Package: anon-apt-sources-list Version: 3:6.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 71 Depends: fasttrack-archive-keyring Homepage: https://github.com/Kicksecure/anon-apt-sources-list Priority: optional Section: misc Filename: pool/main/a/anon-apt-sources-list/anon-apt-sources-list_6.6-1_all.deb Size: 29280 SHA256: 970d4552ad4893afa1aafd031333d853282dc7c7154792d259952c7afa11223d SHA1: b2026344b51d283d4985a71bc66b9e312e84997f MD5sum: 5127d1df8b74122c1dd90de40f167864 Description: Kicksecure APT and Flatpak Repository Configuration Configuring APT and Flatpak sources: - Includes Debian APT repositories (main, updates, backports, fasttrack, security) - Incorporates Debian APT components (main, contrib, non-free, non-free-firmware) - Integrates the Flathub repository (verified and floss subsets only) . Flatpak: - Official Flathub repository only. - Uses subset verified_floss, which means only verified applications and freedom software can be installed by default. . Provides configuration files: - /etc/apt/sources.list.d/debian.list for APT sources - /etc/flatpak/remotes.d/flathub.flatpakrepo for Flatpak sources . A Discussion on Distribution Maintenance Strategies: . The more standard way would indeed be populating /etc/apt/sources.list at install or build time and leaving /etc/apt/sources.list.d alone. . The idea of managing /etc/apt/sources.list.d/debian.list for the user is, the security-focused distribution maintainers can decide when it is a better "change stable to oldstable", "keep wheezy as long as needed to work out [eventual!] issues that would break during upgrade to jessie" and such. Package: anon-connection-wizard Version: 1:9.2-1 Architecture: all Maintainer: iry Installed-Size: 261 Depends: helper-scripts, pkexec, policykit-1-gnome | polkit-1-auth-agent, python3, python3-pyqt5, python3-stem, python3-yaml, qtwayland5 Recommends: obfs4proxy, tor Homepage: https://www.kicksecure.com/wiki/Anon_Connection_Wizard Priority: optional Section: misc Filename: pool/main/a/anon-connection-wizard/anon-connection-wizard_9.2-1_all.deb Size: 92456 SHA256: d832845cc0ea58147cff3e9c0b5c2a6952e4074597e6887326267e1e6ca2d0dc SHA1: 44bcc068e107524660595435bd1ff0bcd2a200d5 MD5sum: 326341cace26d560a968f8cc4667d65b Description: Tor Connection Configuration (ACW) WARNING: Not (yet) a standalone ready to use outside of Whonix: . Creates a Tor settings file: `/usr/local/etc/torrc.d/40_tor_control_panel.conf` . anon-connection-wizard (ACW) is a Tor-launcher-like application that helps users in different Internet environment connect to the Tor network. It helps user to configure Tor to use a proxy and/or Tor bridges. This application is especially useful for system Tor users who would like to run the standalone core Tor with different torified applications. The wizard can be run at any time to change the connection configuration. . Creates a Tor settings file: `/usr/local/etc/torrc.d/40_tor_control_panel.conf` . anon-connection-wizard is produced independently from the Tor anonymity software and carries no guarantee from The Tor Project about quality, suitability or anything else. Package: anon-shared-build-apt-sources-tpo Version: 3:6.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 121 Depends: helper-scripts, gnupg Recommends: deb.torproject.org-keyring Homepage: https://github.com/Kicksecure/anon-shared-build-apt-sources-tpo Priority: optional Section: misc Filename: pool/main/a/anon-shared-build-apt-sources-tpo/anon-shared-build-apt-sources-tpo_6.4-1_all.deb Size: 64068 SHA256: e679b1d101e562f761cd18dc55e5a4e03304349dc552e2ee003449659f4e2af4 SHA1: 7a27cb1e4d05fed88eaddd694c93a27fdabaf51b MD5sum: e06f1ab209beaeb44fe8bb326d5a4db2 Description: Adds TPO's APT repository to Derivative Linux Distributions Comes with "deb http://deb.torproject.org/torproject.org stable main", The Tor Project's APT signing key. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: apparmor-profile-dist Version: 3:8.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 95 Depends: helper-scripts Replaces: apparmor-profile-anondist Homepage: https://www.kicksecure.com/wiki/Apparmor-profile-everything Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-dist/apparmor-profile-dist_8.9-1_all.deb Size: 34960 SHA256: 95ef0e1a258ff875f503f1996315c9eb195d4714ac58c9d998edfe039b9a369d SHA1: 2c84beb209d7b06255d19fd1528aa51b21ee5c7c MD5sum: c62b3ad0679a4057962a9ee86c461304 Description: AppArmor Profile for Derivative Linux Distributions Displaces /etc/apparmor.d/abstractions/base with a version, that includes additions required for Derivative Linux Distributions. . Does not depend on AppArmor, so this package can be installed by default on any anonymity distribution by default, without requiring to also have AppArmor installed. Just for the case, AppArmor gets installed later by the user. Package: apparmor-profile-everything Version: 3:8.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 163 Depends: apparmor, apparmor-profile-torbrowser, libpam-apparmor Homepage: https://www.kicksecure.com/wiki/Apparmor-profile-everything Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-everything/apparmor-profile-everything_8.2-1_all.deb Size: 44248 SHA256: 54a593e067f0c974d837588bb4efa9c17c740ee69b223431a53b1a047698f0ea SHA1: 9722a920985210d1b633d37445be1346e929486d MD5sum: febc85940a0e252da5e0c84518e0142d Description: Full system AppArmor policy This is an AppArmor policy to confine all user space processes on the system which allows one to enforce a strong security model and follow principle of least privilege. An AppArmor policy for the init, systemd is loaded in the initramfs which then applies to all other processes. Specific policies for many system services/applications are also enforced. . This follows design ideas already present in other operating systems such as Android and attempts to make something similar available on desktop Linux. . In addition to locking down user space, this also protects the kernel as it restricts access to kernel interfaces like `/proc` or `/sys`, making kernel pointer and other leaks much less likely. . This does not and cannot confine the kernel or initramfs. . This is expected to be used in combination with other security technologies such as a hardened kernel, strong sandboxing architecture, verified boot and so on. . apparmor-profile-everything supports different boot modes: aadebug and superroot. aadebug allows certain permissions necessary for advanced debugging and superroot relaxes the policy substantially, even making bypasses possible. It is highly recommended to stick to the default boot mode. . It also contains a wrapper to restrict apt as apt requires permissions that may be abused to circumvent the policy. When updating or installing applications, you must use the `rapt` command. . This is still in development and breakage is likely. This should only be used by developers for now. . For now, please only use this development discussion forum thread: https://forums.whonix.org/t/apparmor-for-complete-system-including-init-pid1-systemd-everything-full-system-mac-policy/8339 . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: apparmor-profile-hexchat Version: 3:5.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 60 Depends: apparmor Replaces: apparmor-profile-xchat Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-hexchat/apparmor-profile-hexchat_5.1-1_all.deb Size: 23508 SHA256: 8736fb2b12f22a165f2180f3cc379bfe7d82b9ff7e39f3ff78b517e8959c6937 SHA1: c442bcef6d890ce339d8280e0e1ec8fdc215d85a MD5sum: ae1447ed5da0ca66b977bb6239606215 Description: AppArmor profile for HexChat IRC An AppArmor profile to confine HexChat IRC. This profile is developed by the Whonix team. HexChat IRC is developed by xchat.org / hexchat.github.io. . For better security. Package: apparmor-profile-thunderbird Version: 3:5.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 65 Depends: apparmor Replaces: apparmor-profile-icedove Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-thunderbird/apparmor-profile-thunderbird_5.6-1_all.deb Size: 26372 SHA256: 542a425da07544f8fbf0b3d79180317605c6ef55bbd9d249f93dd958034f32d0 SHA1: e2d19edc5e1697ee1e853edb024bcd6e639f1496 MD5sum: 37edd2f0b005b409d96f5d0b6b5bb58d Description: AppArmor profile for Thunderbird for Debian An AppArmor profile to confine Thunderbird. . This profile is just an extension of the upstream AppArmor Debian profile. The upstream AppArmor upstream profile is the foundation. . Primarily this AppArmor profile makes Debian's AppArmor profile for Thunderbird compatible with Qubes Debian based VMs. . This profile is developed by the Kicksecure team. Thunderbird is developed by mozilla.org. Package: apparmor-profile-torbrowser Version: 3:9.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 73 Depends: apparmor Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-torbrowser/apparmor-profile-torbrowser_9.2-1_all.deb Size: 34240 SHA256: ec52697707248dd65376e34239748697b711da2650b591ca57d4424d281b5dfd SHA1: bbdf54f1bd08e4c45755f8d0053fbbbf24ff67d7 MD5sum: 9f3824256e767e0a6fd906bf9cc31f41 Description: AppArmor profile for The Tor Browser Bundle (TBB) An AppArmor profile to confine The Tor Browser Bundle (TBB). This profile is developed by the Whonix team. TBB is developed by The Tor Project. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: apparmor-profiles-kicksecure Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: apparmor-profile-hexchat, apparmor-profile-thunderbird, apparmor-profile-torbrowser, apparmor-profiles, apparmor-profiles-extra Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/apparmor-profiles-kicksecure_30.9-1_all.deb Size: 76340 SHA256: 62d2febabd280dbfd48f259ba0c0b4710c189721c84314dc4ce5bdaab12bcc6c SHA1: e99d8f71de38d28a77ba279dc34a344390270e68 MD5sum: 582a85fe84ab5a0bd03f37fa68d3cd4f Description: AppArmor profiles developed by the Kicksecure Team A metapackage, which installs apparmor profiles packages from Debian: . * apparmor-profile * apparmor-profiles-extra . as well as installs apparmor profiles developed by the Kicksecure team: . * apparmor-profile-thunderbird * apparmor-profile-torbrowser * apparmor-profile-hexchat . Increases security. . Safe to remove, if you know what you are doing. Package: binaries-freedom Version: 0:2.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 30 Depends: fuse Homepage: https://github.com/Kicksecure/binaries-freedom Priority: optional Section: misc Filename: pool/main/b/binaries-freedom/binaries-freedom_2.9-1_all.deb Size: 10684 SHA256: 97cf97956b5313199a4c9a60f0b79cde27f6eee73e66aaf2881d4c716df7fe01 SHA1: f51d85d84bd2b2c5bdc2bd3054f9e73b7c8e3438 MD5sum: 4b6c5317f8c7d7bd5a70dd0dc40e861d Description: Freedom Software Binaries This is an empty package at this time. . https://forums.whonix.org/t/policy-for-inclusion-of-compiled-software/6635 Package: bindp Version: 3:3.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 27 Homepage: https://github.com/Kicksecure/bindp Priority: optional Section: misc Filename: pool/main/b/bindp/bindp_3.5-1_all.deb Size: 12912 SHA256: 064a52e8af450a109f3d9ad3f9c9ae488148dfc4c63e91f554ab2b19799c0b24 SHA1: 136628b64dc53434b20412d5d89cd5c9f3450f20 MD5sum: 0605b7487fa35c447357811bf445f2b0 Description: Binding specific IP and Port for Linux Running Application This package is probably most useful for Anonymity Distributions. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: bootclockrandomization Version: 3:6.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 86 Depends: msgcollector Homepage: https://www.kicksecure.com/wiki/Boot_Clock_Randomization Priority: optional Section: misc Filename: pool/main/b/bootclockrandomization/bootclockrandomization_6.6-1_all.deb Size: 29980 SHA256: 47c80c978e85bb6e872bcf3a035ae83a4a9d5518dc69e69bdc20f9c279637b0b SHA1: 438f2366f725f57ccb04a0d304f377dacd9a565f MD5sum: 27d7a798d25a27151dd7325e1bc0f3c9 Description: Randomizes clock when systems boots Randomizes clock at boot time. Moves clock a few seconds and nanoseconds to past or future. Useful in context of anonymity/privacy/Tor. . This is useful to enforce the design goal, that the host clock and Gateway/Workstation clock should always slightly differ (even before secure timesync succeeded!) to prevent time based fingerprinting / linkablity issues. . Runs before Tor / sdwdate (if installed). . See also: https://www.whonix.org/wiki/Dev/TimeSync Package: calamares-settings-debian Version: 13.1.2-1 Architecture: all Maintainer: Jonathan Carter Installed-Size: 316 Depends: calamares, cryptsetup, libglib2.0-bin, keyutils, pkexec, qml-module-qtquick-window2, qml-module-qtquick2, dconf-gsettings-backend | gsettings-backend Provides: calamares-settings Homepage: https://salsa.debian.org/live-team/calamares-settings-debian Priority: optional Section: utils Filename: pool/main/c/calamares-settings-debian/calamares-settings-debian_13.1.2-1_all.deb Size: 227196 SHA256: 0e78b171f45468b2dd6a7116d9027631363285b5ce272618b02133d15589667d SHA1: df15faedcab6fe37b18ee76bfe45cad5d4119fdf MD5sum: 29a9a8565061811d639fa6a025604e2b Description: Debian theme and settings for the Calamares Installer Calamares is a generic installer framework for Linux distributions. By default, it contains a set of boilerplate wording and images. This package provides the latest Debian artwork as well as scripts that supports EFI installations. . It also serves as an example for how derivatives can create their own calamares-settings packages. Package: damngpl Version: 3:4.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 31 Depends: perl Homepage: http://www.finnie.org/software/damngpl/damngpl Priority: optional Section: misc Filename: pool/main/d/damngpl/damngpl_4.1-1_all.deb Size: 13088 SHA256: 73f8deb8464d4b52a44b3f30b8bf3be0125974aee96edb0a51717ad2ba8d99d4 SHA1: 42ee6d1cbb1cd1f133a914172dc7e4b5fcb4a62a MD5sum: 0c3e9a0d1ede9350ae52c68dacdea300 Description: Extract source package info from Debian status files damngpl will parse a Debian-style /var/lib/dpkg/status file and extract source package information about installed packages. This information can be used in several ways, usually to download source packages. . Multiple input files can be specified on the command line, or piped into standard input if no files are specified. Results are returned to standard output. . The name damngpl was chosen as a tongue-in-cheek description of its purpose (downloading Debian sources for the Finnix project to remain GPL compliant). Please do not send hate mail to the author, thinking he is anti-GPL. He's not. . See also: http://blog.finnix.org/2011/08/21/finnix-and-gpl-compliance/ Package: deb.torproject.org-keyring Version: 2024.05.22 Architecture: all Maintainer: Peter Palfrader Installed-Size: 20 Priority: important Section: misc Filename: pool/main/d/deb.torproject.org-keyring/deb.torproject.org-keyring_2024.05.22_all.deb Size: 4372 SHA256: 22eb433ce2e23eb79914b80825b84c30f6aa785a824a971a9a7aff93bc0a5057 SHA1: 2d8e1f35f05c2b62051c83bb6fe0bebce0029335 MD5sum: 058f3b902a815b762f79e7b035705d00 Description: GnuPG archive key of the deb.torproject.org repository The deb.torproject.org repository digitally signs its Release files. This package contains the current repository key used for that, and upon installation configures your system to accept archives signed with this key. Package: debug-misc Version: 3:4.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 102 Suggests: systemd-coredump, serial-console-enable Replaces: grub-output-verbose Homepage: https://github.com/Kicksecure/debug-misc Priority: optional Section: misc Filename: pool/main/d/debug-misc/debug-misc_4.0-1_all.deb Size: 25068 SHA256: 0195998f10863366d48e41e3138891e556a8c315f6b400d3155e0edbf4def9f4 SHA1: 9df140f19d137140cdabd88afdfc8a631e953ab5 MD5sum: f29ec71368f61464695aca5af0f6ed30 Description: Enables miscellaneous debug settings Ships a `/etc/default/grub.d/45_debug-misc.cfg` configuration file, that removes `quiet`, `loglevel=0` and `debugfs=off` from the `GRUB_CMDLINE_LINUX_DEFAULT` variable and adds `debug=vc` to the kernel boot parameter to enable verbose output during the initial ramdisk boot phase. . Undo debugging related `sysctl` settings by package `security-misc`. . Enables persistent systemd journal log. . Disables `/lib/systemd/coredump.conf.d/disable-coredumps.conf` by package `security-misc` by creating a symlink from `/etc/systemd/coredump.conf.d/disable-coredumps.conf` to `/dev/null`. `debian/debug-misc.links` . Disables `panic-on-oops`, `remove-system.map` by package `security-misc`. . `config-package-dev` `hide` `/etc/sysctl.d/30_silent-kernel-printk.conf` which kernel.printk to default as if security-misc would not have lowered verbosity. . Configure systemd `getty` service to not clear `tty`. `/lib/systemd/system/getty@tty.service.d/30_debug-misc.conf` . Coredumps are enabled. `/etc/security/limits.d/40_debug-misc.conf` . Coredumps may contain important information such as encryption keys or passwords. Package `security-misc` disables coredumps. Package `debug-misc` re-enables coredumps. . Contains a helper tool to cause a segfault for testing purposes. `segfault-build` creates `segfault-run`. Running `segfault-run` results in `segfault-run` terminating with a segfault. This is useful to test if coredump files are being generated when an application crashes. `/usr/sbin/segfault-build` `/usr/share/debug-misc/segfault.c` . For better usability, to ease debugging in case of issues. . For better security, this package should only be installed on specific machines that require debugging. Unfortunately, security and debugging are conflicting optimization goals. Package: desktop-config-dist Version: 3:10.5-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 142 Conflicts: whonix-xfce-desktop-config Replaces: whonix-xfce-desktop-config Provides: whonix-xfce-desktop-config Homepage: https://github.com/Kicksecure/desktop-config-dist Priority: optional Section: misc Filename: pool/main/d/desktop-config-dist/desktop-config-dist_10.5-1_all.deb Size: 45844 SHA256: d183e178234793200f4cabe0c59952fbab2fc5d516a4e7edfbf789d7c2ac84c6 SHA1: add5750aebe7cfdb78073455aad11a558a0f6718 MD5sum: 95d661701e8b6adfbd2ecab402c9a7c5 Description: Configuration for Derivative Desktop Sets desktop and display setting, wallpaper and desktop icons. Sets icon theme and style. Settings for the default panel aka task bar, like panel position/color/size and panel plugins/shortcuts. . Autologin for user 'user' setting in lightdm. . Live check systray indicator which indicates the status of grub-live, whether the system was booted into persistent or live mode. See also: https://www.kicksecure.com/wiki/grub-live . Adds start menu entries for web browser, terminal emulator, file manager. . Sets Whisker Menu for better usability. . Disable maximize windows when moving to top for better privacy. . Disables thumbnails for better security. . Disables save on exit for better privacy. . Ships `zsh` derivative configuration settings folder `/etc/zsh`. But does not configure `zsh` as default shell. (That is up to package `dist-base-files`.) Package: desktop-config-dist-dependencies Source: desktop-config-dist Version: 3:10.5-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 63 Depends: xfce4-whiskermenu-plugin, xfce4-genmon-plugin, arc-theme, gnome-themes-extra, gnome-themes-extra-data, gtk2-engines-murrine, gnome-colors-common, adwaita-icon-theme Homepage: https://github.com/Kicksecure/desktop-config-dist Priority: optional Section: misc Filename: pool/main/d/desktop-config-dist/desktop-config-dist-dependencies_10.5-1_all.deb Size: 33608 SHA256: 766953c88d8027b33720c3e41c8c1b3f2b645b91cd1b24372d096692b458dfb6 SHA1: 0e0051005f2d9538ec14e3035c9e5e78197dd9bc MD5sum: 1f7c49b6bb3433724507283271b8f860 Description: Dependencies of desktop-config-dist A metapackage with dependencies for package desktop-config-dist. . Only useful for Non-Qubes. Not useful in Qubes. Package: developer-meta-files Version: 3:36.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 387 Depends: python3, bc, jq Homepage: https://github.com/Kicksecure/developer-meta-files Priority: optional Section: misc Filename: pool/main/d/developer-meta-files/developer-meta-files_36.9-1_all.deb Size: 129192 SHA256: ef9482e2ff5490affa9253b7e6e468db77c7cec96a4f40dfdd5da5664c31d2a9 SHA1: ad8d5dc6573c61b23807ec12ef76a8127c94b180 MD5sum: 4c3156cdfb8c928b500282a7129cc6c0 Description: Linux Distributions Maintenance Helper Scripts Todo . Description Package: dist-base-files Version: 3:11.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 362 Depends: sudo, dpkg-dev, helper-scripts, adduser, zsh, zsh-syntax-highlighting, zsh-autosuggestions Conflicts: anon-base-files Replaces: anon-base-files Provides: anon-base-files Homepage: https://github.com/Kicksecure/dist-base-files Priority: optional Section: misc Filename: pool/main/d/dist-base-files/dist-base-files_11.2-1_all.deb Size: 115168 SHA256: 9f5fa8005fc368a401dc8334ae8a2f3f50527ba3c0de4ef24580a2a93fe05937 SHA1: 097d1aebdf26bcd52c28b395eb683b3ef2e3c5f8 MD5sum: 71d4437b018a6367714648c97204fe95 Description: base files for distributions Creates user `user` with empty password (passwordless) (not in Qubes). That is if user `user` is not existing yet. And if it does create user `user` it also locks the root account. Therefore root account locking effectively only happens in new builds not having user `user` already created. . Adds user `user` to groups `cdrom`, `audio`, `dip`, `sudo`, `plugdev`. . Ships a systemd unit file dist-skel-first-boot.service which runs `/usr/libexec/helper-scripts/first-boot-skel` (part of helper-scripts) package. . Simplifies sudo default lecture to only showing the default password once. . Creates version file `/var/lib/dist-base-files/build_version`. . Default shell: Sets default shell for user `user` to `zsh`. (Unless file `/etc/no-shell-change` exists.) `debian/dist-base-files.postinst` . Provides common files for derivative GRUB themes. . This package gets installed by default in both, Kicksecure and Whonix. Package: dummy-dependency Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Provides: firefox-esr, qubes-core-agent-passwordless-root, tb-default-browser, tb-starter, tb-updater Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency_30.9-1_all.deb Size: 76376 SHA256: ac832e4dda86fd63d74fbf3a42fd8a73f0c3d8cc5248cf9cd76f057ae7be3ba8 SHA1: dbd82224924f2308696d84b85d3a5205187b8752 MD5sum: 7225d0c28776014ab46ff5631b0fe6f7 Description: dummy package to satisfy architecture specific dependencies A metapackage, which satisfies the dependency on: . - tb-updater - tb-starter - tb-default-browser - qubes-core-agent-passwordless-root - firefox-esr . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-apparmor-profiles-kicksecure Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Provides: apparmor-profiles-kicksecure Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-apparmor-profiles-kicksecure_30.9-1_all.deb Size: 76312 SHA256: 0afa38e44f7f6e172af4bf746a3dc47cad4280942333a9a3f1c13fd8fd21066e SHA1: 37d0677a071a86afeebe5b915d79eb5934af2d6b MD5sum: a8f7bfac9c239dc6d7ea04c86bf89798 Description: dummy package apparmor-profiles-kicksecure A metapackage, which satisfies the dependency on apparmor-profiles-kicksecure. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-bindp Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Provides: bindp Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-bindp_30.9-1_all.deb Size: 76304 SHA256: 2fa524e619519fbf369948ea7e177b3f60d5c83ea2a74bdc062b7aedeb8c8990 SHA1: 77dc61e37e33abbac3d57761010a1ece2baba596 MD5sum: 4e643d474f4e63f88e798c68e588a7da Description: dummy package to satisfy architecture specific dependency bindp A metapackage, which satisfies the dependency on bindp. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-electrum Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Replaces: dummy-dependency-hardened-electrum Provides: dummy-dependency-hardened-electrum, electrum Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-electrum_30.9-1_all.deb Size: 76312 SHA256: aef2b699642e443d48d16fa642705d091d129e03190734444dfdad0f4c11bb9b SHA1: 75e99c371ba0220bf4017e99bd2340db2590effb MD5sum: 47ffd5b3172117cc7e4f848d13bf058b Description: dummy package to satisfy architecture specific dependency electrum A metapackage, which satisfies the dependency on electrum. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-hardened-malloc Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Provides: hardened-malloc Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-hardened-malloc_30.9-1_all.deb Size: 76308 SHA256: f038f7195bbd6ad37b0b6a02cd3d9bbd4d8239511bd9c4ce1c884b706faa2300 SHA1: fa21a9e5cc0ebf4d1a28f2c1fed27b0f81dd3f7d MD5sum: 3b82832d44118105cd1f0db4048bc171 Description: dummy package to satisfy architecture specific dependency hardened-malloc A metapackage, which satisfies the dependency on: . hardened-malloc . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-kloak Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Provides: kloak Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-kloak_30.9-1_all.deb Size: 76292 SHA256: 5c34be7880b07fbd79ed6491de1c82e43445d829579c7833a10d62544f2b61af SHA1: 1a23ba34456c58cab6d10b4b7fb1b05f37bebd62 MD5sum: 9bda17746021dc4ba4ba407bec2b463c Description: dummy package to satisfy architecture specific dependency kloak A metapackage, which satisfies the dependency on kloak. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-tirdad Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Provides: tirdad Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-tirdad_30.9-1_all.deb Size: 76304 SHA256: 5a0f4262b934b652710666b79f9776761211e0cf9cfd56e95ae2f5efbf7a4a63 SHA1: cedfa32051c3fc2d83aa87e0fcdd8c266628b87e MD5sum: 9659d35238036dd8162aaaa55f6361e7 Description: dummy package to satisfy architecture specific dependency tirdad A metapackage, which satisfies the dependency on tirdad. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-xorg-vm Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Provides: xserver-xorg-video-vmware Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-xorg-vm_30.9-1_all.deb Size: 76296 SHA256: e109c9d5795aedc27a78f1f2cac6e39a4de2f441886ab44ec6d312b1427104c5 SHA1: 56d9ae05e989772d9d2d95f54b28e240dc4ced25 MD5sum: b580b76702eb1e1e85f924fc6dc77a2b Description: dummy dependency xserver-xorg-video-vmware A metapackage, which satisfies the dependency on xserver-xorg-video-vmware. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: genmkfile Version: 3:15.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 153 Depends: make, dpkg-dev, devscripts, strip-nondeterminism, sudo, perl, rsync, python3 Homepage: https://github.com/Kicksecure/genmkfile Priority: optional Section: misc Filename: pool/main/g/genmkfile/genmkfile_15.1-1_all.deb Size: 55280 SHA256: c6c4e71a206f25d8270f8662a6def44fa5003480cbd6d3daa99fa9c08db1c333 SHA1: 1785fea6c12194e80ba36d94b9b28172e482230f MD5sum: 2d317723c682a448de0dbb414d12bfde Description: Generic Makefile Makes packaging simpler. No more need to manually maintain 'make install' targets or distribution specific install files such as debian/pkg-name.install. . Files in etc/... in root source folder will be installed to /etc/..., files in usr/... will be installed to /usr/... and so forth. This should make renaming, moving files around, packaging, etc. very simple. Packaging of most packages can look very similar. . Provides common make targets such as 'make install', 'make dist', 'make installsim', 'make installcheck', 'make uninstall', 'make uninstallcheck', 'make distclean'. . Very extensible through file ./make-helper-overrides.bsh or folder ./make-helper-overrides.d. By using overrides, any make target can be easily extended using pre or post hooks or replaced. Override files which are executable will be used. Override files which are not executable will be skipped. . Contains a minimal Makefile while the heavy lifting is done by a bash script make-helper.bsh. . Building for multiple platforms possible, example: export make_cross_build_platform_list="i386 amd64" . Can call with lintian (static analysis tool for Debian packages). By default it will be using lintian if installed while failing open (non-zero exit code). lintian can be disabled. export make_use_lintian=false Or can be configured to fail closed (non-zero exit code). export make_use_lintian=true . Can build packages without chroot using debuild (default) or inside chroot using cowbuilder. To enable cowbuilder, use: export make_use_cowbuilder=true . Supports signing packages using debsign. (sign a Debian .changes and .dsc file pair using GPG) export make_use_debsign=true Package: gpg-bash-lib Version: 3:4.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 646 Homepage: https://github.com/Kicksecure/gpg-bash-lib Priority: optional Section: libs Filename: pool/main/g/gpg-bash-lib/gpg-bash-lib_4.5-1_all.deb Size: 490216 SHA256: 88bf1bad852a7a2f157da8343d1df8e0a93eb2cc3c5861a72e72952c74d32572 SHA1: 9ed1dd0668ad67babbf1ef3eb549b8d242e1e6a8 MD5sum: 6b536f52b9a62ee5312ea300bcc88d7c Description: gpg bash library Abstracts file verification into common functions. Allows detecting of stale files, i.e. detection downgrade or indefinite freeze attacks by implementing a valid-until like mechanism. . Internally parses gpg's --status-file output. . For better security. Package: grub-live Version: 3:5.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 64 Depends: grub-live-initramfs-tools | grub-live-dracut Provides: boot-live, grub-live-boot Homepage: https://github.com/Kicksecure/grub-live Priority: optional Section: misc Filename: pool/main/g/grub-live/grub-live_5.7-1_all.deb Size: 24716 SHA256: ea29ca7ece54921eea7d0909c5a19b1354ef195ae509b77fac27260cba09888c SHA1: 81e351d6f45581045cdc983193c834d3fe037d1b MD5sum: b8ed9861672db418c2d94879d5b25139 Description: grub live boot menu entry Allows booting the system in live mode. Meaning, no persistent modifications will be written to the disk. All changes stay in RAM. . Adds a grub live boot menu entry. . Existing grub boot entries stay unmodified. . No claims are made with regard to anti forensics. Package: grub-live-dracut Source: grub-live Version: 3:5.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 52 Depends: dracut Provides: boot-live, grub-live-boot Homepage: https://github.com/Kicksecure/grub-live Priority: optional Section: misc Filename: pool/main/g/grub-live/grub-live-dracut_5.7-1_all.deb Size: 22436 SHA256: 25d89d11948b28825c2520d6458875cee7a9d8a0d2155f07892f0f1558130bf3 SHA1: db0e2939db5e7a560c2e26233488bc2b53db72db MD5sum: 30b823cb628a3ad12d3e8b9797313975 Description: grub live dracut dependencies Dracut version metapackage for grub-live. . See also the package grub-live. Package: grub-live-initramfs-tools Source: grub-live Version: 3:5.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 52 Depends: live-boot, live-tools Provides: boot-live, grub-live-boot Homepage: https://github.com/Kicksecure/grub-live Priority: optional Section: misc Filename: pool/main/g/grub-live/grub-live-initramfs-tools_5.7-1_all.deb Size: 22448 SHA256: 429a55693102cd2d93878e2a28c06fb3b7d37f444612d2f640432f1438baf0aa SHA1: d89e9f41f590231d47a195c6519046ff761083ff MD5sum: 72292b1114d12ebbe415e97b320284c2 Description: grub live initramfs-tools dependencies initramfs-tools version metapackage for grub-live . See also grub-live package. Package: hardened-kernel Version: 3:4.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 474 Depends: build-essential, libssl-dev, libncurses-dev, fakeroot, libelf-dev, bison, flex, gcc-12-plugin-dev, curl, bc, kmod, cpio Homepage: https://www.kicksecure.com/wiki/Hardened-kernel Priority: optional Section: misc Filename: pool/main/h/hardened-kernel/hardened-kernel_4.7-1_all.deb Size: 157576 SHA256: d7c4ad2fcecca09a1d4089f73378269bed96a073ad797695f82eeb73d42c65a7 SHA1: f89b0cb1507000a08940eb0027d2f248a0b66ed2 MD5sum: 8c46c9b71b8ba3c000327650d64d8a79 Description: Hardened Kernel for Host and VMs This is a hardened kernel configuration for Whonix / Kicksecure. hardened-vm-kernel is designed specifically for virtual machines and hardened-host-kernel is designed for hosts. . Both configs try to have as many hardening options enabled as possible and have little attack surface. hardened-vm-kernel only has support for VMs and all other hardware options are disabled to reduce attack surface and compile time. . During installation of hardened-vm-kernel, it compiles the kernel on your own machine and does not use a pre-compiled kernel. This ensures the kernel symbols in the compiled image are completely unique which makes it far harder for kernel exploits. This is possible due to hardened-vm-kernel having only VM config options enabled which drastically reduces compile time. . During installation of hardened-host-kernel, the kernel is not compiled on your machine and it uses a pre-compiled kernel. This is because the host kernel needs most hardware options enabled to support most devices which makes compilation take a very long time. . The VM kernel is more secure than the host kernel due to having less attack surface and not being pre-compiled but if you want more security for the host, it is recommended to edit the hardened host config, enable only the hardware options you need and compile the kernel yourself. This makes the security of the host and VM kernel comparable. . Both configs were based on the default Debian config. . These kernels use the linux-hardened patch for further hardening. Custom hardening patches should be sent there. . This only supports LTS kernels as they have the least attack surface (stable kernels have more code and more bugs) and the best stability. . Build script /usr/share/hardened-vm-kernel/build does not run automatic yet. . Kernel does not get installed automatic yet. . See also development discussion: http://forums.whonix.org/t/kernel-recompilation-for-better-hardening Package: helper-scripts Version: 3:23.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 356 Depends: sudo, python3, python3-stem, python3-scapy, python3-yaml, bubblewrap, moreutils, equivs, safe-rm Replaces: anon-shared-helper-scripts, anon-ws-leaktest, curl-scripts, python-guimessages, python3-guimessages Homepage: https://github.com/Kicksecure/helper-scripts Priority: optional Section: misc Filename: pool/main/h/helper-scripts/helper-scripts_23.9-1_all.deb Size: 116072 SHA256: 7a6c15603430ab9a3a16fc9fc0f9b1acf465273c1a9a00beba69722b93223c3d SHA1: bc93e653a3570e837442af5137559e12ee769da1 MD5sum: b76537fd2498fa0a251eb1c69a858c93 Description: Helper scripts useful for Linux Distributions Contains a script for curl progress bar in terminal. Includes another script to convert curl exit codes to curl status messages. Implemented in bash. Common code that can be used by other scripts. . Library that can be used by other (anonymity related) packages that want to programmatically get information about states of Tor. Common code, that is often required. Includes bash and Python helper scripts. . Leak Test for Anonymity Distribution Workstations Integrated leak test. Needs to be manually run. See: https://www.whonix.org/wiki/Dev/Leak_Tests . Translatable GUI Messages Generic modules guimessage.py and translations.py. Called with two parameters: .yaml file path and yaml section. Return translations according to distribution local language (Python 'locale'). . Provides the ld-system-preload-disable wrapper to disable /etc/ld.so.preload per application via bubblewrap. Useful if hardened_malloc is being globally preloaded and needs to be disabled for some applications. . Provides the dummy-dependency script for quickly creating and installing dummy packages for working around package dependencies. Package: icon-pack-dist Version: 3:4.