the Whonix forums. If you have success, please share in an official support thread.Tip: To uninstall Freenet, first run Shutdown Freenet from the Whisker Menu then in Terminal do: java -jar ~/Freenet/Uninstaller/uninstaller.jar
Warning: People running I2P web proxies can view everything you do through them. Only use them for basic eepsite browsing / downloading, and expect all login credentials you enter to be stolen or harvested by the proxy operators if they so choose to.
Warning: Live chat is a very easy way for your personality and writing style to be leaked, as you have no time to think about how you're writing and expressing yourself to others. You could be speaking to a law enforcement officer at any time, so please be aware of this potentially significant risk.
sudo apt install sabnzbdplushttp://localhost:8080/sabnzbd/ and follow the wizard guide to set up the client to start downloading your binaries.Note: With PlayOnLinux, an emulator for Windows apps in Linux, it may be possible to run apps like Windows Photoshop inside Whonix. A better option now would be to create a Windows VM on HiddenVM and run it alongside your Whonix, carefully disabling its network access in VirtualBox.
sudo apt install as well as the default included programs are automatically updated each time you do sudo apt update && sudo apt full-upgrade. Some of the versions issued by the 'Stable' repo are sometimes very old, but the benefit is that whenever updates do come, they are automatic.
sudo apt install partitionmanager && sudo sed -i 's+Exec=partitionmanager+Exec=pkexec partitionmanager+g' /usr/share/applications/org.kde.partitionmanager.desktopNote: Due to a current bug in Whonix 15, to set up KDE Partition Manager, you then need to do this second step:
sudoedit /usr/share/polkit-1/actions/com.ubuntu.pkexec.partitionmanager.policy
changeme into the password prompt, then an empty file in Mousepad will open. Copy the below text into the file, save it, and close it off:
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE policyconfig PUBLIC
 "-//freedesktop//DTD PolicyKit Policy Configuration 1.0//EN"
 "http://www.freedesktop.org/standards/PolicyKit/1/policyconfig.dtd">
<policyconfig>

 <action id="com.ubuntu.pkexec.partitionmanager">
 <message>Authentication is required to run KDE Partition Manager</message>
 <icon_name>partitionmanager</icon_name>
 <defaults>
 <allow_any>auth_admin</allow_any>
 <allow_inactive>auth_admin</allow_inactive>
 <allow_active>yes</allow_active>
 </defaults>
 <annotate key="org.freedesktop.policykit.exec.path">/usr/bin/partitionmanager</annotate>
 <annotate key="org.freedesktop.policykit.exec.allow_gui">true</annotate>
 </action>

</policyconfig>
changeme if asked, and it's now mounted for you to use like any other folder in Whonix for that session.Tip: If you do this as your principal method of Whonix storage expansion, you might want to set it to auto-mount at each Whonix startup and also mount to a specific folder location in Whonix. (Also, under this method, you should choose the arguably superior ext4 file system instead of exfat which is the more n00b-friendly option right now due to some GUI bugs.) In this example, it's a folder called called MyFiles under Home at the same level as Downloads and Desktop. In Terminal, do after the following example:
echo -e /dev/sdb1 /home/user/MyFiles ext4 defaults 0 0 | sudo tee -a /etc/fstab && mkdir /home/user/MyFiles && sudo mount -a && sudo chmod 777 /home/user/MyFiles
If you want to have spaces in the folder name of your mount path, you have to put the delimiter \040 for each space in the first instance of it in the Terminal command above, e.g. echo -e /dev/sdb1 /home/user/My\040Files for /home/user/My Files.
