Last update: March 17, 2019. This website uses cookies. By using our website, you acknowledge that you have read, understood and agreed to our Privacy Policy, Cookie Policy, Terms of Service, and E-Sign Consent. More information

 Actions

Whonix ™ for VirtualBox with XFCE

< VirtualBox

1. Download Whonix Whonix old logo.png XFCE for Windows Windows logo - 2012.svg.png, Mac Rsz osx.png and Linux Tux.png FREE



Version: 14.0.1.4.4

Whonix
Anonymous Download
Possible [4]
Download Security
without Verification
Download Security
with Verification
Https long.png

Download

Yes [4] Medium High [5]
Button sig.png

OpenPGP Signature ( sha512 , sig )

Yes [4] - -
Crypto key.png Verify images using this Signing Key Yes [4] -


Verify the Whonix Images

It is important to check the integrity of the downloaded virtual machine images to ensure that neither a man-in-the-middle attack or file corruption occurred (see Download Security).

Whonix virtual machine images are cryptographically signed by Whonix developer Patrick Schleizer using OpenPGP. [6]

If you know how to use an OpenPGP key, download the Whonix Signing Key and the Whonix signatures straight away.

Otherwise, use the following instructions:

Download Whonix XFCE

2. Install VirtualBox Virtualbox logo.png

  • Linux Tux.png: please press expand on the right side.

Hosts using a non-Debian OS:

Install VirtualBox as per the normal mechanism for your Linux distribution.

Debian hosts:

Note: this applies to Whonix 14.0.1.4.4. Later Whonix versions may use a codename different to stretch.

Package virtualbox should be installed from Debian backports. [7] [8] [9]

1. On the host.

Open a terminal.

2. Add the current Debian stable backports codename stretch-backports to Debian apt sources.

[10]

sudo su -c "echo -e 'deb http://http.debian.net/debian stretch-backports main contrib' > /etc/apt/sources.list.d/backports.list"
3. Update the package lists.

sudo apt-get update

4. Install the selected software.

sudo apt-get install virtualbox/stretch-backports linux-headers-$(uname -r)

The procedure is now complete.

5. Undo.

On occasion it is necessary to undo this configuration, for example when upgrading from Debian stretch to buster. [11] To proceed, run.

sudo rm /etc/apt/sources.list.d/backports.list

3. Import Whonix Whonix old logo.png into VirtualBox Virtualbox logo.png

For Whonix VirtualBox import instructions, please press on expand on the right.

Start VirtualBox
Open The virtualbox1.png

Click on Filethen choose Import Appliance...
Select Import Applience2.png

Navigate and select Whonix image and press next
Select whonix image and press next3.png

Do NOT change anything! Just click on Import
Press import4.png

Then press Agree
Press agree5.png

Wait until Whonix-Gateway.ova has been imported
Wait for importing6.png

Repeat the import step also for Whonix-Workstation.ova
Do the same for whonix workstation7.png

Now start both Whonix-Gateway ™ and Whonix-Workstation ™
Start both of them8.png

Miscellaneous

There are also Video Tutorials.

If you still need help, please check the Support page.

For command line import instructions, see footnote. [12]

4. Start Whonix

Starting Whonix is simple.

Start VirtualBox -> Double-click the Whonix-Gateway ™ and Whonix-Workstation ™.

5. VirtualBox Screen Resolution Bug

Cli4.png

If the display presents like the image on the right-hand side, then you are affected by a screen resolution bug which only occurs in the XFCE version of Whonix in VirtualBox. To correct the resolution, apply the following workaround.

  1. Maximize the window.
  2. VirtualBox VM Windows -> View -> Virtual Screen 1 -> Choose any, resize to another resolution
  3. VirtualBox VM Windows -> View -> Auto-resize Guest Display
Cli3.png

First time user?

Footnotes and Experimental Spectre / Meltdown Defenses

Please press on expand on the right.

