QubesOS / qubes-issues

The Qubes OS Project issue tracker
https://www.qubes-os.org/doc/issue-tracking/
526 stars 46 forks source link

Separate GPU acceleration toggle for Whonix VMs #8970

Open DemiMarie opened 4 months ago

DemiMarie commented 4 months ago

GPU acceleration can be used to compromise anonymity. Whonix VMs should never have access to it, and attempting to enable GPU acceleration for a Whonix VM should fail.

DemiMarie commented 4 months ago

@adrelanos can you confirm (or refute) this?

adrelanos commented 4 months ago

I don't recall such an argument. Only System Identity Camouflage and Virtual Machine Cloaking comes to mind.

In Hardware-accelerated Graphics wiki says it is discouraged for security reasons.

To put it into perspective: Tor Browser (or any torified application) running on real Debian (non-Qubes) would also have access to GPU acceleration.

Suggested change:

Related issues: