Package: anon-apt-sources-list Version: 3:6.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 71 Depends: fasttrack-archive-keyring Homepage: https://github.com/Kicksecure/anon-apt-sources-list Priority: optional Section: misc Filename: pool/main/a/anon-apt-sources-list/anon-apt-sources-list_6.5-1_all.deb Size: 29004 SHA256: 6fa8b2315209fa13e1d284d9374f87239ef4855915220e7615d8b18bcf7e30f4 SHA1: b249e32b173c837959380dddc763ab0914b52aa9 MD5sum: 74f5eb17ea3157694122842d0aa3c764 Description: Kicksecure APT and Flatpak Repository Configuration Configuring APT and Flatpak sources: - Includes Debian APT repositories (main, updates, backports, fasttrack, security) - Incorporates Debian APT components (main, contrib, non-free, non-free-firmware) - Integrates the Flathub repository (verified and floss subsets only) . Flatpak: - Official Flathub repository only. - Uses subset verified_floss, which means only verified applications and freedom software can be installed by default. . Provides configuration files: - /etc/apt/sources.list.d/debian.list for APT sources - /etc/flatpak/remotes.d/flathub.flatpakrepo for Flatpak sources . A Discussion on Distribution Maintenance Strategies: . The more standard way would indeed be populating /etc/apt/sources.list at install or build time and leaving /etc/apt/sources.list.d alone. . The idea of managing /etc/apt/sources.list.d/debian.list for the user is, the security-focused distribution maintainers can decide when it is a better "change stable to oldstable", "keep wheezy as long as needed to work out [eventual!] issues that would break during upgrade to jessie" and such. Package: anon-connection-wizard Version: 1:9.2-1 Architecture: all Maintainer: iry Installed-Size: 261 Depends: helper-scripts, pkexec, policykit-1-gnome | polkit-1-auth-agent, python3, python3-pyqt5, python3-stem, python3-yaml, qtwayland5 Recommends: obfs4proxy, tor Homepage: https://www.kicksecure.com/wiki/Anon_Connection_Wizard Priority: optional Section: misc Filename: pool/main/a/anon-connection-wizard/anon-connection-wizard_9.2-1_all.deb Size: 92456 SHA256: d832845cc0ea58147cff3e9c0b5c2a6952e4074597e6887326267e1e6ca2d0dc SHA1: 44bcc068e107524660595435bd1ff0bcd2a200d5 MD5sum: 326341cace26d560a968f8cc4667d65b Description: Tor Connection Configuration (ACW) WARNING: Not (yet) a standalone ready to use outside of Whonix: . Creates a Tor settings file: `/usr/local/etc/torrc.d/40_tor_control_panel.conf` . anon-connection-wizard (ACW) is a Tor-launcher-like application that helps users in different Internet environment connect to the Tor network. It helps user to configure Tor to use a proxy and/or Tor bridges. This application is especially useful for system Tor users who would like to run the standalone core Tor with different torified applications. The wizard can be run at any time to change the connection configuration. . Creates a Tor settings file: `/usr/local/etc/torrc.d/40_tor_control_panel.conf` . anon-connection-wizard is produced independently from the Tor anonymity software and carries no guarantee from The Tor Project about quality, suitability or anything else. Package: anon-shared-build-apt-sources-tpo Version: 3:6.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 121 Depends: helper-scripts, gnupg Recommends: deb.torproject.org-keyring Homepage: https://github.com/Kicksecure/anon-shared-build-apt-sources-tpo Priority: optional Section: misc Filename: pool/main/a/anon-shared-build-apt-sources-tpo/anon-shared-build-apt-sources-tpo_6.4-1_all.deb Size: 64068 SHA256: e679b1d101e562f761cd18dc55e5a4e03304349dc552e2ee003449659f4e2af4 SHA1: 7a27cb1e4d05fed88eaddd694c93a27fdabaf51b MD5sum: e06f1ab209beaeb44fe8bb326d5a4db2 Description: Adds TPO's APT repository to Derivative Linux Distributions Comes with "deb http://deb.torproject.org/torproject.org stable main", The Tor Project's APT signing key. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: apparmor-profile-dist Version: 3:8.