Actions

Whonix ™ Tuning

From Whonix



Gear-192875640.jpg

Introduction[edit]

Info Everything in this chapter is entirely optional.

Applying steps in this chapter can improve Whonix ™ performance, but often at the cost of reduced security or an increased fingerprinting risk. Earlier entries in this chapter are easier to apply, while later tuning entries require a greater skill level.

At present the tuning steps are primarily focused on the VirtualBox virtualizer. However, contributions for other virtualizers will be happily considered.

Tested Tuning Steps[edit]

Hardware-accelerated Graphics[edit]

Ambox warning pn.svg.png Warning: this procedure lessens security.

To enable hardware-accelerated graphics for Whonix-Workstation ™, perform these steps on the host:

  1. Power off the VM.
  2. VirtualBoxclick a VMSettingsDisplayGraphics ControllerAcceleration: check Enable 3D AccelerationOK
  3. Restart the VM.

Also refer to the VirtualBox manual: Hardware-Accelerated Graphics [archive].

Forum discussion: VirtualBox 3D Acceleration [archive]

Increase Virtual Machine RAM[edit]

Ambox warning pn.svg.png Warning: this procedure may increase fingerprinting risks.

If minor identifiers are not of any concern, [1] then the RAM available to Virtual Machines can be increased via VirtualBox settings. This is most useful for Whonix-Workstation ™ if it runs into low RAM. Whonix-Gateway ™ can also profit if a large number of circuits are created and Tor is kept busy. To check how much RAM is free, use free -m in a Terminal. Consider the example below:

  1. Shutdown the VM.
  2. Assign more RAM: Virtual machineMenuSettingsAdjust Memory slider to 4096Hit: OK
  3. Restart the VM.

See also: Advice for Systems with Low RAM.

Additional CPU Cores[edit]

Ambox warning pn.svg.png Warning: this procedure may increase fingerprinting risks.

On systems with multi-core processors, if minor identifiers are not of any concern [2] then the number of cores available to the Virtual Machine(s) can be increased in VirtualBox settings.

Do not use the maximum since that could lead to system instability! Always leave at least one CPU unassigned; for example, if you have four CPUs then assign a maximum of three CPUs to the VM. [3]

  1. Power off the VM.
  2. VirtualBoxclick a VMSettingsSystemProcessorReduce to 3OK
  3. Restart the VM.

Untested Tuning Steps[edit]

Disable CPU Mitigations[edit]

Ambox warning pn.svg.png Warning: this procedure lessens security.

Untested!

Consider disabling the Spectre Meltdown mitigations. (Related forum discussion [archive].)

This step should be performed in the VM intended for disabled CPU mitigations and on the host operating system if either Kicksecure or security-misc are in use.

1. Remove the relevant CPU mitigations file.

sudo rm /etc/default/grub.d/40_cpu_mitigations.cfg

2. Update grub.

sudo update-grub

3. Reboot.

4. Done.

Nested Paging and VPIDs[edit]

It is possible to increase performance by using largepages and/or Virtual Processor Identifiers (VPIDs). It is unknown if this decreases security or stability. For further information refer to the VirtualBox manual: Nested Paging and VPIDs [archive].

vboxmanage modifyvm Whonix-Workstation-XFCE --largepages on

vboxmanage modifyvm Whonix-Gateway-XFCE --largepages on

vboxmanage modifyvm Whonix-Workstation-XFCE --vtxvpid on

vboxmanage modifyvm Whonix-Gateway-XFCE --vtxvpid on

Memory Ballooning, Page Fusion and Memory Overcommitment[edit]

Ambox warning pn.svg.png Warning: this procedure lessens security.

Memory ballooning worsens security because it is a vector for side channel attacks on memory; see here for further information. [4]

For other security considerations, refer to the VirtualBox manual: Memory Overcommitment [archive].

Undocumented Tuning Settings[edit]

There are probably more tuning-related settings, but these are currently undocumented at Whonix ™. Interested readers can review the VirtualBox manual for relevant settings, which are unlikely to be bundled under a "tuning" chapter.

To view all settings, run.

vboxmanage showvminfo Whonix-Workstation-XFCE

Next, learn about all of these settings by reviewing the VirtualBox manual [archive].

Optimized Builds[edit]

Since the Whonix ™ concept is flexible and distribution-agnostic, it is possible to create your own implementation. For example, Gentoo could be used with optimized build flags for a personal system. See:

PCI Passthrough[edit]

Ambox warning pn.svg.png Warning: this procedure lessens security.

This setting can improve graphics performance dramatically, but it worsens security because VMs should not have direct access to physical hardware.

In simple terms, this feature allows the direct use of physical PCI devices on the host by the guest even if the host does not have drivers for the particular device. For further information, refer to VirtualBox Manual: PCI Passthrough [archive].

See Also[edit]

Footnotes[edit]

  1. The amount of detectable VM RAM is considered a minor risk.
  2. Adding CPU cores is considered a minor risk.
  3. VirtualBox ticket: VirtualBox should now prohibit assigning all physical CPUs to a VM and/or fix VirtualBox CPU assignment manual [archive].
  4. This entry relates to KVM but the research similarly applies to other virtualizers unless they have implemented and documented specific protections.


Fosshost is sponsors Kicksecure ™ stage server 100px
Fosshost About Advertisements

Search engines: YaCy | Qwant | ecosia | MetaGer | peekier | Whonix ™ Wiki


Follow: 1024px-Telegram 2019 Logo.svg.png Iconfinder Apple Mail 2697658.png Twitter.png Facebook.png Rss.png Reddit.jpg 200px-Mastodon Logotype (Simple).svg.png

Support: Discourse logo.png

Donate: Donate Bank Wire Paypal Bitcoin accepted here Monero accepted here Contribute

Whonix donate bitcoin.png Monero donate Whonix.png United Federation of Planets 1000px.png

Twitter-share-button.png Facebook-share-button.png Telegram-share.png Iconfinder Apple Mail 2697658.png Reddit.jpg Hacker.news.jpg 200px-Mastodon Logotype (Simple).svg.png

Twitter-share-button.png Facebook-share-button.png Telegram-share.png Iconfinder Apple Mail 2697658.png Reddit.jpg Hacker.news.jpg 200px-Mastodon Logotype (Simple).svg.png

https link onion link Priority Support | Investors | Professional Support

Whonix | © ENCRYPTED SUPPORT LP | Heckert gnu.big.png Freedom Software / Osi standard logo 0.png Open Source (Why?)

The personal opinions of moderators or contributors to the Whonix ™ project do not represent the project as a whole.

By using our website, you acknowledge that you have read, understood and agreed to our Privacy Policy, Cookie Policy, Terms of Service, and E-Sign Consent.