VirtualBox Stable Version | VirtualBox Testers Only Version

Testers only! For more information please press on expand on the right.

These experimental Spectre/Meltdown defenses are related to issues outlined in Firmware Security and Updates. Due to the huge performance penalty and unclear security benefits of applying these changes, it may not be worth the effort. The reason is VirtualBox is still likely vulnerable, even after:

  1. A host microcode upgrade.
  2. A host kernel upgrade.
  3. A VM kernel upgrade.
  4. A "not vulnerable" result from spectre-meltdown-checker run on the host.
  5. Installation of the latest VirtualBox version. [13]
  6. All Spectre/Meltdown-related VirtualBox settings are tuned for better security as documented below.

To learn more, see: VirtualBox 5.2.18 vulnerable to spectre/meltdown despite microcode being installed and the associated VirtualBox forum discussion. [14] Users must patiently wait for VirtualBox developers to fix this bug.

On the host. [15] [16] [17] [18] [19] [20] [21]

VBoxManage modifyvm "Whonix-Gateway" --ibpb-on-vm-entry on
VBoxManage modifyvm "Whonix-Workstation" --ibpb-on-vm-entry on
VBoxManage modifyvm "Whonix-Gateway" --ibpb-on-vm-exit on
VBoxManage modifyvm "Whonix-Workstation" --ibpb-on-vm-exit on
VBoxManage modifyvm "Whonix-Gateway" --l1d-flush-on-vm-entry on
VBoxManage modifyvm "Whonix-Workstation" --l1d-flush-on-vm-entry on
VBoxManage modifyvm "Whonix-Gateway" --l1d-flush-on-sched on
VBoxManage modifyvm "Whonix-Workstation" --l1d-flush-on-sched on
VBoxManage modifyvm "Whonix-Gateway" --spec-ctrl on
VBoxManage modifyvm "Whonix-Workstation" --spec-ctrl on
VBoxManage modifyvm "Whonix-Gateway" --nestedpaging off
VBoxManage modifyvm "Whonix-Workstation" --nestedpaging off


The above instructions only apply to the default VM names Whonix-Gateway ™ and Whonix-Workstation ™. Therefore, if Multiple Whonix-Workstation ™s and/or Multiple Whonix-Gateway ™s are configured, then repeat these instructions using the relevant name/s.


Footnotes[edit]

  1. https://forums.whonix.org/t/whonix-virtualbox-14-0-1-4-4-unified-ova-downloads-point-release/6996
  2. https://forums.whonix.org/t/whonix-kvm-14-0-1-4-4-unified-tar-gz-download-point-release/7061
  3. This change reduces the number of steps users are required to apply (one download instead of two). No functionality was lost. This improves usability, makes Whonix downloads more standardized compared to other software, and simplifies Whonix infrastructure maintenance work. The Whonix split VM design (separate Whonix-Gateway ™ and Whonix-Workstation ™) remains unmodified.
  4. 4.0 4.1 4.2 4.3 By using the Tor Browser Bundle (TBB). For an introduction, see Tor Browser. See also Hide Tor and Whonix from your ISP.
  5. It does not matter if the bulk download is done over an insecure channel if OpenPGP verification is used at the end.
  6. OpenPGP is a standard for data encryption that provides cryptographic privacy and authentication through the use of keys owned by its users.
  7. This is required since VirtualBox in unavailable in Debian stretch.
  8. This is non-ideal, see next footnote.
  9. Users should Prefer Packages from Debian Stable Repository, but using backports is better than manual software installation or using third party package managers since this prefers APT. To contain the risk, Non-Qubes-Whonix ™ users might want to consider using Multiple Whonix-Workstation ™ and Qubes-Whonix ™ users might want to consider using Multiple Qubes-Whonix ™ TemplateVMs or Software Installation in a TemplateBasedVM.
  10. Or alternatively use the .onion mirror.
    sudo su -c "echo -e 'deb tor+http://vwakviie2ienjx6t.onion/debian stretch-backports main contrib' > /etc/apt/sources.list.d/backports.list"
  11. Most often this step applies before attempting major Whonix upgrades; upgrade instructions are also made available at that time (see stay tuned).
  12. For Linux: Read License Agreement.
    vboxmanage import Whonix-XFCE-15.0.0.0.6.ova --vsys 0 --eula show --vsys 1 --eula show
    vboxmanage import Whonix-XFCE-15.0.0.0.6.ova --vsys 0 --eula accept --vsys 1 --eula accept
  13. VirtualBox version 5.2.18 or above is required since only that version comes with Spectre/Meltdown defenses. See https://forums.whonix.org/t/whonix-vulerable-due-to-missing-processor-microcode-packages/5739/22.
  14. Also see the following Whonix forum discussion: Whonix vulerable due to missing processor microcode packages? spectre / meltdown / retpoline / L1 Terminal Fault (L1TF)
  15. --ibpb-on-vm-[enter|exit] on|off: Enables flushing of the indirect branch prediction buffers on every VM enter or exit respectively. This could be enabled by users overly worried about possible spectre attacks by the VM. Please note that these options may have sever impact on performance.
    https://www.virtualbox.org/manual/ch08.html