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 95 Depends: helper-scripts Replaces: apparmor-profile-anondist Homepage: https://www.kicksecure.com/wiki/Apparmor-profile-everything Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-dist/apparmor-profile-dist_8.9-1_all.deb Size: 34960 SHA256: 95ef0e1a258ff875f503f1996315c9eb195d4714ac58c9d998edfe039b9a369d SHA1: 2c84beb209d7b06255d19fd1528aa51b21ee5c7c MD5sum: c62b3ad0679a4057962a9ee86c461304 Description: AppArmor Profile for Derivative Linux Distributions Displaces /etc/apparmor.d/abstractions/base with a version, that includes additions required for Derivative Linux Distributions. . Does not depend on AppArmor, so this package can be installed by default on any anonymity distribution by default, without requiring to also have AppArmor installed. Just for the case, AppArmor gets installed later by the user. Package: apparmor-profile-everything Version: 3:8.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 163 Depends: apparmor, apparmor-profile-torbrowser, libpam-apparmor Homepage: https://www.kicksecure.com/wiki/Apparmor-profile-everything Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-everything/apparmor-profile-everything_8.2-1_all.deb Size: 44248 SHA256: 54a593e067f0c974d837588bb4efa9c17c740ee69b223431a53b1a047698f0ea SHA1: 9722a920985210d1b633d37445be1346e929486d MD5sum: febc85940a0e252da5e0c84518e0142d Description: Full system AppArmor policy This is an AppArmor policy to confine all user space processes on the system which allows one to enforce a strong security model and follow principle of least privilege. An AppArmor policy for the init, systemd is loaded in the initramfs which then applies to all other processes. Specific policies for many system services/applications are also enforced. . This follows design ideas already present in other operating systems such as Android and attempts to make something similar available on desktop Linux. . In addition to locking down user space, this also protects the kernel as it restricts access to kernel interfaces like `/proc` or `/sys`, making kernel pointer and other leaks much less likely. . This does not and cannot confine the kernel or initramfs. . This is expected to be used in combination with other security technologies such as a hardened kernel, strong sandboxing architecture, verified boot and so on. . apparmor-profile-everything supports different boot modes: aadebug and superroot. aadebug allows certain permissions necessary for advanced debugging and superroot relaxes the policy substantially, even making bypasses possible. It is highly recommended to stick to the default boot mode. . It also contains a wrapper to restrict apt as apt requires permissions that may be abused to circumvent the policy. When updating or installing applications, you must use the `rapt` command. . This is still in development and breakage is likely. This should only be used by developers for now. . For now, please only use this development discussion forum thread: https://forums.whonix.org/t/apparmor-for-complete-system-including-init-pid1-systemd-everything-full-system-mac-policy/8339 . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: apparmor-profile-hexchat Version: 3:5.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 60 Depends: apparmor Replaces: apparmor-profile-xchat Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-hexchat/apparmor-profile-hexchat_5.1-1_all.deb Size: 23508 SHA256: 8736fb2b12f22a165f2180f3cc379bfe7d82b9ff7e39f3ff78b517e8959c6937 SHA1: c442bcef6d890ce339d8280e0e1ec8fdc215d85a MD5sum: ae1447ed5da0ca66b977bb6239606215 Description: AppArmor profile for HexChat IRC An AppArmor profile to confine HexChat IRC. This profile is developed by the Whonix team. HexChat IRC is developed by xchat.org / hexchat.github.io. . For better security. Package: apparmor-profile-thunderbird Version: 3:5.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 65 Depends: apparmor Replaces: apparmor-profile-icedove Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-thunderbird/apparmor-profile-thunderbird_5.6-1_all.deb Size: 26372 SHA256: 542a425da07544f8fbf0b3d79180317605c6ef55bbd9d249f93dd958034f32d0 SHA1: e2d19edc5e1697ee1e853edb024bcd6e639f1496 MD5sum: 37edd2f0b005b409d96f5d0b6b5bb58d Description: AppArmor profile for Thunderbird for Debian An AppArmor profile to confine Thunderbird. . This profile is just an extension of the upstream AppArmor Debian profile. The upstream AppArmor upstream profile is the foundation. . Primarily this AppArmor profile makes Debian's AppArmor profile for Thunderbird compatible with Qubes Debian based VMs. . This profile is developed by the Kicksecure team. Thunderbird is developed by mozilla.org. Package: apparmor-profile-torbrowser Version: 3:9.