Jump to: navigation, search

Comparison of different Whonix variants

This page contains changes which are not marked for translation.

Other languages:
Deutsch • ‎English

Comparison of different Whonix variants[edit]

Related to Virtualization or Hardware[edit]

Name Number of systems Security Usability
Standard Download version host+VM+VM=3 Basic. Easily redistributable and installable.
Physical Isolation with bare metal Gateway host+VM+host=3 Stronger than Standard Download version. Difficult to install, advanced users only.
Physical Isolation with virtualized Gateway host+VM+host+VM=4 Higher attack surface. Easier to deploy. Four operating systems must be kept updated.
Physical Isolation without any virtualization host+host=2 Basically same as standard Physical Isolation.; [1] Smaller attack surface because:
  • not using Virtual Machines.
  • No protection against hardware fingerprinting.
Difficult to install, advanced users only.
Qubes dom0+VM+VM=3 Better compartmentalization. See Why use Qubes over other Virtualizers? Best.

Virtual machines can provide following security related features:

  • Network isolation (connections can easily be forced through tor)
  • Hardware isolation (hide unique hardware serials)
  • Roll back feature
  • Cheap and simple multi-level security through running multiple clones/VMs

Live CDs offer:

  • Non-persistence in case of software compromises
  • Anti-Forensics and deniability (no encryption keys to disclose, if it is powered down and RAM is wiped/faded everything is "gone")
  • But: difficult to roll out security updates

Related to Operating System[edit]

Multiple options for operating system.

Security Comparison: Whonix-Download-Workstation vs. Whonix-Custom-Workstation[edit]

See Security Comparison: Whonix-Download-Workstation vs. Whonix-Custom-Workstation.

Unless otherwise stated, the documentation and design is about the Default-Download-Version.


  1. See forum topic More or Less Protection inside a VM? for some more discussion.

Random News:

Love Whonix and want to help spread the word? You can start by telling your friends or posting news about Whonix on your website, blog or social media.

Impressum | Datenschutz | Haftungsausschluss

https | (forcing) onion
Share: Twitter | Facebook | Google+
This is a wiki. Want to improve this page? Help is welcome and volunteer contributions are happily considered! See Conditions for Contributions to Whonix, then Edit! IP addresses are scrubbed, but editing over Tor is recommended. Edits are held for moderation. Whonix (g+) is a licensee of the Open Invention Network. Unless otherwise noted, the content of this page is copyrighted and licensed under the same Libre Software license as Whonix itself.