Jump to: navigation, search


Random News:

Join us testing new AppArmor profiles for improved security! (forum discussion)

Other languages:
English • ‎español • ‎русский

First time user?[edit]

Download Whonix[edit]


Note: You need to download both Gateway and Workstation virtual machine images.

(1.5 GB)
(1.6 GB)
Anonymous Download
possible [1]
Download Security
without Verification
Download Security
with Verification
[2] [3]
Download Easy Download Easy Yes [1] Very Low [4] High [5]
Button sig.png OpenPGP Signature

( sha512, sig)

OpenPGP Signature

( sha512, sig)

Yes [1] - -
Crypto key.png Verify the images using the Signing Key Yes [1] - -
Btorrent-icon.png[6] Torrent Download

( sig)

Torrent Download

( sig)

No Medium [7] High [5]
Onion1.png [8] Onion Download Onion Download Yes [1] Low High [5]
Template source.png Build from source code See Build Anonymity Very High [9] Best [9] [10]

Verify the Whonix images[edit]

It is important to check the integrity of the virtual machine images you downloaded to make sure no man-in-the-middle attack or file corruption happened. (See Download Security.)

Whonix virtual machine images are cryptographically signed using OpenPGP[11] by Whonix developer Patrick Schleizer.

If you know how to use an OpenPGP key, download the Whonix Signing Key and the Whonix signatures straight away.

Otherwise, follow the instructions:

Install Whonix[edit]

Before installing[edit]

Read and apply the Security Advice.


  • Install VirtualBox.
    • Windows: Download VirtualBox and install. [12]
    • Linux and others: sudo apt-get install virtualbox linux-headers-$(uname -r) to install virtualbox.
  • Download Whonix and import both Whonix images[13] into VirtualBox. Do not change any settings when importing!

In case you need help[edit]

There is a tutorial with screenshots, see VirtualBox import instructions.

There are also Video Tutorials.

If you still need help, please check the Support page.

After installing[edit]

Read and apply the Post Install Advice.

Stay tuned[edit]


Reading the latest news is important to stay on top of latest developments. Should security vulnerabilities ever be found in Whonix, any major issues (such as with the updater) happen or should an improved version be released, you should be informed.

Whonix News Blogs[edit]

For your convenience, there are multiple choices to get news. Choose at your preference.

  1. Whonix Important Blog Whonix Important Blog Rss - Most important stuff only. Security vulnerabilities and new stable versions only. For people with very limited time and interest in Whonix development and news.
  2. Whonix Feature Blog Whonix Feature Blog rss - Includes everything from Whonix Important Blog. Also testers-only and developers versions are announced. Has a relaxed posting policy. Also blog posts about updated articles, new features, future features, development, call for testing, general project thoughts and so on will be published.
  3. Other choices. [14]

It's recommended at least to read Whonix Important Blog if you are in a hurry. Have a look into Whonix Feature Blog if you are generally interested to learn about anonymity/privacy/security related things or to see what's going on with Whonix.

Operating System Updates[edit]

You should regularly check for operating system updates on your host operating system, on Whonix-Workstation and on Whonix-Gateway as highly recommended in the Security Guide.

Tor Browser[edit]

There is no auto-update feature for Tor Browser. You will be notified about new Tor Browser versions by whonixcheck. Tor Browser's built in update check mechanism also works in Whonix. For instructions how to update the browser, see Tor Browser. Additionally it might also be wise to subscribe to https://blog.torproject.org for news.

Whonix Version Check and Whonix News[edit]

whonixcheck graphical user interface screnshot
Whonix Version Check (first rectangle in black) and
Whonix News
(second rectangle in green)

Furthermore you will be automatically notified about new Whonix versions by Whonix Version Check and about the most important occurrences[15] by Whonix News, both of which are part of whonixcheck.

Social Media Profiles[edit]

There are some Whonix Social Media Profiles, but please don't rely on them for getting Whonix News and please don't use them to contact Whonix developers. (See Contact for contact information.)

Because some people will do so even though it is not recommended, messages from the Whonix Feature Blog will be automatically mirrored to Whonix Twitter Profile, to Whonix Facebook Profile and to Whonix Google+ Profile.

If you won't get into trouble by letting others learn about Whonix, feel free to follow or like those profiles (with your anonymous account) as a little way to Contribute. You can share this page on: Twitter | Facebook | Google+.

Source Code[edit]

In case you are interested in Whonix source code updates, subscribe to code changes.

Known bugs[edit]


Mounting (CD/DVD) Devices[edit]

You can use the following workaround.

sudo mkdir /mnt/cdrom
sudo mount -o ro /dev/cdrom /mnt/cdrom/

Using the ro flag will mount the CD/DVD read-only.

