[tor-talk] Use of TBB behind a physically isolated Tor router?

Lolint lolint at protonmail.com
Mon May 22 09:27:23 UTC 2017


> Even with software isolation though I am beginning to think that hardware isolation
when implemented properly is more secure than software isolation, with all the Xen
bugs recently.

The Qubes OS team are going to ditch paravirtualization for hardware-based virtualization
since all the fatal Xen bugs that affected Qubes have been in mechanisms for handling
memory virtualization for paravirtualized (PV) VMs.

> Is there any comments on the way Whonix gateway and TBB work together?

In the Whonix workstation they use this package to prevent Tor over Tor with the TBB,

https://github.com/Whonix/anon-ws-disable-stacked-tor

Its implementation is well documented here,

https://www.whonix.org/wiki/Dev/anon-ws-disable-stacked-tor#Why.3F


More information about the tor-talk mailing list