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 2696 Conflicts: anon-icon-pack Replaces: anon-icon-pack Provides: anon-icon-pack Homepage: https://github.com/Kicksecure/icon-pack-dist Priority: optional Section: misc Filename: pool/main/i/icon-pack-dist/icon-pack-dist_4.4-1_all.deb Size: 1478216 SHA256: 252814bef6c607acf880542f3b2f35ef167fa9e2bfbfb413e9883b8733756983 SHA1: cdd7bb994b890274e1f7aa0b11a88d383dc37c28 MD5sum: fda034651a6e8ac5a3d4702556379167 Description: Icon Pack for Derivative Distributions Contains icons, that are used by other derivative distribution specific packages. Others are welcome to use these icons according to their Free licenses as well. Package: initializer-dist Version: 3:6.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 70 Depends: psmisc, debsums, damngpl, safe-rm Conflicts: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Replaces: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Provides: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Homepage: https://www.kicksecure.com/wiki/Verifiable_Builds Priority: optional Section: misc Filename: pool/main/i/initializer-dist/initializer-dist_6.9-1_all.deb Size: 29692 SHA256: 322937ca7824ac23041944a1800aa5c91295e21eccdfed84a641cdf619b10215 SHA1: a95708b959fce9d5887f92ee68e9851e461d0072 MD5sum: 0ac0639b7e5298effc5b0cc71adff9f7 Description: Initializes Linux distributions, Release Upgrades and Legacy Contains a chroot-scripts-post.d script, that cleans up temporary files, logs. . Deletes random seeds. Since these should not be included in a redistributed image. Also sometimes called 'golden' image. . - /var/lib/urandom/random-seed - /var/lib/systemd/random-seed - /var/lib/random-seed - See also: https://systemd.io/RANDOM_SEEDS.html Package: kicksecure-base-files Version: 3:8.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 468 Depends: less, sudo Conflicts: diverts-etc++issue, diverts-etc++motd, diverts-etc++skel++.bashrc Provides: diverts-etc++issue, diverts-etc++motd, diverts-etc++skel++.bashrc Homepage: https://github.com/Kicksecure/kicksecure-base-files Priority: optional Section: misc Filename: pool/main/k/kicksecure-base-files/kicksecure-base-files_8.0-1_all.deb Size: 338520 SHA256: eee1122091972c4be0088af0f2862a025e77fbe9591685cdb804e95f784ffd9f SHA1: 18ebe65272129037063c4727b10cff73d9f65474 MD5sum: c093965e28614bc88c0c2ee96a7a2942 Description: Kicksecure base system miscellaneous files This package contains several important miscellaneous files, such as /etc/issue, /etc/motd, /etc/dpkg/origins/kicksecure, /etc/skel/.bashrc, /usr/bin/kicksecure, and others. . Sets the KICKSECURE environment variable to 1 as well. Package: kicksecure-cli Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: anon-apt-sources-list, dosfstools, kicksecure-base-files, kicksecure-default-applications-cli, kicksecure-dependencies-cli, kicksecure-recommended-cli, lvm2, ntfs-3g, obfs4proxy Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-cli_30.9-1_all.deb Size: 76296 SHA256: 4e0932d5f8ef354f2dddc078e568df466a98bb861f21fd2b8321c78057a1e212 SHA1: 003979f1661f95cf4013ee1c19f5b1841846a9fb MD5sum: 4c5a25efa81c56e184c8e114ad20305b Description: Kicksecure command line interface CLI A metapackage, which installs packages, for Kicksecure CLI. . Do not remove. Package: kicksecure-cli-host Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: kicksecure-cli, kicksecure-cli-host-packages-recommended, kicksecure-dependencies-system, non-qubes-enhancements-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-cli-host_30.9-1_all.deb Size: 76264 SHA256: 57802098d4af5ff87fecc6f1f39814745a5a7a5c3ca0e7f919071e4a4b779c10 SHA1: 90413ebd2fa36b54064cacbfa283a7876e8c886c MD5sum: 45a21550fa55aca3a098089291855b40 Description: Kicksecure Host command line interface CLI A metapackage, which installs packages, for Kicksecure CLI Host. . Do not remove. Package: kicksecure-cli-host-packages-recommended Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: tirdad Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-cli-host-packages-recommended_30.9-1_all.deb Size: 76284 SHA256: 199889f88cfaf4c64826574b2b66ebd8065736ac05788e9c8b1199db34edf524 SHA1: b9680ae6705fefc39e36f301f77b0ec24229b99b MD5sum: d6de6edefe53380a9212aa262bbb6134 Description: Recommended Kicksecure Host CLI Packages A metapackage, which installs packages, which are recommended for Kicksecure CLI Host. . Not useful to have inside Qubes. . Safe to remove, if you know what you are doing. Package: kicksecure-cli-vm Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: kicksecure-cli, kicksecure-dependencies-system, kicksecure-network-conf, non-qubes-enhancements-cli, vm-config-dist Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-cli-vm_30.9-1_all.deb Size: 76328 SHA256: a2a172bb2acea3c1d3342a1812cff0f517af6cd90e82d62149fdd187c2e39315 SHA1: 971d12a11617f9253f29066e7983580c7b881e6d MD5sum: 1ae01c191aab22cf3a50eff651e18f2e Description: Kicksecure command line interface CLI VMs A metapackage, which installs packages, for Kicksecure CLI Virtual Machines. . Not suitable for Qubes since it depends on packages not yet compatible with Qubes. . Do not remove. Package: kicksecure-default-applications-cli Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: codecrypt, diceware, dirmngr, equivs, extrepo, fuse, gpg, gpg-agent, magic-wormhole, makepasswd, pwgen Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-default-applications-cli_30.9-1_all.deb Size: 76336 SHA256: 8c98d3326df384d2a715b7593f2fcc5347c7c22cc0829a805df959c965ef3c31 SHA1: 3c45166ed77af59c43feda381c19ee9b9cd6f318 MD5sum: 347f1a28335cfdd3bb4b48f68003ccc3 Description: Default applications packages for Kicksecure A metapackage, which includes default packages to ensure, Kicksecure useful recommended tools are installed. . Safe to remove, if you know what you are doing. Package: kicksecure-dependencies-cli Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: apparmor-profile-dist, apt-transport-tor, apt-utils, bootclockrandomization, ca-certificates, desktop-config-dist, dialog, dist-base-files, gawk, init, initializer-dist, locales, menu, repository-dist, sdwdate, security-misc, setup-dist, sudo, timesanitycheck, usrmerge Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-dependencies-cli_30.9-1_all.deb Size: 76400 SHA256: 7be6ed1158202ddda45881baa6d312561daf7f4a79b0d9fbd7316c036af6ffcc SHA1: 1881bf3247de18bc675d2ebd6b045e37f8e5f769 MD5sum: 9942f21b2004f2c1cfd326e27b970e5e Description: Dependencies for hardened systems CLI A metapackage, which installs command line interface (CLI) packages which should be installed on hardened systems. . Do not remove. Package: kicksecure-dependencies-system Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: dracut | linux-initramfs-tool | initramfs-tools Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-dependencies-system_30.9-1_all.deb Size: 76288 SHA256: ddf1308113fcd0b188be90781e397aee181c0bfd175fd3a7a6ff9b1d1b2a51da SHA1: 8944ca794d33495dd10ea58c06bab5663526a4a3 MD5sum: a6897e0aef1405d6ef46c0b47fee714c Description: System for hardened systems A metapackage, which installs system packages which should be installed on hardened systems. . Currently only depends on boot process related dependencies. . Do not remove. Package: kicksecure-desktop-applications-recommended Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: catfish, electrum | dummy-dependency-electrum, firefox-esr | dummy-dependency, flatpak, gpa, keepassxc, kicksecure-welcome-page, msgcollector-gui, repository-dist-wizard, ristretto, sdwdate-gui, setup-wizard-dist, tumbler, vlc Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-desktop-applications-recommended_30.9-1_all.deb Size: 76384 SHA256: 7435da0bc41e9c15d786828cd490a5d42ea2c400c047b9fa448fefc38980413c SHA1: 8bf69ce460e199a34e2a269863c37fee131e7e6b MD5sum: 3ece95088d991ab269a24e91980a3c55 Description: Kicksecure Recommended Desktop Applications A metapackage, which installs recommended packages, for graphical user interface (GUI) Kicksecure. . Do not remove. Package: kicksecure-desktop-applications-xfce Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: gvfs, libexo-2-0, lxqt-sudo, mousepad, pkexec, policykit-1-gnome, polkitd, thunar, thunar-archive-plugin, thunar-volman, xarchiver, xfce4-terminal Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-desktop-applications-xfce_30.9-1_all.deb Size: 76368 SHA256: 1f72f9fe87839315f1ede5c71aaea4e00a63a641186b4f65ab81e2a31d6edc5d SHA1: 46ded9d9dc4fd9763e58192d549e6bd8b54103c3 MD5sum: 658c3078305788cdd26efcb04de6e87c Description: Recommended applications for hardened Xfce desktop GUI A metapackage, which installs minimal, yet complete enough to contain the very basics, Xfce applications. . Safe to remove. Package: kicksecure-desktop-environment-essential-gui Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: desktop-config-dist, desktop-config-dist-dependencies, gtk2-engines-pixbuf, libgl1-mesa-dri, mesa-vulkan-drivers, upower, x11-xserver-utils, xdg-desktop-portal, xserver-xorg, xserver-xorg-video-fbdev, xserver-xorg-video-vesa, xserver-xorg-video-vmware | dummy-dependency-xorg-vm Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-desktop-environment-essential-gui_30.9-1_all.deb Size: 76392 SHA256: 607e0a3aadc533193cd1ed7d72133686d266a0864b2eab9f08538d9da76c68e7 SHA1: e6695a04385a7fc42a9851625abc0edcc995de0e MD5sum: 9a08516a540b34b26ca5a84c1e89e817 Description: Desktop Depends GUI A metapackage, which installs dependencies for desktop environments, such as KDE, GNOME, etc. . kicksecure-desktop-environment-essential-xfce depends on this package. Package: kicksecure-desktop-environment-essential-xfce Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: accountsservice, gnome-brave-icon-theme, gnome-keyring, kicksecure-desktop-environment-essential-gui, lightdm, xdg-desktop-portal-gtk, xfce4 Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-desktop-environment-essential-xfce_30.9-1_all.deb Size: 76356 SHA256: dca28032f331ce5f3008ebbd5f998145264c7dd426379cd99d51069177a84cc0 SHA1: 2de7c48cc36efac5941b3bbb774a4e435e2e4c26 MD5sum: 041ba1d13c3a119e78846911f12c0eb0 Description: Recommended applications for hardened Xfce Desktop Environment A metapackage, which installs minimal, yet complete enough to contain a very basic Xfce Desktop Environment. . Safe to remove. Package: kicksecure-network-conf Version: 3:6.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 74 Depends: network-manager, iw, wpasupplicant, netbase, wireless-tools Homepage: https://github.com/Kicksecure/kicksecure-network-conf Priority: optional Section: misc Filename: pool/main/k/kicksecure-network-conf/kicksecure-network-conf_6.4-1_all.deb Size: 22228 SHA256: 786cf37f6488fedd5c312ba87feed93052e68b4794774730ce553ed112749fc5 SHA1: b5b5be536595e6457c7e4405477d3b4a2d2b7673 MD5sum: a72f3accb088e64d865de7671d5f6b48 Description: Network Configuration for Kicksecure CLI Disables systemd Predictable Network Interface Names. . Disables systemd-resolved during boot unless file /etc/dns-enable exists. . Disables systemd-resolved fallback DNS (which by default is set to Google). . Disables NetworkManager hostname management (useful in redistributed Kicksecure VMs). Package: kicksecure-network-conf-gui Source: kicksecure-network-conf Version: 3:6.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 48 Depends: network-manager-gnome Homepage: https://github.com/Kicksecure/kicksecure-network-conf Priority: optional Section: misc Filename: pool/main/k/kicksecure-network-conf/kicksecure-network-conf-gui_6.4-1_all.deb Size: 18868 SHA256: 71b93d49913676712677eda7f1f43455d55bc0fc631b500aa58efa7ad2822bca SHA1: 725be503327b4d6c9b0d1e31d59f35f1b8c2590c MD5sum: e117f3ee697301dc2aaef2292ee2ed35 Description: Network Configuration for Kicksecure GUI A metapackage with dependencies recommended for a Kicksecure GUI for networking. . See also kicksecure-network-conf. Package: kicksecure-packages-dependencies-pre Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Depends: dist-base-files, kicksecure-network-conf Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-packages-dependencies-pre_30.9-1_all.deb Size: 76288 SHA256: 362ef5cf63ae882b33e310e582090dff9804610d0dd554d3908256aac6169549 SHA1: 053e50a51f0934c94f85b0bd190269aa84f1932c MD5sum: d473dd7b88a6b2c9e1f1d40143918486 Description: Dependencies for Kicksecure that changes network related files A metapackage, which installs packages which Kicksecure depends on. Can not be merged into another package due to conflicts with chroot build process. . Do not remove. Package: kicksecure-qubes-cli Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: kicksecure-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-qubes-cli_30.9-1_all.deb Size: 76312 SHA256: 45ac5f1e3701095ed840f4117ef3dcb32c307710850f2dd2fbe9ac44795ae60d SHA1: 78ea1f88fdfcef4517dfd1ffe88b83fa42aa2aff MD5sum: 72c485e95ba364ade5d705dd588129a8 Description: Default packages for Kicksecure-Qubes CLI A metapackage, which installs packages, for Kicksecure on Qubes without recommended GUI applications. . Currently only depends on kicksecure-cli but useful for future maintenance in case Qubes specific changes will be required. . Do not remove. Package: kicksecure-qubes-gui Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: kicksecure-desktop-applications-recommended, kicksecure-desktop-applications-xfce, kicksecure-qubes-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-qubes-gui_30.9-1_all.deb Size: 76272 SHA256: 6d2b7d5864175030ac25c2847e9d64038feeb9ad3c03265fc89570092bf4c7f1 SHA1: 262380f1b4614ef37d560dfbbda79d9f2f84c8ad MD5sum: bdef3b8dc425d15f09c49047f52ea877 Description: Default packages for Kicksecure-Qubes GUI A metapackage, which installs packages, for Kicksecure on Qubes including recommended GUI applications. . Do not remove. Package: kicksecure-recommended-cli Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: apparmor-profiles-kicksecure | dummy-dependency-apparmor-profiles-kicksecure, apparmor-utils, bash-completion, boot-info-script, btrfs-progs, bzip2, curl, debian-keyring, dbus-user-session, distro-info-data, dnsutils, e2fsprogs, eject, file, haveged, hunspell-en-us, iotop, iproute2, iputils-ping, jitterentropy-rngd, less, libblockdev-crypto2, libpam-tmpdir, lsof, man-db, mesa-utils, most, nano, net-tools, open-link-confirmation, openvpn, p7zip-full, pciutils, pcmciautils, procps, secure-delete, sensible-utils, strace, sysfsutils, systemcheck, torsocks, traceroute, udisks2, unar, unzip, usability-misc, usbutils, vim, xz-utils, zip Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-recommended-cli_30.9-1_all.deb Size: 76600 SHA256: 1db8c0a1b12229abf0eacadd4b63afb72a2de512d5d45ba2637ae31b2f77048b SHA1: 36f9b9b1578b6bed0ffc64c199f833a0504b3a51 MD5sum: 6bf7c630d5510e3053e35ae5722a0748 Description: Recommended packages for Kicksecure A metapackage, which includes recommended packages to ensure, Kicksecure standard tools are available. . Safe to remove, if you know what you are doing. Package: kicksecure-shared-host-xfce Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: ddrescueview, discover, gddrescue, gnome-disk-utility, gnome-system-monitor, gparted, grub-live | grub-live-boot | boot-live, gsmartcontrol, hwinfo, icon-pack-dist, non-qubes-enhancements-gui, laptop-detect, lm-sensors, lshw, non-qubes-audio, nvme-cli, psensor, pv, sdwdate-gui, smart-notifier, smartmontools, xfce4-power-manager, xfce4-screenshooter, xfce4-xkb-plugin, xscreensaver Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-shared-host-xfce_30.9-1_all.deb Size: 76492 SHA256: bdbadda0a51321402bc994b81b41cb67193eefe8da8ab73162e90fbc2aee1c60 SHA1: 4e45568b71f6c059a218fc9f9d49a954b8b44c24 MD5sum: 7894941570e160904413aaae613f8d32 Description: Kicksecure Shared Host Xfce GUI A metapackage, which installs packages, which are recommended for Kicksecure Xfce Host as well as a Whonix-Host with a graphical user interface (GUI). . Safe to remove, if you know what you are doing. Package: kicksecure-welcome-page Version: 3:6.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 989 Depends: fonts-roboto-fontface, libjs-jquery Homepage: https://github.com/Kicksecure/kicksecure-welcome-page Priority: optional Section: misc Filename: pool/main/k/kicksecure-welcome-page/kicksecure-welcome-page_6.8-1_all.deb Size: 902784 SHA256: 97665bc91180edba5fe18755693cc605534b954ac3eb9f9ca13a2a8194d2f4d7 SHA1: 687d78a55096da54448ab76c7af4e919aca3ee22 MD5sum: 988e0a6844423f07bb2cc59b3c09f891 Description: Local Browser Homepage for Kicksecure Kicksecure specific browser start page. . Contains Kicksecure logo and Kicksecure links. . Safe to remove, if you know what you are doing. Package: kicksecure-xfce Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: kicksecure-cli, kicksecure-desktop-applications-xfce, kicksecure-desktop-environment-essential-xfce Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-xfce_30.9-1_all.deb Size: 76236 SHA256: 33f6b433eb2a3d90c5387656276bc3efd5e59d995701e8e09e0d1aea0377fec8 SHA1: 1b7ea1c449f36e1ae9a4871045500d67744447b4 MD5sum: ea6bd33f0ead5348dc4ad863ca5b8a3f Description: Kicksecure Xfce GUI A metapackage, which installs packages, for Kicksecure Xfce. . Do not remove. Package: kicksecure-xfce-host Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: kicksecure-cli-host, kicksecure-desktop-applications-recommended, kicksecure-network-conf, kicksecure-network-conf-gui, kicksecure-shared-host-xfce, kicksecure-xfce Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-xfce-host_30.9-1_all.deb Size: 76276 SHA256: 045f476dd0ea70a21b6ce914f64fccd9bee3ddd5ea21f05c968f4e6fc5ff154f SHA1: d6f4ea4f7a7e25b917126ef79d51a738856aab97 MD5sum: 82e18f836c57c8a962d6a917b1137bc2 Description: Kicksecure Host Xfce GUI A metapackage, which installs packages, for Kicksecure Xfce Host. . Do not remove. Package: kicksecure-xfce-vm Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: kicksecure-cli-vm, kicksecure-desktop-applications-recommended, kicksecure-network-conf-gui, kicksecure-xfce, non-qubes-audio, non-qubes-enhancements-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-xfce-vm_30.9-1_all.deb Size: 76344 SHA256: 5027a27f4c22cc0154ea6574148d8b1747569885ee99088296e89585cac4f360 SHA1: 85fb5cdcc6587e7f8323b622b3dcf4342a010384 MD5sum: 3d20f8ef177726621ab1d46e29b3f26e Description: Kicksecure Xfce GUI for VMs A metapackage, which installs packages, for Kicksecure Xfce in Virtual Machines. . Not suitable for Qubes since it depends on packages not yet compatible with Qubes. . Do not remove. Package: legacy-dist Version: 3:15.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 126 Depends: helper-scripts, apt-forktracer, deborphan Conflicts: vbox-disable-timesync, whonix-legacy Replaces: vbox-disable-timesync, whonix-legacy Provides: vbox-disable-timesync, whonix-legacy Homepage: https://github.com/Kicksecure/legacy-dist Priority: optional Section: misc Filename: pool/main/l/legacy-dist/legacy-dist_15.4-1_all.deb Size: 48660 SHA256: d017ca9edc7bb62f7c9817b511347a2cdf41f819f756e6cb011260261c0a15ad SHA1: 25539142f27d59e8e4fa7cff44c5bac56d7f79ca MD5sum: 3ab4fe742f27734e28a2893a49859135 Description: Prepare older Build Versions of Whonix for Upgrade Applies fixes required for upgrading from for example Whonix 8.x to Whonix 9.x etc. . Upgrades from Whonix 7.x or older versions is unsupported. . Safe to remove. Package: libvirt-dist Version: 3:10.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 141 Depends: adduser, qemu-kvm, libvirt-daemon-system, libvirt-clients, virt-manager, gir1.2-spiceclientgtk-3.0, dnsmasq-base, helper-scripts, msgcollector Conflicts: whonix-libvirt Replaces: whonix-libvirt Provides: whonix-libvirt Homepage: https://github.com/Kicksecure/libvirt-dist Priority: optional Section: misc Filename: pool/main/libv/libvirt-dist/libvirt-dist_10.3-1_all.deb Size: 53460 SHA256: d5a2fb9034390be3c7f51aa9e9cfe059fb432763aa1b2a00220f21f98e32e61e SHA1: 98f6ff975150eda4b316ba9dd9919c67fc94161c MD5sum: 6e495f4f43e0ac951e94db7a92d327ba Description: Whonix Libvirt XML Files for KVM and QEMU Libvirt XML files for Whonix-Gateway, Whonix-Workstation, Whonix-Custom-Workstation and Whonix's internal network. . Whonix-Host grub branding, motd and issue banner. . Whonix-Host boot popup. . See also: - https://www.kicksecure.com/wiki/KVM - https://www.kicksecure.com/wiki/QEMU Package: live-config-dist Version: 3:6.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 280 Depends: helper-scripts, pkexec, rsync, libglib2.0-bin, xdg-user-dirs Homepage: https://github.com/Kicksecure/live-config-dist Priority: optional Section: misc Filename: pool/main/l/live-config-dist/live-config-dist_6.7-1_all.deb Size: 140900 SHA256: 18669fa61e54d806e82b7435d78aac4c164336084e70b1d0dbd7a6876aad641a SHA1: 86233907070eb799d45bd37fdb5227cd5a2342fb MD5sum: c64c9e70d4c741d31b5296fd9c6b1479 Description: calamares-settings-kicksecure and maybe calamares-settings-whonix Installed in Host ISO Live. . Supposed to be removed in Host installed. . Kernel parameters required for Live ISO. Package: lkrg Version: 0.9.6.2-1 Architecture: all Maintainer: Mikhail Morfikov Installed-Size: 16 Depends: lkrg-dkms (= 0.9.6.2-1) Homepage: https://lkrg.org Priority: optional Section: kernel Filename: pool/main/l/lkrg/lkrg_0.9.6.2-1_all.deb Size: 9300 SHA256: 06099d7d14880eca02ea4e8355f25c9664668ed8420c956051bb61541958f41f SHA1: 77f32a0334d6359a084ddd96d6e0f2bed6c7c4ae MD5sum: 75c8c83ff7bbc8eb47ce425bebd69b13 Description: Linux Kernel Runtime Guard (LKRG) LKRG performs runtime integrity checking of the Linux kernel and detection of security vulnerability exploits against the kernel. . LKRG is a kernel module (not a kernel patch), so it can be built for and loaded on top of a wide range of mainline and distros' kernels, without needing to patch those. . That is only a dependency package to install the LKRG kernel module and also some systemd service in order to help to manage loading/unloading the module at system boot/shutdown. Package: lkrg-dkms Source: lkrg Version: 0.9.6.2-1 Architecture: all Maintainer: Mikhail Morfikov Installed-Size: 787 Depends: dkms (>= 2.1.0.0) Recommends: lkrg-systemd (= 0.9.6.2-1) Homepage: https://lkrg.org Priority: optional Section: kernel Filename: pool/main/l/lkrg/lkrg-dkms_0.9.6.2-1_all.deb Size: 103928 SHA256: 858cedaefb1958b7966548f5d5f5990835d09965c415c8f6bd4039d589919503 SHA1: ba764d1501476e67904976cfbb64aa7630fb182f MD5sum: 45700ff02b87e317c1bebf8b12dd191b Description: Linux Kernel Runtime Guard (LKRG) Source Code and DKMS LKRG performs runtime integrity checking of the Linux kernel and detection of security vulnerability exploits against the kernel. . LKRG is a kernel module (not a kernel patch), so it can be built for and loaded on top of a wide range of mainline and distros' kernels, without needing to patch those. . This package uses DKMS to automatically build the LKRG kernel module. Package: lkrg-systemd Source: lkrg Version: 0.9.6.2-1 Architecture: all Maintainer: Mikhail Morfikov Installed-Size: 24 Depends: lkrg-dkms (= 0.9.6.2-1), systemd Homepage: https://lkrg.org Priority: optional Section: kernel Filename: pool/main/l/lkrg/lkrg-systemd_0.9.6.2-1_all.deb Size: 10196 SHA256: 575d2ef015a44056b11b894004ee5e026361ff44a894628c197d18d435b48cc9 SHA1: 78f3ebfdc801a3510a1104f8783389578d9514d1 MD5sum: 70d7d1e11516ccf08559234cec2cfeec Description: Systemd integration for Linux Kernel Runtime Guard (LKRG) LKRG performs runtime integrity checking of the Linux kernel and detection of security vulnerability exploits against the kernel. . LKRG is a kernel module (not a kernel patch), so it can be built for and loaded on top of a wide range of mainline and distros' kernels, without needing to patch those. . This package provides systemd integration for the LKRG kernel module. Package: mediawiki-shell Version: 3:3.