Note: Auto-mounting your Virtual Hard Disk in Whonix using the above tip has a caveat. If you somehow power on Whonix-Workstation-XFCE without it being able to access the VDI file (e.g. the storage media containing the file is not connected, you've deleted the file, or you've specifically detached it from the VM via VirtualBox settings), Whonix's internal Linux tries to mount the missing drive and fails, resulting in a command line-only troubleshooting 'emergency mode'. Luckily no data is lost, but to fix your Whonix you need to log into the emergency mode as root as suggested (input the usual changeme password), do nano /etc/fstab then use your arrow keys and backspace to remove the entire line that starts with /dev/sdb/ then save the file by pressing Ctrl-O then Enter then close off nano by pressing Ctrl-X, do reboot and it's fixed.
Warning: NEVER use the Gateway VM for file storage. That VM can see your real IP address and therefore associate it to any data you place inside its local file system. Read more here.
sudo update-rc.d -f <service_name> remove), and also /etc/systemd/system/ (delete in Terminal after this example: sudo systemctl disable <your_service>). Be careful with these commands and make a full backup of your VM files beforehand just in case.sudo apt install <packagename> method, or find a 64-bit .deb file to install it by double-clicking on it (opening with GDebi Package Installer) as the second best method.sudo apt install gdebi
ver). Create a hidden VeraCrypt volume out of a whole external disk using the Create a Hidden VeraCrypt Volume instructions.
Note: The transfer process between two highly secure VeraCrypt volumes like this can take hours depending on the speed of your USB / hard drive / CPU, but it's worth it for the safety it provides. Invest in a large USB drive, and back up your Whonix on a regular basis. You'll be thankful later.
This is a record of improvements or milestones of the guide. It does not always mention everything, but sometimes only big things.
2020-07-04:- Launch of Guide v3.0. Tails is now the mandatory host OS. HiddenVM is the tool that allows us to run Whonix on Tails. This is the biggest upgrade in safety since the launch of the original Guide. BIG moment!
2020-07-02:- In multiple locations in the guide, added important tip to never re-use your VC volume password anywhere else.
2020-06-30:- New instructions for using external drives with Whonix. Now simpler and safer method thanks to Tails.
2020-06-23:- Added tip for how to make VeraCrypt volumes larger than 2TB in size.
- Added ADVANCED TIP for how to move files between whonix and RL worlds more safely.
2019-10-18:- Added a how-to under 'Performance Optimizations' for speeding up VM boot time (remove splash and boot screens).
- Introduced new sharper font for 'Improve Whonix Appearance'.
- Added 'Prevent long shutdown' to a new 'Random Whonix Bugfixes' section.
2019-10-13:- Launch of v2.5 of the guide. Updated for Whonix 15, new screenshots, and more.
- Dropped support for macOS as a host OS.
2019-05-26:- Added a how-to 'Disable JavaScript on specific sites' in 'Post-Install Steps'
2019-04-22:- Added instructions for turning off advertisements in JDownloader.
2019-04-19:- Updated Setup instructions to reflect the Whonix Project's change of now offering the dual VMs in a single OVA file.
- Added Foxit Reader in the guide as an excellent PDF reader default for Whonix.
2019-04-07:- Updated the default recommended 'Image Viewing' program to XnView MP with provided customizations.
2019-03-01:- Bugfix in VirtualBox host OS install instructions.
- Now recommending to disable 3D / 2D acceleration for Workstation due to security advice. Thanks Old Lurker!
2019-02-01:- Updated the 'unpack' script (in JDownloader section) to not create an extra subdir for extracted files. Neater IMO.
- Added cool tip about JDownloader's backup/restore function in its mini-guide. Thanks Jamie_Boy!
- Added MediaInfo mini-guide for inspecting any media file.
2019-01-19:- Added a critical security step to the SETUP section, 'Turn off VM 'Preview' in VirtualBox'.
- Added instructions to Post-install Steps to enable languages like Korean to display properly in Whonix.
2019-01-12:- Image Viewer how-to improved with plugins add-on.
2019-01-04:- New Year's gift! Guide updated to v2.1 for Whonix 14 Xfce! Too many improvements to list. HUGE UPDATE. NOW WAY FASTER.
