Re: Whonix 14 has been Released

Franz <[email protected]> Sat, 18 Aug 2018 07:54:17 -0300
Newsgroups gmane.os.qubes.user,gmane.network.tor.user,gmane.linux.debian.derivatives,gmane.comp.security.full-disclosure,gmane.technology.liberationtech
Message-ID <CAPzH-qAq-n2MGVK6F2E6wAda5B_fJgo4GxQSAFGp3bRgMXofXw@mail.gmail.com>
--00000000000070d4de0573b37f50
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Tue, Aug 7, 2018 at 7:17 AM, Patrick Schleizer <
patrick-mailinglists-hfd0J/[email protected]> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
>
> After more than two years of development, the Whonix Project is proud
> to announce the release of Whonix 14.
>
> Whonix 14 is based on the Debian stretch (Debian 9) distribution which
> was released in June 2017. This means users have access to many new
> software packages in concert with existing packages such as a modern
> branch of GNuPG, and more. [1][2][3]
>
> **Major Changes and New Features**
>
> Whonix 14 contains extensive security and usability improvements, new
> features and bug fixes. For a detailed description of these and other
> changes, please refer to the official release notes. [4]
>
> * Rebased Whonix on **Debian stretch** (Debian 9).
> * Whonix 14 is **64-bit** (amd64) only - 32-bit (i386) images will no
> longer be built and made available for download. [5]
> * The new **Anon Connection Wizard** [6] feature in Whonix simplifies
> connections to the Tor network via a Tor bridge and/or a proxy.
> * The Tor pluggable transport **meek_lite** [7] is now supported,
> making it much easier to connect to the Tor network in heavily
> censored areas, like China. [8]
> * **Onioncircuits** are installed by default in Whonix. [9]
> * Tails' **onion-grater** program has been implemented to enable
> **OnionShare, Ricochet and Zeronet** compatibility with Whonix. [10]
> * **Onion sources** are now preferred for Whonix updates/upgrades for
> greater security.
> * Reduced the size of the default, binary Whonix images by
> approximately **35 per cent** using zerofree. [11] [12]
> * **Updated Tor** to version 3.3.7 (stable) release to enable full v3
> onion functionality for both hosting of onion services and access to
> v3 onion addresses in Tor Browser.
> * Created the **grub-live package** [13] which can run Whonix as a
> **live system** on non-Qubes-Whonix platforms. [14]
> * Corrected and hardened various **AppArmor profiles** to ensure the
> correct functioning of Tor Browser, obfsproxy and other applications.
>
>
> **Known Issues**
>
> * Desktop shortcuts are no longer available in non-Qubes-Whonix.
> * OnionShare is not installed by default in Whonix 14 as it is not in
> the stretch repository. [15] It can still be manually installed by
> following the Whonix wiki instructions [16] or building it from source
> code. [17]
> * Enabling seccomp (Sandbox 1) in /usr/local/etc/torrc.d/50_user.conf
> causes the Tor process to crash if a Tor version lower than 0.3.3 is
> used. [18] [19]
>
>
> While there may be other issues that exist in this declared stable
> release, every effort has been made to address major known problems.
>
> Please report any other issues to us in the forums, after first
> searching for whether it is already known.
>
>   https://www.whonix.org/wiki/Known_Issues
>
> **Download Whonix 14**
>
> Whonix is cross-platform and can be installed on the Windows, macOS,
> Linux or Qubes operating systems. Choose your operating system from
> the link below and follow the instructions to install it.
>
>   https://www.whonix.org/download/
>
> **Upgrade to Whonix 14**
>
> Current Whonix users (or those with 32-bit hardware) who would prefer
> to upgrade their existing Whonix 13 platform should follow the upgrade
> instructions below.
>
>   https://whonix.org/wiki/Upgrading_Whonix_13_to_Whonix_14
>
> **What=E2=80=99s Next?**
>
> Work on Whonix 15 is ongoing and interested users can refer to the
> roadmap to see where Whonix is heading. [20]
>
> Developer priorities are currently focused on easing the transition to
> the next Debian release due in 2019 (=E2=80=9Cbuster=E2=80=9D; Debian 10)=
 and
> squashing existing bugs, rather than implementing new features.
>
> We need your help and there are various ways to contribute to Whonix -
> donating or investing your time will help the project immensely. Come
> and talk with us! [21]
>
> **References**
>
> [1] https://www.debian.org/News/2017/20170617
> [2] https://www.debian.org/releases/stable/amd64/release-notes/
> [3] https://www.debian.org/releases/stable/i386/release-notes/
> [4] https://whonix.org/wiki/Whonix_Release_Notes#Whonix_14
> [5] Whonix 13 users with 32-bit systems can however upgrade their
> platform by following the available wiki instructions, rather than
> download new Whonix-WS and Whonix-GW images.