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 141 Depends: helper-scripts, jq, retry, python3 Homepage: https://github.com/Kicksecure/mediawiki-shell Priority: optional Section: misc Filename: pool/main/m/mediawiki-shell/mediawiki-shell_3.3-1_all.deb Size: 40932 SHA256: 10b4838d0c8d10d2167a58f1ea302645c8503e80600f1b350ba0274230fde31d SHA1: ee697f4a8fd44ad0ebd45b8b4677bcd3edfed0d1 MD5sum: f1899587021170e404719e269d099eda Description: bash shell scripts for usage of MediaWiki API Description here. . TODO Package: msgcollector Version: 3:13.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 217 Depends: python3, inotify-tools, procps, safe-rm, init-system-helpers (>= 1.52) Conflicts: diverts-etc++bash.bash+-+logout Provides: diverts-etc++bash.bash+-+logout Homepage: https://github.com/Kicksecure/msgcollector Priority: optional Section: misc Filename: pool/main/m/msgcollector/msgcollector_13.2-1_all.deb Size: 65680 SHA256: 4a0bc793704973ce3753f3cb1e0ee4b8e546a6967424db579e34454ad5e4f9d5 SHA1: 934db8fa1026344dcf51ee21b6e0fd2b3dc65e2b MD5sum: 1ff2d60a5f553dba1b7efd675154f2dd Description: Command Line Interface Messages Toolkit Library A programming library providing an application programming interface (API) that allows the programmer to output colored text in terminal user interfaces (CLI). . Applications can send messages to msgcollector which it collects and dispatches once instructed to do so by the application. . For clarity and avoidance of confusion, msgcollector does not collect any data. Applications that do not use msgcollector do not interact with msgcollector. It is roughly in the same category as ncurses but has of course much less and very different features. . For graphical user interface (GUI) support also install package msgcollector-gui. Package: msgcollector-gui Source: msgcollector Version: 3:13.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 73 Depends: msgcollector, wmctrl, python3-pyqt5, qtwayland5, zenity, libnotify-bin | kde-baseapps-bin, mate-notification-daemon, x11-utils, gnome-colors-common Homepage: https://github.com/Kicksecure/msgcollector Priority: optional Section: misc Filename: pool/main/m/msgcollector/msgcollector-gui_13.2-1_all.deb Size: 44264 SHA256: b26075aee93270e7aab870cd558216d27cfacb5018fdb4da32d02eda3103ef58 SHA1: dddede8e407983489db0e83287b92244045926c4 MD5sum: db5cd21798a5cb7d079d63257a398b4e Description: Graphical User Interface Toolkit Library A programming library providing an application programming interface (API) that allows the programmer to output colored text in graphical user interfaces (GUI). . Applications can send messages to msgcollector which it collects and dispatches once instructed to do so by the application. . For clarity and avoidance of confusion, msgcollector does not collect any data. Applications that do not use msgcollector do not interact with msgcollector. It is roughly in the same category as Qt or GDK but has of course much less and very different features. . A metapackage that installs required dependencies for graphical user interface support. Package: non-qubes-audio Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: libasound2, pavucontrol, pipewire-audio | pulseaudio, pipewire-pulse | pulseaudio, rtkit | pulseaudio, wireplumber | pipewire-media-session-pulseaudio | pulseaudio Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/non-qubes-audio_30.9-1_all.deb Size: 76368 SHA256: d598142f1ac50cb33ce406558e28dfcd87c2265507345bea127a0c3c559c7f44 SHA1: 2b626e978fb23c6adfa0dc4a5f34a52a8cf52374 MD5sum: 437d52ecc898e4f8d010cdcc879f7669 Description: Recommended packages for Audio Support in non-Qubes A metapackage, which includes recommended packages which are useful to provide audio support. . These are not useful in Qubes, since Qubes already has its own native audio implementation. . Safe to remove, if you know what you are doing. Package: non-qubes-enhancements-cli Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: acpi-support, console-common, console-setup, cryptsetup, dmsetup, grub-live | grub-live-boot | boot-live, kbd, keyboard-configuration, libzulucrypt-plugins, swap-file-creator, tirdad, udev, zulucrypt-cli Replaces: non-qubes-vm-enhancements-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/non-qubes-enhancements-cli_30.9-1_all.deb Size: 76460 SHA256: 83e689ba2db0120eb85ad7ab607cf8493a85c3341f5fd4eab977448196bf72c2 SHA1: aa43325a2e9cc2faa49972f80e71e361810a4364 MD5sum: 5df81a8fef0d4740989c6b2de3b4a4ac Description: Recommended packages for terminal based machines (CLI) A metapackage, which includes recommended packages which are useful within CLI based non-Qubes machines. . These are not useful in Qubes, since Qubes already has native implementations for those. . Safe to remove, if you know what you are doing. Package: non-qubes-enhancements-gui Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: non-qubes-enhancements-cli, rads, zulucrypt-gui Replaces: non-qubes-vm-enhancements-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/non-qubes-enhancements-gui_30.9-1_all.deb Size: 76368 SHA256: b4b9de36962d0b48dc61f24579bd84eb604d5c3d7fc9cfec9ef8b2b022db2256 SHA1: bdebf3289e30cabc9f00a89687c1172ec489e853 MD5sum: 63272337657bfae504449ed850663edb Description: Recommended packages for graphical systems (GUI) A metapackage, which includes recommended packages which are useful within GUI based non-Qubes machines. . These are not useful in Qubes, since Qubes already has native implementations for those. . Safe to remove, if you know what you are doing. Package: open-link-confirmation Version: 3:6.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 87 Depends: sensible-utils, icon-pack-dist, msgcollector, xdg-utils Recommends: tb-starter, tb-updater, tb-default-browser Homepage: https://github.com/Kicksecure/open-link-confirmation Priority: optional Section: misc Filename: pool/main/o/open-link-confirmation/open-link-confirmation_6.3-1_all.deb Size: 30004 SHA256: c4680c336014d763f7ea7bc9244f64cf75b35a91e42ea02ea5ed27250a19edb2 SHA1: 31e8628890440cba3f86a544a8aff39e086f237d MD5sum: dde270ce9543c66c933658b68a82bbdf Description: Asks for confirmation before opening links Asks before a link is (accidentally) opened in a browser. Links are opened in x-www-browser. . Currently only the Tor Browser starter from the tb-starter package (by Whonix developers) supports using open-link-confirmation. Shell wrappers could be written to support other browsers as well. . On an Anonymity Gateway (when the anon-gw-base-files package is installed), it honors the $EDITOR environment variable (falls back to mousepad if unset), asks if a file should be opened in an editor before opening it and informs, that opening links on a Gateway is unsupported for security reasons. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: orca-screen-reader-support Source: kicksecure-meta-packages Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 104 Pre-Depends: legacy-dist Depends: gstreamer1.0-plugins-good, libatk-adaptor, libgail-common, non-qubes-audio, orca, python3-gst-1.0, sound-icons, speech-dispatcher-espeak-ng, xbrlapi Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/orca-screen-reader-support_30.9-1_all.deb Size: 76364 SHA256: 1db1bed94885c11531ba23faab5c22f6ac592ca7a7e9aa419be27626d413bf56 SHA1: 4e0a4ce2c313d827fc0c1e04acec6b0b3c0141e7 MD5sum: 8d5bfc892021c019385d5596ef3fa6e9 Description: dependencies for the orca screen reader A metapackage, which includes depencency packages for the orca screen reader. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: rads Version: 3:7.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 111 Depends: systemd Homepage: https://www.kicksecure.com/wiki/RAM_Adjusted_Desktop_Starter Priority: optional Section: misc Filename: pool/main/r/rads/rads_7.2-1_all.deb Size: 34736 SHA256: c5c4eb52aabb77a3b939761d9603c8e6b5d525a059d2019ee2db32a162ccddd7 SHA1: 18a4365295514955f6a2dda212995f066d486a33 MD5sum: 1f53a3253b7760768ccb05489d9f32cd Description: RAM Adjusted Desktop Starter If there is more than X MB RAM in total, the desktop environment will be started. . If less than X MB RAM in total (for example, only 196 MB RAM in total), no desktop environment will be started. . This should be quite convenient, because users with low RAM could reduce Y MB and even if they sometimes wanted to configure/check something, they could assign 512 RAM and automagically boot into the graphical desktop. There are also many settings in /etc/rads.d/ (stackable) to configure this feature, so if you want, you can also add a lot RAM, but not boot into a desktop environment, or use different display managers and so on. . Most useful in virtual machines. Package: ram-wipe Version: 3:2.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 101 Depends: helper-scripts, dracut, kexec-tools Homepage: https://github.com/Kicksecure/ram-wipe Priority: optional Section: misc Filename: pool/main/r/ram-wipe/ram-wipe_2.8-1_all.deb Size: 24312 SHA256: b4b2a53efd5144066ec7d7ad426f2414b242915564fd8a3ec8ca629d97b2fb5e SHA1: 1eb022d4f18a043b9d21442a00d2af1bfaf715cb MD5sum: dcf1591ba9aad46bdd39f0deefe5657d Description: Wipe RAM on shutdown and reboot A dracut module that wipes RAM on shutdown and reboot. . Not implemented for initramfs. Package: repository-dist Version: 3:11.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 198 Depends: helper-scripts, lsb-release, python3:any Homepage: https://www.kicksecure.com/wiki/Project-APT-Repository Priority: optional Section: misc Filename: pool/main/r/repository-dist/repository-dist_11.3-1_all.deb Size: 104028 SHA256: 453aa93f1ad7a012868508b5ddf4007211efa088b325e6ec8dc02997b02b4a21 SHA1: 8a310ddb16df1790611d307329dc93dccc45f89a MD5sum: 5e0f4841637df3378a02b35b503569fb Description: Derivative APT Repository Command Line Interface (CLI) This tool can always be used to enable either Derivative's stable, testers or developers repository or to disable Derivative's repository. . Derivative's APT Repository is not enabled by default. Some users prefer this for trust/security reasons. . On first boot of Derivative, the Derivative Repository Tool gets automatically started by setup-dist. The user is free to either leave Derivative's repository disabled or to configure it as desired. . Technically speaking, this tool creates or deletes file `/etc/sources.list.d/derivative.list`. . Using APT `signed-by`. Package: repository-dist-wizard Source: repository-dist Version: 3:11.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 70 Depends: pkexec, python3-pyqt5, python3:any, qtwayland5 Homepage: https://www.kicksecure.com/wiki/Project-APT-Repository Priority: optional Section: misc Filename: pool/main/r/repository-dist/repository-dist-wizard_11.3-1_all.deb Size: 36952 SHA256: dd110478dede74ab66304973d0b6d3223e9db0eebc4d87e1447ac0f4520fe7af SHA1: 0d83eed9f1064d3e870762f620ec4e3ca2fa28be MD5sum: 7ebb15a6fdf9e575cc1a2e428305ac4d Description: Derivative APT Repository Graphical User Interface (GUI) This tool can always be used to enable either Derivative's stable, testers or developers repository or to disable Derivative's repository. . This is a metapackage depending on the required packages for the GUI (Graphical User Interface). Package: ro-mode-init Version: 3:2.8-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 60 Depends: live-boot, live-boot-initramfs-tools, live-tools Conflicts: grub-default-live, grub-live Replaces: grub-default-live, grub-live Provides: boot-live Homepage: https://github.com/Kicksecure/ro-mode-init Priority: optional Section: misc Filename: pool/main/r/ro-mode-init/ro-mode-init_2.8-1_all.deb Size: 19004 SHA256: 25f626fc9873ebbaf06d53f745b5918d62519bf0c27e0fa4c45ac33adc609ec0 SHA1: a848ea36168f059ba2c0e1beb98f00f0bf4ec521 MD5sum: 92a9416b15691d729af03ddb6aeac9b9 Description: Detects read-only disks and automatically enables live-boot Allows booting the system in live mode. Meaning, no persistent modifications will be written to the disk. All changes stay in RAM. . No claims are made with regard to anti forensics. Package: sandbox-app-launcher Version: 0:6.