2018-12-25:- Christmas surprise! Guide now updated to v2.0, Whonix 14! Sorry, too many improvements and too little time to list them here. Just enjoy!
2018-07-31:- Added how to set a hotkey to toggle Dolphin/Terminal/any app in Whonix in the 'Further Tips' section.
2018-06-15:- Added the 'Virtual Hard Disk' how-to for expanding your Whonix storage.
2018-06-11:- Added how to back up your Whonix under 'Regularly Backup Your Whonix'.
2018-06-10:- Added how-to rotate videos (HandBrake, now 'Basic Video Editing').
2018-06-09:- Added tip for how to check the IP address in JDownloader.
- Added a mini-guide for 'Basic Image Editing'.
2018-06-08:- Added a tip for how to fix jerky video playback in VLC.
2018-06-07:- Added a suggestion tip for Mac hardware users to create a macOS bootable USB installer disk in 'SETUP'.
2018-05-31:- Added a post-install step to disable 'non-free' check (an annoying default pop-up).
2018-05-27:- Added a mini-guide for combining a video + subs into single MKV without reencoding.
2018-05-23:- Updated, cleaned up and finalized the SSD wiping section under 'SETUP'. It's now no longer a nightmare.
2018-03-13:- Added PeaUtils, a GUI tool for checksum/hash and join/split file.
2018-03-12:- Noted a current limitation of the archive file auto-crack and extract script.
2018-03-11:- Updated the method for creating archives to be much easier and now on-par with Windows. - Added a tip for how to view massive photo folders or collections in Whonix.
2018-03-06:- Added privacy tip to FIU mini-guide.
- Added tip about how to update FIU easily from within the app.
2018-03-04:- Added a script to auto-crack and extract files when JDownloader's workflow fails.
2018-03-02:- Made installing VirtualBox Extension Pack as a default instruction in the setup steps.
2018-03-01:- Added extra detail for how to protect hidden VeraCrypt volume when outer volume is mounted.
- Added a tip for how to make GIMP actually nice to use (like Photoshop).
- Made hint about Opera hijacking the default browser status and how to fix it.
2018-02-23:- Made the VPN method much better in the 'Unblock Sites That Block Tor IPs' mini-guide.
2018-02-22:- Added 'xterm' to post-install steps. - Clarified the 'The Internet has stopped working' FAQ adding details about what it can look like.
2018-02-21:- Improved and clarified instructions in the Setup section. - Added keyboard shortcut how-to for 'Shut down' (two options).
2018-02-20:- Added browser add-ons tip to 'My Whonix is starting to slow down' FAQ.
2018-02-19:- Launch.
[b][size=100][bgcolor=#563D7C][color=#166FA6][/color][color=#F7F7F7]"Hidden Whonix" Guide. Stop using Windows. Start being safe.[/color][color=#C13B5B][/color][/bgcolor][/size][/b]Note: This is when you should confirm that Tails works on your computer. Some hardware can be problematic such as newer Apple computers. Create a Tails USB, and test it out. If you're having problems, let us know in an official support thread and we will try to improve the guide with more pointers. If it just doesn't work, you may have to buy another computer to move to "Hidden Whonix".
Note: This is a very detailed set of instructions that will satisfy the most paranoid user possible. The only thing more secure than these steps - and you should actually consider it - is to physically destroy an existing SSD that has had unencrypted files on it.
You don't have to try all these steps. Decide what you'd like to do. All steps are included so that even the highest-level targets can refer to this. What you should do depends how paranoid you are, how much time you have, and how much money you have.
Tip: How do I boot from a USB? On most PCs, at bootup you repeatedly press either F12, F2 or Del to choose to boot from a USB Hard Disk. If that doesn't work, research online or find out by exploring your BIOS. On Mac hardware, hold down the alt key at bootup.