Help fixing this bug is welcome! (ticket)

VLC / Video Player Crash[edit]

You can use this workaround.

VLC -> Tools -> Preferences -> Video -> Output -> X11 -> Save


libtorsocks Warning[edit]

During running apt-get dist-upgrade, you may see a warning similar to the following one.

15:36:37 libtorsocks(12225): sendmsg: Connection is a UDP or ICMP stream, may be a DNS request or other form of leak: rejecting.
Cannot talk to rtnetlink: No such file or directory
acpid: error talking to the kernel via netlink

Sounds scary, but is of no concern. See footnote for technical explanation. [16]

"apt-get source package" will show "dpkg-source: warning: failed to verify signature"[edit]

This is not a security issue. It is only a warning. More info here (and in the following mails).

If you want, you can get rid of it with the following workaround.

1. Modify /etc/dpkg/origins/default.

sudo unlink /etc/dpkg/origins/default
sudo ln -s /etc/dpkg/origins/debian /etc/dpkg/origins/default

2. apt-get source package

3. Undo afterwards to prevent unexpected issues.

sudo unlink /etc/dpkg/origins/default
sudo ln -s /etc/dpkg/origins/whonix /etc/dpkg/origins/default

Proxychains Tor Browser Issue[edit]

Want to use proxychains for the connection scheme user -> Tor -> proxy? This currently won't work. For more information, see Tunnel_Proxy_or_SSH_or_VPN_through_Tor#Tor_Browser.


  1. 1.0 1.1 1.2 1.3 1.4 By using the Tor Browser Bundle (TBB). For an introduction, see Tor Browser. See also Hide Tor and Whonix from your ISP.
  2. Unencrypted, unauthenticated http.
  3. Fallback mirror if the current one is unaccessible, try this one: http://whonix.thecthulhu.com
  4. Man-in-the-middle attacks could poison the download.
  5. 5.0 5.1 5.2 It does not matter if you did the bulk download over an insecure channel, if you use OpenPGP verification at the end.
  6. Torrent clients known to work: transmission, Vuze, Deluge. Check this clients table. If nobody is seeding at the time, only clients with the "as" feature can be used, because we are providing a webseed.
  7. It's at least as secure as SSL and SHA-1, better than plain http. This is because you get the torrent file or magnet link over https and the torrent/magnet client checks the SHA-1 checksum at the end. Using OpenPGP verification would be safer.
  8. You need Tor to be able to download over .onion (Tor Browser, Whonix, Tails, etc.)
  9. 9.0 9.1 When you build from source code, audit the source code for being non-malicious and reasonably bug free, you do not have to Trust the developers, the website or the SSL certificate authorities.
  10. By additional verification that you got the source code from the original authors and by ensuring you're using the same source code as others you get better security.
  11. OpenPGP is a standard for data encryption that provides cryptographic privacy and authentication through the use of keys owned by its users.
  12. You could alternatively search for Portable VirtualBox.
  13. You need both Whonix-Gateway.ova and Whonix-Workstation.ova images. Whonix is a two machine setup.
  14. Other choices.
  15. Such as when a version becomes unsupported, if manual action is required, if major features break, or if security vulnerabilities are found. The policy is to use Whonix News as rarely as possible.
  16. This is because in order to implement Stream Isolation, Whonix's apt-get uwt wrapper forces apt-get through torsocks. Unfortunately, not only apt-get is forced through Tor, but also sysvinit and subsequently all daemons sysvinit is restarting. acpi_fakekey daemon uses local connections. Those will be rejected by torsocks. The worst that can happen is that acpi_fakekey won't operate until manually restarted. This is a bigger issue for web servers and alike, because those may not function until manually restarted. This will likely be fixed as soon Whonix will be based on Debian jessie, because that uses systemd, that is not affected by this as well as torsocks 2.0 may solve this.


Whonix Download wiki page Copyright (C) Amnesia <amnesia at boum dot org>
Whonix Download wiki page Copyright (C) 2012 -2014 Patrick Schleizer <adrelanos@riseup.net>

This program comes with ABSOLUTELY NO WARRANTY; for details see the wiki source code.
This is free software, and you are welcome to redistribute it
under certain conditions; see the wiki source code for details.
Some icons created by third parties, Free licenses as well, see Authorship Images created by third parties for details.

Log in | OpenID | Contact | Impressum | Datenschutz | Haftungsausschluss | Investors | Donate

https | Mirror | Mirror | Share: Twitter | Facebook | Google+

This is a wiki. Want to improve this page? See Conditions for Contributions to Whonix, then Edit! IP addresses are scrubbed, but editing over Tor is recommended. Edits are held for moderation.

Whonix (g+) is a licensee of the Open Invention Network. Unless otherwise noted above, content of this page is copyrighted and licensed under the same Free (as in speech) license as Whonix itself.