    There is a mistake in the VirtualBox manual stating enter which does not work. It is actually entry.

  16. https://www.virtualbox.org/manual/ch08.html

    --l1d-flush-on-vm-enter on|off: Enables flushing of the level 1 data cache on VM enter. See Section 13.4.1, “CVE-2018-3646”.

  17. --l1d-flush-on-sched on|off: Enables flushing of the level 1 data cache on scheduling EMT for guest execution. See Section 13.4.1, “CVE-2018-3646”.
    https://www.virtualbox.org/manual/ch08.html

  18. https://www.virtualbox.org/manual/ch13.html#sec-rec-cve-2018-3646

    For users not concerned by this security issue, the default mitigation can be disabled using

    VBoxManage modifyvm name --l1d-flush-on-sched off

    Since we want to enable the security feature we set --l1d-flush-on-sched on.

  19. --spec-ctrl on|off: This setting enables/disables exposing speculation control interfaces to the guest, provided they are available on the host. Depending on the host CPU and workload, enabling speculation control may significantly reduce performance.
    https://www.virtualbox.org/manual/ch08.html

  20. According to this VirtualBox ticket --spec-ctrl should be set to on.
  21. --nestedpaging on|off: If hardware virtualization is enabled, this additional setting enables or disables the use of the nested paging feature in the processor of your host system; see Section 10.7, “Nested paging and VPIDs” and Section 13.4.1, “CVE-2018-3646”.


No user support in comments. See Support.

Comments will be deleted after some time. Specifically after comments have been addressed in form of wiki enhancements. See Wiki Comments Policy.


Anonymous user #1

3 months ago
Score 0 You
Please add I2P to the Whonix too, because sometime is really hard to connect Tor Circuit...

Patrick

2 months ago
Score 1++

Not exactly what you're asking for, but may interest you: https://www....org/wiki/I2P

i2p integration development discussion:

https://foru...gration/4981

Anonymous user #1

2 months ago
Score 0 You
The download of "Download Whonix-Workstation" presents fail when it is around 250MiB.

Patrick

2 months ago
Score 0++
Could you try again please? Does this issue persist?

Anonymous user #1

2 months ago
Score 0 You
For me the download also stopped with a "fail" message at about 250MB, but a simple click on "retry" would start from where the download stopped, and it seems to work so far. (downloaded using tor browser, if that helps to identify the issue)

Patrick

2 months ago
Score 0++

The inability of resuming downloads is a hassle indeed. However, cannot be fixed from the Whonix side.

The download restarting from zero is not a problem caused by the Whonix website. Download resumption is possible when using downloaders such as wget or curl with resume option.

Many browsers unfortunately still nowadays don't support resuming of downloads by default.