Warning: The following secure erase commands must be performed while the SSD is directly connected to the motherboard via internal cable such as SATA or PATA (IDE), otherwise the commands may permanently break the drive. If you want to securely wipe an SSD from an external enclosure, you must take it out and connect to your computer directly via SATA/IDE cable (instead of through USB / Firewire / SAS / SCSI / RAID card). Try the commands on a USB thumb drive (or USB-connected large external drive) but do so at your own risk, with possibly less risk by using the very latest version of hdparm.
Note: With many SSD models, the only way to create a bootable utility disk is via a Windows utility. So if you're not already coming from the Windows environment, you may have to install Windows just for this process, or in the case of a Mac, install a temporary Windows in VirtualBox or Parallels (or Boot Camp). Additionally, for Mac SSDs, there can be no official manufacturer utility compatible with the drive, depending on the SSD model.
apt update && apt install gdebi -y. Then download hdparm's Debian testing version here. Open the containing folder of the DEB file, right-click on it and select Open With Another Application. Select GDebi Package Installer. Click the blue Select button. It will guide you to install it.fdisk -l | grep "Disk /dev/sd" to carefully determine which disk in the list is the one you want to wipe, by checking their disk size. The examples below are for sda, but yours may be different.
dd if=/dev/urandom of=/dev/sda bs=1M. Wait for the screen to return from the flashing cursor to the normal prompt, and beware that this optional step could take hours (e.g. 9 hours for a 2 TB disk). It depends on the size of the SSD.
hdparm --yes-i-know-what-i-am-doing --sanitize-crypto-scramble /dev/sdahdparm --yes-i-know-what-i-am-doing --sanitize-block-erase /dev/sdahdparm --yes-i-know-what-i-am-doing --sanitize-overwrite --pattern=/dev/urandom /dev/sdahdparm -I /dev/sda | grep frozen
Tip: If you are still having trouble unfreezing the drive for hdparm, try some further methods posted online here and here. Further methods include hot re-plugging an SSD drive via either its SATA and/or power cable while Linux Mint is running. Also, you may need to enable AHCI in your computer's BIOS for it to work, read here.
hdparm --user-master u --security-mode m --security-set-pass 'temppassword' /dev/sda && hdparm -I /dev/sda and make sure the output shows enabled near the top, without a not before it.hdparm --user-master u --security-mode m --security-erase-enhanced 'temppassword' /dev/sdahdparm --user-master u --security-mode m --security-erase 'temppassword' /dev/sdahdparm -I /dev/sda and reading the output where it will say something like 9min for SECURITY ERASE UNIT. During command operation, wait for the Terminal to return to the normal command prompt, which is how you will know the process is done.Note: For further reference and information about all the above SSD wiping procedures, visit these four links.
Warning: If you have file data that was at any stage unencrypted on an SSD (not a magnetic HDD), then be aware that there are small possibilities that data traces can still be present in hard-to-erase areas in the SSD cells. This is extremely unlikely, but technically possible. There is no open-source software method or inexpensive at-home forensic procedure to verify for 100% sure that your data is irretrievable after performing the above steps. This concern is only applicable for users at the highest level, i.e. 10/10 paranoia. If you cannot afford to trust any form of data security outside the mathematics of open-source cryptography (and note that this concern also applies to HDDs), then you will have to physically destroy the disk, buy a brand new disk, and consider this an expensive education in file data safety.
Note: The animated GIF format was NOT invented for GIFs like the example above. It was meant for 3D vector-based animations in loop format like the 'live' logo images from websites in the 90's - not for photo-realistic, JPEG-type stuff like today's GIF memes. It took a long time to produce the example above - it's a miracle GIF - and it's still 3.5 MB, i.e. too big!
The actual image format of each frame in an animated GIF is lossless PNG. That's why file size reduction is difficult. Without the compression and lossy possibilities like JPEG, you have to save space in other weird ways like limiting color range (from 256 down to 64 or even 32), and generally being creative with your design.
sudo apt install <packagename>.sudo apt install imagemagick first), do: convert -coalesce original.gif %07d.jpg (Then move the original GIF into different folder to the split frames.)
num=0; for i in *; do mv "$i" "$(printf '%04d' $num).${i#*.}"; ((num++)); done then do in the frames folder: ffmpeg -framerate 10 -i %04d.jpg -c:v libx264 -profile:v high -crf 20 -pix_fmt yuv420p mp4export.mp4
ffmpeg -i mp4export.mp4 animated.gif
gifsicle -O3 animated.gif -o animated_o.gif then to reduce colors from 256 to 64: gifsicle --colors 64 animated_o.gif -o animated_o_c.gif (And do try 32, it may look OK enough and it saves decent space.)
convert -delay 10 -loop 0 *.jpg output.gif and for a longer / shorter pause between every frame, increase / decrease the delay number accordingly. This method makes far too big a GIF so instead I've instructed the mp4 intermediate step above.Note: These tips are based on the assumption the you already are using Whonix in Tails as per this guide and already taking into consideration every other tip and suggestion offered in the main Guide. These are only extra tips after all that.
hdparm --user-master u --security-mode m --security-set-pass 'mySEDpassword' /dev/sda. To use, at the beginning of each session to access your files, in Tails' Root Terminal do after this example: hdparm --security-unlock 'mySEDpassword' /dev/sda && partprobe. Tails can then access your hard drive as normal. The SED will remain unlocked through any other Tails reboots until you fully power off. To remove this feature and return the SED to work like a normal HDD again, unfreeze the drive once more then do after this example: hdparm --security-disable 'mySEDpassword' /dev/sda. Read these pages for reference and more info.
Tip: For a few reasons, it's suggested to upgrade major Whonix versions (such as 13 to 14, 14 to 15, etc.) by importing a new OVA instead of upgrading in-place your existing Workstation VM. Even if the risk is rare, it's a chance to discard any malware in the VM. It may speed it up if you have unused programs that are clogging up your autostart and shutdown scripts. It may also be necessary if the Whonix project advises it.
Tip: To enable Internet on multiple Gateway / Workstation pairs at the same time, in VirtualBox go to Gateway VM's Settings > Network > Adapter 2 and change Name: from Whonix to Whonix2 then click OK, then Workstation VM's Settings > Network > Adapter 1 and change Name: from Whonix to Whonix2. Then restart all VMs if necessary.
Tip: To see a list of every package you have installed in your old VM via APT or DEB file, do this in its Terminal: apt-mark showmanual | sort | grep -v -F -f <(apt show $(apt-mark showmanual) 2> /dev/null | grep -e ^Depends -e ^Pre-Depends | sed 's/^Depends: //; s/^Pre-Depends: //; s/(.*)//g; s/:any//g' | tr -d ',|' | tr ' ' '\n' | grep -v ^$ | sort -u)
sudo apt update && sudo apt full-upgrade. Try to ensure there are no more updates reported to perform by repeating that command again. To potentially fix a kernel update error, do: sudo dpkg --configure -a
~/.config/Thunar/uca.xml
~/.tb/tor-browser/Browser/TorBrowser/Data/Browser/ in Thunar File Manager and delete the profile.default folder.
~/.tb/tor-browser/Browser/TorBrowser/Data/Browser/profile.default/ folder into the new VM location.
~/.tb/tor-browser/Browser/.config/gtk-3.0/bookmarks.
~/.mozilla/firefox/ and overwrite it in the new VM, but rename it to the new profile folder name before starting up W15's Firefox ESR.
~/.config/opera/ folder.
~/.thunderbird/ folder. Create it in the new VM if it does not exist yet.
~/.config/libreoffice/4/user/ folder. Create it in the new VM if it does not exist yet.
~/.config/vlc/
~/.local/share/clipit/
~/.config/hexchat/
~/.config/autokey/data/
~/.config/ folder for other useful program config folders to copy over.
~/.config/autostart/