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 131 Depends: sudo, bubblewrap, apparmor, libseccomp-dev, helper-scripts, dbus-x11 Homepage: https://www.kicksecure.com/wiki/Sandbox-app-launcher Priority: optional Section: misc Filename: pool/main/s/sandbox-app-launcher/sandbox-app-launcher_6.6-1_all.deb Size: 48376 SHA256: 5d2321904e83310698a1730f0bd919f87d5b6e7dbc81ff3f0d603ad8d319bd77 SHA1: cf837cdb2e3469381c9a2345c892d0500a686515 MD5sum: 51b74b9c6fa87389b7e428b698e2a923 Description: application launcher to start apps in a restrictive sandbox sandbox-app-launcher runs each app as its own user, in a bubblewrap sandbox and confined by apparmor. . The directory, `/shared`, is shared across all app sandboxes to transfer files across. . This implements a permissions system to configure what apps can access. There are currently 5 available permissions: . * Network access . * Webcam access . * Microphone access . * Shared storage access (read-only or read-write) . * Dynamic native code execution . All apps the user installs will be automatically configured to run in the sandbox and a prompt will ask the user which permissions they wish to grant the application (not implemented yet). . Currently a WIP and not for actual use. Package: sdwdate Version: 3:24.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 339 Depends: sudo, bc, helper-scripts, adduser, gcc, libc6-dev, python3-stem, python3-dateutil, python3-socks, python3-sdnotify, python3-requests, python3, tor, python3:any Recommends: timesanitycheck, bootclockrandomization Conflicts: time-daemon Provides: time-daemon Homepage: https://www.kicksecure.com/wiki/Sdwdate Priority: optional Section: misc Filename: pool/main/s/sdwdate/sdwdate_24.0-1_all.deb Size: 147292 SHA256: b1d654961688c09953c1ebf72aa7747c724100d78e0d3f67e6f25e0760b0b768 SHA1: c2b51358915b00d61c350c3018e15aae07f320ab MD5sum: d5fa2dc06043f20c1012c021c4b2cf7c Description: Secure Distributed Network Time Synchronization Time keeping is crucial for security, privacy, and anonymity. Sdwdate is a Tor friendly replacement for rdate and ntpdate that sets the system's clock by communicating via onion encrypted TCP with Tor onion webservers. . At randomized intervals, sdwdate connects to a variety of webservers and extracts the time stamps from http headers (RFC 2616). Using sclockadj option, time is gradually adjusted preventing bigger clock jumps that could confuse logs, servers, Tor, i2p, etc. . This package contains the sdwdate time fetcher and daemon. No installation on remote servers required. To avoid conflicts, this daemon should not be enabled together with ntp or tlsdated. Package: sdwdate-gui Version: 1:10.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 239 Depends: sudo, python3, python3-pyqt5, qtwayland5, helper-scripts, sdwdate, adduser Homepage: https://www.kicksecure.com/wiki/sdwdate-gui Priority: optional Section: misc Filename: pool/main/s/sdwdate-gui/sdwdate-gui_10.2-1_all.deb Size: 90160 SHA256: 48ceba52b3331d7aeefb4227fc90874a2181cd697eabc0613f46e8f62c4c24fc SHA1: eb34453cf02d063484af59b38a6d169a35ec61da MD5sum: 92305dcf2d1faa8ddfabc6c1519bce1a Description: Sdwdate Monitor sdwdate-gui is a systray icon monitor for sdwdate: checks sdwdate's status and modify the tray icon accordingly. In addition, it allows the user to restart sdwdate and view the log. Package: security-misc Version: 3:40.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 556 Depends: adduser, apparmor-profile-dist, dmsetup, helper-scripts, libcap2-bin, libglib2.0-bin, libpam-modules-bin, libpam-runtime, libpam-umask, python3, secure-delete, sudo, dconf-gsettings-backend | gsettings-backend Replaces: anon-gpg-tweaks, swappiness-lowest, tcp-timestamps-disable Homepage: https://www.kicksecure.com/wiki/Security-misc Priority: optional Section: misc Filename: pool/main/s/security-misc/security-misc_40.8-1_all.deb Size: 196572 SHA256: c09ee3a17b4380df15815f3944fe6ae0a462931a8e129dfc748ee44ccef62e01 SHA1: 1e7c0b67c4e8d4a23948396a1eb635753e45aebb MD5sum: e825ab92c31a1a3b499da947107cd5db Description: Enhances Miscellaneous Security Settings https://github.com/Kicksecure/security-misc/blob/master/README.md . https://www.kicksecure.com/wiki/Security-misc . Discussion: . Happening primarily in Whonix forums. https://forums.whonix.org/t/kernel-hardening/7296 Package: serial-console-enable Version: 3:4.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 61 Homepage: https://github.com/Kicksecure/serial-console-enable Priority: optional Section: misc Filename: pool/main/s/serial-console-enable/serial-console-enable_4.1-1_all.deb Size: 17528 SHA256: bca714e19b0cb79468a7a4e5c21d1c773f50f565adc050a051eee9bf0d3de4c5 SHA1: afcf614e4ebf7b99974a4addcd237c6e1e769e02 MD5sum: cc005f12c21ae426e1b4aeaaab6c6260 Description: Enables serial console Ships a /etc/default/grub.d/30_serial_console.cfg configuration file, that enables serial console. . Enables /lib/systemd/system/getty.target.wants/serial-getty@ttyS0.service by creating a symlink from: /lib/systemd/system/serial-getty@.service to: /lib/systemd/system/getty.target.wants/serial-getty@ttyS0.service . Useful for serial console login such as into Whonix KVM VMs from the host operating system. . Forum discussion: https://forums.whonix.org/t/how-do-i-enter-the-whonix-shell-from-cli/7271 . Safe to remove if you do not require serial console login such as: virsh console vm-name Package: setup-dist Version: 3:10.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 138 Depends: helper-scripts, dialog, sudo, menu, python3 Conflicts: whonixsetup Replaces: whonixsetup Provides: whonixsetup Homepage: https://github.com/Kicksecure/setup-dist Priority: optional Section: misc Filename: pool/main/s/setup-dist/setup-dist_10.3-1_all.deb Size: 45868 SHA256: 19df711513193ee030ea0856e0cfcd29d6df3beec40a5b2c2c0e5bcb32e09b03 SHA1: c9b1971a698a3b94712ea2797ad13e674767c03c MD5sum: 56545c1ed59979de51dd3c56ddc02891 Description: First Time Connection Setup Disclaimer. . When the derivative starts for the first time, it won't automatically connect to the public Tor network. This is useful for users who want to hide Tor from their ISP. setup-dist is automatically started, which educates about different methods to connect (public Tor network, bridges, etc.). Package: setup-wizard-dist Version: 3:11.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 130 Depends: setup-dist, python3-yaml, python3-distutils, helper-scripts, python3, x11-xserver-utils Recommends: icon-pack-dist Conflicts: whonix-setup-wizard Replaces: whonix-setup-wizard Provides: whonix-setup-wizard Homepage: https://github.com/Kicksecure/setup-wizard-dist Priority: optional Section: misc Filename: pool/main/s/setup-wizard-dist/setup-wizard-dist_11.1-1_all.deb Size: 55580 SHA256: 6f0bc7c9bcc1e4316c985ce35ea7504f17e9ac5f78ba7f5d2155263f14de32fd SHA1: 6fd8570b9d04e672877132f32597687e8bf4696d MD5sum: 6c985c79cb3a676fcaaea868d72fbca4 Description: First Boot Setup Disclaimer. . When distribution starts for the first time, it won't automatically connect to the public Tor network. This is useful for users who want to hide Tor from their ISP. Anon Connection Wizard is automatically started, which educates about different methods to connect (public Tor network, bridges, etc.). Package: swap-file-creator Version: 3:7.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 83 Depends: helper-scripts, cryptsetup-bin, bc Recommends: haveged, jitterentropy-rngd Homepage: https://www.kicksecure.com/wiki/Swap-file-creator Priority: optional Section: misc Filename: pool/main/s/swap-file-creator/swap-file-creator_7.2-1_all.deb Size: 30808 SHA256: e04e7d91d3d2c817cc96b1e43217ba9b5edaa79ca5abe134297196ec1a0f36de SHA1: f66542e9ade34dd80a52d920fecd3c03a2846867 MD5sum: 42ac4a3c631a594026adc006be4c5f33 Description: Adds encrypted swap file to the system On every boot, creates a new encrypted swapfile with a random key. . Useful for systems with low RAM such as inside virtual machines. . Has an option to shred the swapfile on shutdown. Package: systemcheck Version: 3:30.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 432 Depends: dist-base-files, python3, signify-openbsd, curl, ca-certificates, msgcollector, psmisc, sudo, vrms, libarchive-tools, helper-scripts, net-tools, systemd, adduser, security-misc, spectre-meltdown-checker, apparmor-profile-dist Recommends: icon-pack-dist, msgcollector-gui Conflicts: apparmor-profile-whonixcheck, whonixcheck Replaces: apparmor-profile-whonixcheck, whonixcheck Homepage: https://www.kicksecure.com/wiki/systemcheck Priority: optional Section: misc Filename: pool/main/s/systemcheck/systemcheck_30.9-1_all.deb Size: 139660 SHA256: e2e620e3460d3616255e3c9ea83130d0ec1e18d23fc112af9a82215504c5917c SHA1: 0fc4376729eab4339bedba6004d134d747045fdb MD5sum: 308dba9be5167317bd1b7633aa870594 Description: Anonymity and security check Checks many important aspects for better security. . Only checks things. Does not change things. . Safe to remove. Package: tb-default-browser Version: 3:5.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 78 Depends: tb-starter Recommends: tb-updater, open-link-confirmation Homepage: https://github.com/Kicksecure/tb-default-browser Priority: optional Section: misc Filename: pool/main/t/tb-default-browser/tb-default-browser_5.0-1_all.deb Size: 24052 SHA256: 46f1288f71daacb838d97e21828cd6f3aacf61f666a9a9743767a2975a0dd2ec SHA1: b6993d53bd252cfcd53e3735ad44a0e6efc0eab9 MD5sum: 746a41c51f9e1848b9ce33e9e238784a Description: Configures system to use /usr/bin/torbrowser as default browser Sets /usr/bin/x-www-browser to /usr/bin/torbrowser. . Sets /usr/bin/gnome-www-browser to /usr/bin/torbrowser. . Sets BROWSER environment variable to /usr/bin/x-www-browser by using /etc/profile.d/ and /etc/X11/Xsession.d/ hooks. . Registers of MIME type handlers to 'torbrowser'. . Sets KDE's default browser to x-www-browser. This only takes effect for newly created user accounts. Not for existing user accounts. This is most useful to help Linux distribution maintainers setting divergent defaults. . See also: The Default Browser on Linux Debacle http://blog.codef00.com/2011/02/18/the-default-browser-on-linux-debacle/ . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: tb-starter Version: 3:16.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 165 Depends: msgcollector Recommends: tb-updater, tb-default-browser, open-link-confirmation, icon-pack-dist Provides: torbrowser-launcher Homepage: https://github.com/Kicksecure/tb-starter Priority: optional Section: misc Filename: pool/main/t/tb-starter/tb-starter_16.8-1_all.deb Size: 65204 SHA256: 9f4418963b295f3cec8d54fdd949ea70f7d30caf884414db1ed0818062e94feb SHA1: 14f199144f19c478705fb49ef9604b18dffa5cba MD5sum: 06f7f7c59b27265802c6e615e17c0e55 Description: Tor Browser Starter (by Whonix developers) Both, a starter for Tor Browser. Provides security hardening, integration with Debian, Whonix and Qubes. . Starter. . - Tor Browser Starter start menu entry and `/usr/bin/torbrowser` starter. Starts `/home/user/.tb/tor-browser/start-tor-browser`. . When config option tb_hardening=true is set or when using command line option --hardening, firejail will be used. . Uses open-link-confirmation if available. . Prompts to install the browser if not yet installed. . Changes directory into browser directly before startup. . Custom homepage support. . Qubes integration. . Sanity tests: - Aborts if detected being run as root. - Aborts in Qubes TemplateVM. - Aborts in Qubes DVM Template. - Waits for Qubes mount dirs and gui agent being ready. . In Qubes AppVM copies browser from root image to private image at first start. . Tor Browser documentation by Whonix. . - https://www.whonix.org/wiki/Tor_Browser - https://www.whonix.org/wiki/Tor_Browser/Advanced_Users . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: tb-updater Version: 3:35.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 520 Depends: msgcollector-gui, curl, psmisc, gpg-bash-lib, pv, libarchive-tools, sudo, jq, libdbus-glib-1-2, python3 Recommends: tb-starter, icon-pack-dist, helper-scripts Suggests: tb-default-browser, open-link-confirmation Homepage: https://github.com/Kicksecure/tb-updater Priority: optional Section: misc Filename: pool/main/t/tb-updater/tb-updater_35.2-1_all.deb Size: 238936 SHA256: 5a7861d84f65e649a2fd23785a01e0b126b25f2c23ebac5c911cc873f920e0d9 SHA1: 49373b87c2ce5d6d0eb6612943b3f3f1a1761f23 MD5sum: 8cde6f5801952fbcb80fa3d28b8f5ffc Description: Tor Browser Downloader by Whonix developers Automates download and verification of Tor Browser from The Tor Project's website. Useful for initial installation of Tor Browser, clean re-installations of Tor Browser and keeping newly created Qubes AppVMs inherited from updated Qubes TemplateVMs can ship up to date versions of Tor Browsers. . Incapable of preserving of updating and preserving user data. Use Tor Browser's internal updater for that purpose. Notifies about already exiting installations of Tor Browser. Renamed rather than deletes old versions of Tor Browsers to avoid user data loss. . Has a cli and a gui mode. Can auto detect latest version numbers or use user configured version numbers. Comes with a download confirmation screen that lets users choose which version to download. [1] Has a installation confirmation screen [2] that enables users to detect indefinite freeze and rollback attacks. . Integrates well with tb-starter, tb-default-browser and open-link-confirmation package as well as with Qubes. . Without the helper-scripts package installed, the GUI will not move the progress bar. . If you have the helper-scripts package installed, it will show a nicer progress bar when run in terminal and more meaningful curl exit code messages, when curl failed. . When having the helper-scripts package installed (recommended for Anonymity Distributions), Tor Browser Downloader will check, that Tor is enabled, that no package manager is currently running and that Tor finished bootstrapping before download attempts. . Supports being run inside chroot and from Debian maintainer postinst script. . Qubes integration: . - Up-to-date browser versions made available to freshly created AppVMs and DispVMs. - In DispVM mounts browser folder which resides in root image to user home folder rather than copying for faster browser startup. . This package is produced independently of, and carries no guarantee from, The Tor Project. . [1] https://www.whonix.org/wiki/Tor_Browser#Download_Confirmation_Screen [2] https://www.whonix.org/wiki/Tor_Browser#Installation_Confirmation_Screen Package: timesanitycheck Version: 3:6.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 78 Homepage: https://www.whonix.org/wiki/Dev/TimeSync Priority: optional Section: misc Filename: pool/main/t/timesanitycheck/timesanitycheck_6.6-1_all.deb Size: 26584 SHA256: 9f6df2a5378375f1d445ce134db69462c544c30a01c29826e7d6da7f92ce7c3c SHA1: 1cad7bbee4b4a91e49cbebc2546dc9a3e86d4ec9 MD5sum: bad3ed3cebbcc728e38c1dfddbfe348c Description: Checks if the system clock is sane between build timestamp and expiration date Reports, if clock is sane and not slower than build timestamp or faster than expiration date (configurable, default currently set to 17 MAY 2033 10:00:00). . This should catch situations, where the host's clock is too much off (CMOS battery defect, user mistakenly set a very wrong date, etc.), resulting in network time synchronization tools (such as sdwdate) no longer being able to correct the clock; catch eventual bigger bugs in network time synchronization tools; and some types of attacks on network time synchronization. Package: tor-control-panel Version: 1:6.6-1 Architecture: all Maintainer: troubadour Installed-Size: 178 Depends: anon-connection-wizard, helper-scripts, pkexec, policykit-1-gnome | polkit-1-auth-agent, python3, python3-ipy, python3-pyqt5, python3-stem, qtwayland5 Recommends: obfs4proxy, tor Homepage: https://www.whonix.org/wiki/Tor-control-panel Priority: optional Section: misc Filename: pool/main/t/tor-control-panel/tor-control-panel_6.6-1_all.deb Size: 68204 SHA256: 729ce2d086eba1b6d3d99503af6387c445d11b4f090dad91029021418d065d38 SHA1: b1dbae96b0d64f8aefb0aed6b2fd2979cb4b99b1 MD5sum: 2b783ba245ea07bcfe10d55b7cc51ca8 Description: Tor Control Graphical User Interface WARNING: Not (yet) a standalone ready to use outside of Whonix: . tor-control-panel is a Tor controller. . tor-control-panel is produced independently from the Tor anonymity software and carries no guarantee from The Tor Project about quality, suitability or anything else. Package: tor-ctrl Version: 3:5.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 75 Depends: tor, netcat-openbsd, xxd Homepage: https://gitweb.torproject.org/torspec.git/tree/control-spec.txt Priority: optional Section: misc Filename: pool/main/t/tor-ctrl/tor-ctrl_5.5-1_all.deb Size: 26652 SHA256: b6aa1262eea60201441b300b8d0e4d8f358e53c1ef6b036771f9dc8a6038c01a SHA1: 6e4c7af0d04a213ee001bed0d20162fc1db8ff21 MD5sum: 1afa21e6ce9e33bfd2a817cdbefd5a20 Description: Tor controller command line tool Command line tool for setting up stream for communication from the Tor Controller's (client) to a Tor process (server). The client send commands using TCP sockets or Unix-domain sockets and receive replies from the server. . https://gitweb.torproject.org/torspec.git/tree/control-spec.txt . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: tor-geoipdb Source: tor Version: 0.4.8.13-2~d12.bookworm+1 Architecture: all Maintainer: Peter Palfrader Installed-Size: 19566 Depends: tor (>= 0.4.8.13-2~d12.bookworm+1) Breaks: tor (<< 0.2.4.8) Replaces: tor (<< 0.2.4.8) Homepage: https://www.torproject.org/ Priority: optional Section: net Filename: pool/main/t/tor/tor-geoipdb_0.4.8.13-2~d12.bookworm+1_all.deb Size: 2415852 SHA256: 8402c2171b54cfc3919803471a06b25871e64b639295bf6ecde8b8c1d25a0dfc SHA1: bd973168ef5d4db605ee665cb7c806ea1e4acee3 MD5sum: 7d1b3bab1ffa3d1c8654559d96880c9d Description: GeoIP database for Tor This package provides a GeoIP database for Tor, i.e. it maps IPv4 addresses to countries. . Bridge relays (special Tor relays that aren't listed in the main Tor directory) use this information to report which countries they see connections from. These statistics enable the Tor network operators to learn when certain countries start blocking access to bridges. . Clients can also use this to learn what country each relay is in, so Tor controllers like arm or Vidalia can use it, or if they want to configure path selection preferences. Package: usability-misc Version: 3:23.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 636 Depends: sudo, policyrcd-script-zg2, adduser, python3, damngpl, helper-scripts Replaces: gpl-sources-download, grub-screen-resolution, scurl Homepage: https://github.com/Kicksecure/usability-misc Priority: optional Section: misc Filename: pool/main/u/usability-misc/usability-misc_23.2-1_all.deb Size: 214440 SHA256: ea018437e0fbbb6e53c702572ec90cbcade1c1faf5ed9a72a59c700865cf2ca9 SHA1: 8ce2db72ab148ee8202b84fee4e636dc66f87ef5 MD5sum: 78c31cb45147dc94f5c44ed60b84da6b Description: Misc usability improvements Enables auto login for user `user` in `lightdm`. `/etc/lightdm/lightdm.conf.d/30_autologin.conf` https://www.kicksecure.com/wiki/Desktop#Disable_Autologin . Creates folders /home/user/Downloads and /home/user/Pictures. . Adds user "user" to group libvirt as well as to group kvm. . Ships a file /etc/sudoers.d/user-passwordless that contains comments and "#user ALL=(ALL:ALL) NOPASSWD:ALL". Lets user "user" easily run all commands without password. Disabled (out commented) by default. . Simplifies running OpenVPN as unprivileged user. . Ships a FoxyProxy add-on configuration file for use with Tor Browser. . Provides apt-get-noninteractive that is a simple wrapper around apt-get, that sets all required environment variables to make it interactive as well as to prevent systemd service starts and restarts during apt-get. . Sets mousepad as the default editor for environment variable VISUAL is unset and if mousepad is installed. . Disable sudo default lecture. /etc/sudoers.d/sudo-lecture-disable . Add pwfeedback to sudo Defaults so password asterisks are shown while typing. /etc/sudoers.d/pwfeedback . xfce4-terminal: . * Disables automatic scroll on output when manually scrolled up to make reading output such as "sudo journalctl -f" easier. Automatic scroll on output still happening in default when not manually scrolling up beforehand first. . * Enables unlimited scrollback by default to avoid output from being truncated. . Ships gsudoedit, a wrapper to run sudoedit with a graphical editor. . Bisq workarond "sudo mkdir -p /usr/share/desktop-directories" as per https://github.com/bisq-network/bisq/issues/848 . gpl_sources_download GPL'ed source code of all installed packages. Used damngpl to get a list of all GPL'ed packages, then downloads them using apt-get source. . SSL curl wrapper: Simple wrapper called scurl, that adds "--tlsv1.3 --proto =https" in front of all invocations of "curl" when running "scurl". . Sets 1024x768 as boot screen resolution Ships a /etc/default/grub.d/30_screen_resolution.cfg configuration file, that injects "vga=0x0317" into the GRUB_CMDLINE_LINUX_DEFAULT variable. Package: vm-config-dist Version: 3:10.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 135 Depends: sudo, adduser, p7zip-full Replaces: power-savings-disable-in-vms, shared-folder-help Homepage: https://github.com/Kicksecure/vm-config-dist Priority: optional Section: misc Filename: pool/main/v/vm-config-dist/vm-config-dist_10.5-1_all.deb Size: 40244 SHA256: 41fc4cd7e2f97bdcf23ff80b91cbbc339aca3c60445ffaa4725147e4e28d048a SHA1: d150305c67a4d3949c714c4b16a6a2c1ebe63353 MD5sum: 471286ecd49b36d287b50f807685036b Description: usability enhancements inside virtual machines Sets environment variable `QMLSCENE_DEVICE=softwarecontext` as workaround for "Automatic fallback to softwarecontext renderer". . It is not useful to open a screensaver or to power down the desktop for operating systems that are run inside VMs. There is no real display that could be saved and no real power that could be saved. From usability perspective it also is counter intuitive when looking at the VM window and only seeing a black screen. Therefore it makes sense to disable power savings in VMs. `/etc/X11/Xsession.d/20_kde_screen_locker_disable_in_vms.sh` `/etc/profile.d/20_power_savings_disable_in_vms.sh` `/etc/X11/Xsession.d/20_software_rendering_in_vms.sh` `/usr/share/kde-power-savings-disable-in-vms/kdedrc` `/usr/share/kde-screen-locker-disable-in-vms/kscreenlockerrc` . Disables screen locker when running in VMs because that is not useful either. . Makes setting up a shared folder for virtual machines a bit easier. . * Creates a folder `/mnt/shared` with `chmod 777`, adds a group "vboxsf", adds user "user" to group "vboxsf". Facilitates auto-mounting of shared folders. . * Helps using shared folders with VirtualBox and KVM a bit easier (as in requiring fewer manual steps from the user). . * `/lib/systemd/system/mnt-shared-vbox.service` * `/lib/systemd/system/mnt-shared-kvm.service` . Set screen resolution 1920x1080 by default for VM in VirtualBox and KVM. Workaround for low screen resolution 1024x768 at first boot. When using lower screen resolutions, Xfce will automatically scale down. `/etc/skel/.config/xfce4/xfconf/xfce-perchannel-xml/displays.xml` . Installs VirtualBox guest additions if package `virtualbox-guest-additions-iso` is installed if environment variable `dist_build_virtualbox=true` or if running inside VirtualBox. (`systemd-detect-virt` returning `oracle`) `/usr/bin/vbox-guest-installer`