Anonymous user #1

one month ago
Score 0 You
Try using IDM, it downloads the zip file quite fast, 400 - 500KB/Sec and takes about an hour to do the job.

Anonymous user #1

2 months ago
Score 0 You

Cuando trato de iniciar ambos me sale el siguiente error:

Fallo al abrir una sesión para la máquina virtual Whonix-Gateway-XFCE.

VT-x is disabled in the BIOS for all CPU modes (VERR_VMX_MSR_ALL_VMX_DISABLED).

Result Code: E_FAIL (0x80004005) Componente: ConsoleWrap

Interfaz: IConsole {872da645-4a9b-1727-bee2-5585105b9eed}

Patrick

2 months ago
Score 0++

VirtualBox issue.

https://www...._in_the_BIOS.

Please enable VT-x in BIOS.

Anonymous user #1

2 months ago
Score 0 You

Fallo al abrir una sesión para la máquina virtual Whonix-Gateway-XFCE.

VT-x is disabled in the BIOS for all CPU modes (VERR_VMX_MSR_ALL_VMX_DISABLED).

Result Code: E_FAIL (0x80004005) Componente: ConsoleWrap

Interfaz: IConsole {872da645-4a9b-1727-bee2-5585105b9eed}

Patrick

2 months ago
Score 0++

VirtualBox issue.

https://www...._in_the_BIOS

Please enable VT-x in BIOS.

Anonymous user #1

2 months ago
Score 0 You

Hello. I'm having a problem with importing it to my virtual machine (Oracle VM VirtualBox Manager, version 6.0.4). It says "Failed to import appliance C:\Users\*****\Whonix-Workstation-XFCE-14-0-1-8.ova." Anyone knows why? All help is appriciated.

//uYu

Patrick

2 months ago
Score 0++

There may be an issue with the file download. The file may be corrupted. Please re-download.

Did you verify the downloaded file?

File verification recommended:

https://www....honix_images

Anonymous user #1

2 months ago
Score 0 You

1) Does Whonix requires VirtualBox 5.x or VirtualBox 6.x can be used too?

2) Do I need to remove VirtualBox Extensions Pack because it is not free? Does it dangerous to use it with Whonix?

Patrick

2 months ago
Score 0++

1) yes

https://www....her_Versions

2) not required for Whonix. If you don't need, don't use. If you want to use it, up to you. Less is better.

Anonymous user #1

2 months ago
Score 0 You

I am getting the following errors on both Linux and macOS systems: Failed to open a session for the virtual machine Whonix-Workstation-XFCE.

The virtual machine 'Whonix-Workstation-XFCE' has terminated unexpectedly during startup with exit code 1 (0x1).

Result Code: NS_ERROR_FAILURE (0x80004005) Component: MachineWrap Interface: IMachine {5047460a-265d-4538-b23e-ddba5fb84976}

what do I do? thanks

Anonymous user #1

2 months ago
Score 0 You
Are you running VirtualBox v. 5.2? If so install the newest Version 6.0.4

Anonymous user #1

2 months ago
Score 0 You
Just wondering why is downloading Whonix so slow. Both the Gateway and Workstation files download sooo slow and I'm using a wired connection. It takes me well over an hour for each file to download.

Anonymous user #1

2 months ago
Score 0 You
I'm just curious why is downloading the files so slow and why did my post not get posted to this website?

Patrick

2 months ago
Score 0++
Dunno but looks like your comment went through.

Anonymous user #1

2 months ago
Score 0 You
if I install a gateway after my ISPs' SURFboard can I flash Whonix to that Gateway then connect to my router then connect to my network devices. would that create anonymity?

Patrick

2 months ago
Score 0++

Whonix can't operate as router software at this point in time.

The closest to this is:

- Whonix RPi - https://www....al_Isolation

- https://www....ting_Systems

Anonymous user #1

one month ago
Score 0 You

I can't connect to whonix tor network tor our country

solution Turkey

Anonymous user #1

one month ago
Score 0 You
The screen resolution workaround doesn't work. The other resolution, and the auto-resize are greyed out. Any suggestion?