> [6] https://whonix.org/wiki/Anon_Connection_Wizard
> [7] https://www.whonix.org/blog/meek_lite-whonix-14
> [8]
> https://github.com/Yawning/obfs4/commit/611205be681322883a4d73dd00fcb13c
> 4352fe53
> <https://github.com/Yawning/obfs4/commit/611205be681322883a4d73dd00fcb13c=
%0A4352fe53>
> [9] https://packages.debian.org/stretch/onioncircuits
> [10] https://phabricator.whonix.org/T657
> [11] https://phabricator.whonix.org/T790
> [12] VirtualBox .ova and libvirt qcow2 raw images. The Whonix-Gateway
> is reduced from 1.7 GB to 1.1 GB, while the Whonix-Workstation is
> reduced from 2 GB to 1.3 GB.
> [13] https://whonix.org/wiki/Whonix_Live
> [14] grub-live is optional and requires the user to first enable it
> manually.
> [15] https://packages.debian.org/search?searchon=3Dnames&keywords=3Donion=
sha
> re
> [16] https://whonix.org/wiki/Onionshare
> [17] https://github.com/micahflee/onionshare/blob/master/BUILD.md#gnulin
> ux
> [18] https://trac.torproject.org/projects/tor/ticket/22605
> [19] https://packages.debian.org/stretch/tor
> [20] https://phabricator.whonix.org/maniphest/query/open/
> [21] https://forums.whonix.org
>

Many thanks for the hard work.
My upgrade to Whonix 14/Qubes 3.2  worked, but only if sys-whonix depends
on template whonix-gw, but if it depends on template whonix-gw-14 which
would seem more appropriate to me, then it is unable to connect to Tor.

--=20
You received this message because you are subscribed to the Google Groups "=
qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to qubes-users+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/[email protected]
To post to this group, send email to qubes-users-/JYPxA39Uh5TLH3MbocFF+G/[email protected]
To view this discussion on the web visit https://groups.google.com/d/msgid/=
qubes-users/CAPzH-qAq-n2MGVK6F2E6wAda5B_fJgo4GxQSAFGp3bRgMXofXw%40mail.gmai=
l.com.
For more options, visit https://groups.google.com/d/optout.

--00000000000070d4de0573b37f50
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo=
te">On Tue, Aug 7, 2018 at 7:17 AM, Patrick Schleizer <span dir=3D"ltr">&lt=
;<a href=3D"mailto:patrick-mailinglists-hfd0J/[email protected]" target=3D"_blank">patri=
ck-mailinglists-hfd0J/[email protected]</a>&gt;</span> wrote:<br><blockquote class=3D"gm=
ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,=
204,204);padding-left:1ex">-----BEGIN PGP SIGNED MESSAGE-----<br>
Hash: SHA512<br>
<br>
After more than two years of development, the Whonix Project is proud<br>
to announce the release of Whonix 14.<br>
<br>
Whonix 14 is based on the Debian stretch (Debian 9) distribution which<br>
was released in June 2017. This means users have access to many new<br>
software packages in concert with existing packages such as a modern<br>
branch of GNuPG, and more. [1][2][3]<br>
<br>
**Major Changes and New Features**<br>
<br>
Whonix 14 contains extensive security and usability improvements, new<br>
features and bug fixes. For a detailed description of these and other<br>
changes, please refer to the official release notes. [4]<br>
<br>
* Rebased Whonix on **Debian stretch** (Debian 9).<br>
* Whonix 14 is **64-bit** (amd64) only - 32-bit (i386) images will no<br>
longer be built and made available for download. [5]<br>
* The new **Anon Connection Wizard** [6] feature in Whonix simplifies<br>
connections to the Tor network via a Tor bridge and/or a proxy.<br>
* The Tor pluggable transport **meek_lite** [7] is now supported,<br>
making it much easier to connect to the Tor network in heavily<br>
censored areas, like China. [8]<br>
* **Onioncircuits** are installed by default in Whonix. [9]<br>
* Tails&#39; **onion-grater** program has been implemented to enable<br>
**OnionShare, Ricochet and Zeronet** compatibility with Whonix. [10]<br>
* **Onion sources** are now preferred for Whonix updates/upgrades for<br>