Anonymous user #1

one month ago
Score 0 You

I'm having problems with importing whonix into the virtual machine. The following error pops up: E_INVALIDARG (0x80070057)

What can I do about it?

Anonymous user #1

one month ago
Score 0 You
This is the same user writing. I wanted to add, that I am using the latest version of virtualbox and I trited to re-download whonix multiple times, but that didn't help. Looking forward for any help I can get.

Patrick

one month ago
Score 0++

Any more information in that error message?

The VirtualBox forum may have some suggestions.

try a web search

site:virtualbox.org "E_INVALIDARG (0x80070057)"

A lot results.

Anonymous user #1

one month ago
Score 0 You

I'm having troubles with importing whonix into the virtualbox. I recieve the following error every time: E_INVALIDARG (0x80070057)

I've re-downloaded whonix multiple times, verified the images and even reinstalled virtualbox. What else can I do to resolve this issue?

Patrick

one month ago
Score 0++

Any more information in that error message?

The VirtualBox forum may have some suggestions.

try a web search

site:virtualbox.org "E_INVALIDARG (0x80070057)"

A lot results.

Anonymous user #1

one month ago
Score 0 You

Hello,

The Whonix-Gateway is no more avialable to be downloaded?

(

Anonymous user #1

one month ago
Score 0 You
After continueing installaton of Whonix-XFCE package, it seems both ( the gateway and XFCE ) are bundeled in the same package named  : Whonix-XFCE

Patrick

one month ago
Score 0++

Indeed.

No functionality has been lost. Everything still possible just one download less. See also:

https://foru...release/6996

Anonymous user #1

one month ago
Score 0 You

Why is the download on sourceforge.net it used to be directly from this website is it safe sourceforge.net? I remember vaguely hearing issues with sourceforge.net in the past.

Thank you.

Anonymous user #1

one month ago
Score 0 You
Why don't you check the files with the OpenPGP signatures and OpenPGP key?

Anonymous user #1

one month ago
Score 0 You

@Patrick I see, my predecessor can't.

You didn't provide the signature files and didn't provide a link to the public key.

Patrick

one month ago
Score 0++
Press `expand` then you'll see signing key and signature.

Patrick

one month ago
Score 0++

Why sourceforge for downloads: in short server issues + too much traffic.

(Traffic isn't free.)

Of course, this is a step back.

There might be a Whonix news in future addressing this. We also might find other solutions. Stay tuned.

https://www....i/Stay_Tuned

Anonymous user #1

one month ago
Score 0 You

Hello, I cannot use any snapshot anymore with VirtualBox 6, tried on Windows and Unbuntu. Here is the code error I get on both system:

Failed to load unit 'lsilogicsas' (VERR_SSM_LOADED_TOO_LITTLE).

Code d'erreur : NS_ERROR_FAILURE (0x80004005)

Any idea about that ?

Patrick

one month ago
Score 0++

Please check on virtualbox.org. Search for:

site:virtualbox.org VERR_SSM_LOADED_TOO_LITTLE

Anonymous user #1

one month ago
Score 0 You

I faced the following problem: Failed to open a session for the virtual machine Whonix-Gateway-XFCE.

WHvCapabilityCodeHypervisorPresent is FALSE! Make sure you have enabled the 'Windows Hypervisor Platform' feature. (VERR_NEM_NOT_AVAILABLE).

VT-x is not available (VERR_VMX_NO_VMX).

Result Code: E_FAIL (0x80004005) Component: ConsoleWrap Interface: IConsole {872da645-4a9b-1727-bee2-5585105b9eed}

So, kindly how can I fix it? Plz help..

Patrick

one month ago
Score 0++
Please enable VT-x / virtualization in BIOS.