greater security.<br>
* Reduced the size of the default, binary Whonix images by<br>
approximately **35 per cent** using zerofree. [11] [12]<br>
* **Updated Tor** to version 3.3.7 (stable) release to enable full v3<br>
onion functionality for both hosting of onion services and access to<br>
v3 onion addresses in Tor Browser.<br>
* Created the **grub-live package** [13] which can run Whonix as a<br>
**live system** on non-Qubes-Whonix platforms. [14]<br>
* Corrected and hardened various **AppArmor profiles** to ensure the<br>
correct functioning of Tor Browser, obfsproxy and other applications.<br>
<br>
<br>
**Known Issues**<br>
<br>
* Desktop shortcuts are no longer available in non-Qubes-Whonix.<br>
* OnionShare is not installed by default in Whonix 14 as it is not in<br>
the stretch repository. [15] It can still be manually installed by<br>
following the Whonix wiki instructions [16] or building it from source<br>
code. [17]<br>
* Enabling seccomp (Sandbox 1) in /usr/local/etc/torrc.d/50_<wbr>user.conf<=
br>
causes the Tor process to crash if a Tor version lower than 0.3.3 is<br>
used. [18] [19]<br>
<br>
<br>
While there may be other issues that exist in this declared stable<br>
release, every effort has been made to address major known problems.<br>
<br>
Please report any other issues to us in the forums, after first<br>
searching for whether it is already known.<br>
<br>
=C2=A0 <a href=3D"https://www.whonix.org/wiki/Known_Issues" rel=3D"noreferr=
er" target=3D"_blank">https://www.whonix.org/wiki/<wbr>Known_Issues</a><br>
<br>
**Download Whonix 14**<br>
<br>
Whonix is cross-platform and can be installed on the Windows, macOS,<br>
Linux or Qubes operating systems. Choose your operating system from<br>
the link below and follow the instructions to install it.<br>
<br>
=C2=A0 <a href=3D"https://www.whonix.org/download/" rel=3D"noreferrer" targ=
et=3D"_blank">https://www.whonix.org/<wbr>download/</a><br>
<br>
**Upgrade to Whonix 14**<br>
<br>
Current Whonix users (or those with 32-bit hardware) who would prefer<br>
to upgrade their existing Whonix 13 platform should follow the upgrade<br>
instructions below.<br>
<br>
=C2=A0 <a href=3D"https://whonix.org/wiki/Upgrading_Whonix_13_to_Whonix_14"=
 rel=3D"noreferrer" target=3D"_blank">https://whonix.org/wiki/<wbr>Upgradin=
g_Whonix_13_to_Whonix_<wbr>14</a><br>
<br>
**What=E2=80=99s Next?**<br>
<br>
Work on Whonix 15 is ongoing and interested users can refer to the<br>
roadmap to see where Whonix is heading. [20]<br>
<br>
Developer priorities are currently focused on easing the transition to<br>
the next Debian release due in 2019 (=E2=80=9Cbuster=E2=80=9D; Debian 10) a=
nd<br>
squashing existing bugs, rather than implementing new features.<br>
<br>
We need your help and there are various ways to contribute to Whonix -<br>
donating or investing your time will help the project immensely. Come<br>
and talk with us! [21]<br>
<br>
**References**<br>
<br>
[1] <a href=3D"https://www.debian.org/News/2017/20170617" rel=3D"noreferrer=
" target=3D"_blank">https://www.debian.org/News/<wbr>2017/20170617</a><br>
[2] <a href=3D"https://www.debian.org/releases/stable/amd64/release-notes/"=
 rel=3D"noreferrer" target=3D"_blank">https://www.debian.org/<wbr>releases/=
stable/amd64/release-<wbr>notes/</a><br>
[3] <a href=3D"https://www.debian.org/releases/stable/i386/release-notes/" =
rel=3D"noreferrer" target=3D"_blank">https://www.debian.org/<wbr>releases/s=
table/i386/release-<wbr>notes/</a><br>
[4] <a href=3D"https://whonix.org/wiki/Whonix_Release_Notes#Whonix_14" rel=
=3D"noreferrer" target=3D"_blank">https://whonix.org/wiki/<wbr>Whonix_Relea=
se_Notes#Whonix_14</a><br>
[5] Whonix 13 users with 32-bit systems can however upgrade their<br>
platform by following the available wiki instructions, rather than<br>