Anonymous user #1

one month ago
Score 0 You
Hello, i stop at 10% in anon connection wizard( bridge "meek-azure") in VirtualBox, and i find people in the internet said there is something wrong with bridge. But i can use tor browser in windows 10( bridge "meek-azure"). What should i do? Thanks for your reading.

Patrick

one month ago
Score 0++

Could you try type of bridge please?

See also:

https://www....wiki/Bridges

Anonymous user #1

one month ago
Score 0 You
How do I download Whonix-Workstation.ova or Whonix-Gateway.ova ? I can only download Whonix-XFCE.ova .

Patrick

one month ago
Score 0++

That file contains both gateway, and workstation. Downloads are now unified.

Same functionality as before. See also:

https://foru...release/6996

Anonymous user #1

one month ago
Score 0 You
Hello, i have some problem with anon connection wizard. I stopped at 10%, and i find people in internet said there are something wrong with bridge. But i can use tor browser with same bridge(meek-azure). What should i do? And why? Thank you for your reading.

Patrick

one month ago
Score 0++

Could you try type of bridge please?

See also: https://www....wiki/Bridges

Anonymous user #1

one month ago
Score 0 You
@Patrick Thanks for your help. I have tried twice, but it didn't work. I think it because i try to connect by a chinese ip. And i don't how to get a usefull bridge. By the way, what is the different between whonix(VirtualBox) and tor browser(windows10)?

Anonymous user #1

27 days ago
Score 0 You

I start up gateway, I am presented with a BIOS-looking interface to load into 'Whonix GNU/Linux' or an advanced version. When I select either, the VM turns to black.

Any help?

Anonymous user #1

9 days ago
Score 0 You
Hey? Where is the gateway at?

Patrick

9 days ago
Score 0++

This release introduces unified ova downloads. Rather than separate Whonix-Gateway ™ and Whonix-Workstation ™ ova downloads, there is now only a single Whonix ova which includes both Whonix virtual machines (VMs), Whonix-Gateway ™ and Whonix-Workstation ™.

> https://foru...release/6996

> This change reduces the number of steps users are required to apply (one download instead of two). No functionality was lost. This improves usability, makes Whonix downloads more standardized compared to other software, and simplifies Whonix infrastructure maintenance work. The Whonix split VM design (separate Whonix-Gateway ™ and Whonix-Workstation ™) remains unmodified.

Anonymous user #1

17 hours 29 minutes ago
Score 0 You
1,6 GB and only 1 file ? is it something wrong with this ? i can't even use it there is error. I tried to unpack this after that i have 2 virtual disk i added both to virtual box but it not works system shuting down with errors and working unstable.

Anonymous user #1

15 hours 56 minutes ago
Score 0 You
What is the difference between the gateway and the workstation? I open both but that do the same thing?
Add your comment
Whonix welcomes all comments. If you do not want to be anonymous, register or log in. It is free.


Random News:

Don't mind having your name connected to Whonix ™? Follow us on Twitter / Facebook.


https | (forcing) onion

Share: Twitter | Facebook

This is a wiki. Want to improve this page? Help is welcome and volunteer contributions are happily considered! Read, understand and agree to Conditions for Contributions to Whonix ™, then Edit! Edits are held for moderation.

Copyright (C) 2012 - 2019 ENCRYPTED SUPPORT LP. Whonix ™ is a trademark. Whonix ™ is a licensee of the Open Invention Network. Unless otherwise noted, the content of this page is copyrighted and licensed under the same Freedom Software license as Whonix ™ itself. (Why?)

Whonix ™ is a derivative of and not affiliated with Debian. Debian is a registered trademark owned by Software in the Public Interest, Inc.

Whonix ™ is produced independently from the Tor® anonymity software and carries no guarantee from The Tor Project about quality, suitability or anything else.

By using our website, you acknowledge that you have read, understood and agreed to our Privacy Policy, Cookie Policy, Terms of Service, and E-Sign Consent. Whonix ™ is provided by ENCRYPTED SUPPORT LP. See Imprint.