download new Whonix-WS and Whonix-GW images.<br>
[6] <a href=3D"https://whonix.org/wiki/Anon_Connection_Wizard" rel=3D"noref=
errer" target=3D"_blank">https://whonix.org/wiki/Anon_<wbr>Connection_Wizar=
d</a><br>
[7] <a href=3D"https://www.whonix.org/blog/meek_lite-whonix-14" rel=3D"nore=
ferrer" target=3D"_blank">https://www.whonix.org/blog/<wbr>meek_lite-whonix=
-14</a><br>
[8]<br>
<a href=3D"https://github.com/Yawning/obfs4/commit/611205be681322883a4d73dd=
00fcb13c%0A4352fe53" rel=3D"noreferrer" target=3D"_blank">https://github.co=
m/Yawning/<wbr>obfs4/commit/<wbr>611205be681322883a4d73dd00fcb1<wbr>3c<br>
4352fe53</a><br>
[9] <a href=3D"https://packages.debian.org/stretch/onioncircuits" rel=3D"no=
referrer" target=3D"_blank">https://packages.debian.org/<wbr>stretch/onionc=
ircuits</a><br>
[10] <a href=3D"https://phabricator.whonix.org/T657" rel=3D"noreferrer" tar=
get=3D"_blank">https://phabricator.whonix.<wbr>org/T657</a><br>
[11] <a href=3D"https://phabricator.whonix.org/T790" rel=3D"noreferrer" tar=
get=3D"_blank">https://phabricator.whonix.<wbr>org/T790</a><br>
[12] VirtualBox .ova and libvirt qcow2 raw images. The Whonix-Gateway<br>
is reduced from 1.7 GB to 1.1 GB, while the Whonix-Workstation is<br>
reduced from 2 GB to 1.3 GB.<br>
[13] <a href=3D"https://whonix.org/wiki/Whonix_Live" rel=3D"noreferrer" tar=
get=3D"_blank">https://whonix.org/wiki/<wbr>Whonix_Live</a><br>
[14] grub-live is optional and requires the user to first enable it<br>
manually.<br>
[15] <a href=3D"https://packages.debian.org/search?searchon=3Dnames&amp;key=
words=3Donionsha" rel=3D"noreferrer" target=3D"_blank">https://packages.deb=
ian.org/<wbr>search?searchon=3Dnames&amp;<wbr>keywords=3Donionsha</a><br>
re<br>
[16] <a href=3D"https://whonix.org/wiki/Onionshare" rel=3D"noreferrer" targ=
et=3D"_blank">https://whonix.org/wiki/<wbr>Onionshare</a><br>
[17] <a href=3D"https://github.com/micahflee/onionshare/blob/master/BUILD.m=
d#gnulin" rel=3D"noreferrer" target=3D"_blank">https://github.com/micahflee=
/<wbr>onionshare/blob/master/BUILD.<wbr>md#gnulin</a><br>
ux<br>
[18] <a href=3D"https://trac.torproject.org/projects/tor/ticket/22605" rel=
=3D"noreferrer" target=3D"_blank">https://trac.torproject.org/<wbr>projects=
/tor/ticket/22605</a><br>
[19] <a href=3D"https://packages.debian.org/stretch/tor" rel=3D"noreferrer"=
 target=3D"_blank">https://packages.debian.org/<wbr>stretch/tor</a><br>
[20] <a href=3D"https://phabricator.whonix.org/maniphest/query/open/" rel=
=3D"noreferrer" target=3D"_blank">https://phabricator.whonix.<wbr>org/manip=
hest/query/open/</a><br>
[21] <a href=3D"https://forums.whonix.org" rel=3D"noreferrer" target=3D"_bl=
ank">https://forums.whonix.org</a><br>
</blockquote><div><br></div><div>Many thanks for the hard work.<br></div></=
div>My upgrade to Whonix 14/Qubes 3.2=C2=A0 worked, but only if sys-whonix =
depends on=20
template whonix-gw, but if it depends on template whonix-gw-14 which=20
would seem more appropriate to me, then it is unable to connect to Tor.</di=
v></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;qubes-users&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:qubes-users+unsubscribe-/[email protected]">qubes-u=
sers+unsubscribe-/[email protected]</a>.<br />
To post to this group, send email to <a href=3D"mailto:qubes-users@googlegr=
oups.com">qubes-users-/[email protected]</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/d/msgid/qubes-users/CAPzH-qAq-n2MGVK6F2E6wAda5B_fJgo4GxQSAFGp3bRgMXofXw%=
40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.goo=
gle.com/d/msgid/qubes-users/CAPzH-qAq-n2MGVK6F2E6wAda5B_fJgo4GxQSAFGp3bRgMX=
ofXw%40mail.gmail.com</a>.<br />
For more options, visit <a href=3D"https://groups.google.com/d/optout">http=
s://groups.google.com/d/optout</a>.<br />

--00000000000070d4de0573b37f50--