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 73 Depends: apparmor Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-torbrowser/apparmor-profile-torbrowser_9.2-1_all.deb Size: 34240 SHA256: ec52697707248dd65376e34239748697b711da2650b591ca57d4424d281b5dfd SHA1: bbdf54f1bd08e4c45755f8d0053fbbbf24ff67d7 MD5sum: 9f3824256e767e0a6fd906bf9cc31f41 Description: AppArmor profile for The Tor Browser Bundle (TBB) An AppArmor profile to confine The Tor Browser Bundle (TBB). This profile is developed by the Whonix team. TBB is developed by The Tor Project. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: apparmor-profiles-kicksecure Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: apparmor-profile-hexchat, apparmor-profile-thunderbird, apparmor-profile-torbrowser, apparmor-profiles, apparmor-profiles-extra Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/apparmor-profiles-kicksecure_30.7-1_all.deb Size: 75992 SHA256: aca9a6e5a2f2dcaecf9f7ec51ec303b9b6a8a418303cb9df4fd443a29426f071 SHA1: 94626c823d3ac54095cb6288b26902b23c004538 MD5sum: 78ce403704a4347a15e236f6182fac58 Description: AppArmor profiles developed by the Kicksecure Team A metapackage, which installs apparmor profiles packages from Debian: . * apparmor-profile * apparmor-profiles-extra . as well as installs apparmor profiles developed by the Kicksecure team: . * apparmor-profile-thunderbird * apparmor-profile-torbrowser * apparmor-profile-hexchat . Increases security. . Safe to remove, if you know what you are doing. Package: binaries-freedom Version: 0:2.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 30 Depends: fuse Homepage: https://github.com/Kicksecure/binaries-freedom Priority: optional Section: misc Filename: pool/main/b/binaries-freedom/binaries-freedom_2.9-1_all.deb Size: 10684 SHA256: 97cf97956b5313199a4c9a60f0b79cde27f6eee73e66aaf2881d4c716df7fe01 SHA1: f51d85d84bd2b2c5bdc2bd3054f9e73b7c8e3438 MD5sum: 4b6c5317f8c7d7bd5a70dd0dc40e861d Description: Freedom Software Binaries This is an empty package at this time. . https://forums.whonix.org/t/policy-for-inclusion-of-compiled-software/6635 Package: bindp Version: 3:3.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 27 Homepage: https://github.com/Kicksecure/bindp Priority: optional Section: misc Filename: pool/main/b/bindp/bindp_3.5-1_all.deb Size: 12912 SHA256: 064a52e8af450a109f3d9ad3f9c9ae488148dfc4c63e91f554ab2b19799c0b24 SHA1: 136628b64dc53434b20412d5d89cd5c9f3450f20 MD5sum: 0605b7487fa35c447357811bf445f2b0 Description: Binding specific IP and Port for Linux Running Application This package is probably most useful for Anonymity Distributions. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: bootclockrandomization Version: 3:6.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 86 Depends: msgcollector Homepage: https://www.kicksecure.com/wiki/Boot_Clock_Randomization Priority: optional Section: misc Filename: pool/main/b/bootclockrandomization/bootclockrandomization_6.6-1_all.deb Size: 29980 SHA256: 47c80c978e85bb6e872bcf3a035ae83a4a9d5518dc69e69bdc20f9c279637b0b SHA1: 438f2366f725f57ccb04a0d304f377dacd9a565f MD5sum: 27d7a798d25a27151dd7325e1bc0f3c9 Description: Randomizes clock when systems boots Randomizes clock at boot time. Moves clock a few seconds and nanoseconds to past or future. Useful in context of anonymity/privacy/Tor. . This is useful to enforce the design goal, that the host clock and Gateway/Workstation clock should always slightly differ (even before secure timesync succeeded!) to prevent time based fingerprinting / linkablity issues. . Runs before Tor / sdwdate (if installed). . See also: https://www.whonix.org/wiki/Dev/TimeSync Package: calamares-settings-debian Version: 13.1.2-1 Architecture: all Maintainer: Jonathan Carter Installed-Size: 316 Depends: calamares, cryptsetup, libglib2.0-bin, keyutils, pkexec, qml-module-qtquick-window2, qml-module-qtquick2, dconf-gsettings-backend | gsettings-backend Provides: calamares-settings Homepage: https://salsa.debian.org/live-team/calamares-settings-debian Priority: optional Section: utils Filename: pool/main/c/calamares-settings-debian/calamares-settings-debian_13.1.2-1_all.deb Size: 227196 SHA256: 0e78b171f45468b2dd6a7116d9027631363285b5ce272618b02133d15589667d SHA1: df15faedcab6fe37b18ee76bfe45cad5d4119fdf MD5sum: 29a9a8565061811d639fa6a025604e2b Description: Debian theme and settings for the Calamares Installer Calamares is a generic installer framework for Linux distributions. By default, it contains a set of boilerplate wording and images. This package provides the latest Debian artwork as well as scripts that supports EFI installations. . It also serves as an example for how derivatives can create their own calamares-settings packages. Package: damngpl Version: 3:4.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 31 Depends: perl Homepage: http://www.finnie.org/software/damngpl/damngpl Priority: optional Section: misc Filename: pool/main/d/damngpl/damngpl_4.1-1_all.deb Size: 13088 SHA256: 73f8deb8464d4b52a44b3f30b8bf3be0125974aee96edb0a51717ad2ba8d99d4 SHA1: 42ee6d1cbb1cd1f133a914172dc7e4b5fcb4a62a MD5sum: 0c3e9a0d1ede9350ae52c68dacdea300 Description: Extract source package info from Debian status files damngpl will parse a Debian-style /var/lib/dpkg/status file and extract source package information about installed packages. This information can be used in several ways, usually to download source packages. . Multiple input files can be specified on the command line, or piped into standard input if no files are specified. Results are returned to standard output. . The name damngpl was chosen as a tongue-in-cheek description of its purpose (downloading Debian sources for the Finnix project to remain GPL compliant). Please do not send hate mail to the author, thinking he is anti-GPL. He's not. . See also: http://blog.finnix.org/2011/08/21/finnix-and-gpl-compliance/ Package: deb.torproject.org-keyring Version: 2024.05.22 Architecture: all Maintainer: Peter Palfrader Installed-Size: 20 Priority: important Section: misc Filename: pool/main/d/deb.torproject.org-keyring/deb.torproject.org-keyring_2024.05.22_all.deb Size: 4372 SHA256: 22eb433ce2e23eb79914b80825b84c30f6aa785a824a971a9a7aff93bc0a5057 SHA1: 2d8e1f35f05c2b62051c83bb6fe0bebce0029335 MD5sum: 058f3b902a815b762f79e7b035705d00 Description: GnuPG archive key of the deb.torproject.org repository The deb.torproject.org repository digitally signs its Release files. This package contains the current repository key used for that, and upon installation configures your system to accept archives signed with this key. Package: debug-misc Version: 3:4.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 102 Suggests: systemd-coredump, serial-console-enable Replaces: grub-output-verbose Homepage: https://github.com/Kicksecure/debug-misc Priority: optional Section: misc Filename: pool/main/d/debug-misc/debug-misc_4.0-1_all.deb Size: 25068 SHA256: 0195998f10863366d48e41e3138891e556a8c315f6b400d3155e0edbf4def9f4 SHA1: 9df140f19d137140cdabd88afdfc8a631e953ab5 MD5sum: f29ec71368f61464695aca5af0f6ed30 Description: Enables miscellaneous debug settings Ships a `/etc/default/grub.d/45_debug-misc.cfg` configuration file, that removes `quiet`, `loglevel=0` and `debugfs=off` from the `GRUB_CMDLINE_LINUX_DEFAULT` variable and adds `debug=vc` to the kernel boot parameter to enable verbose output during the initial ramdisk boot phase. . Undo debugging related `sysctl` settings by package `security-misc`. . Enables persistent systemd journal log. . Disables `/lib/systemd/coredump.conf.d/disable-coredumps.conf` by package `security-misc` by creating a symlink from `/etc/systemd/coredump.conf.d/disable-coredumps.conf` to `/dev/null`. `debian/debug-misc.links` . Disables `panic-on-oops`, `remove-system.map` by package `security-misc`. . `config-package-dev` `hide` `/etc/sysctl.d/30_silent-kernel-printk.conf` which kernel.printk to default as if security-misc would not have lowered verbosity. . Configure systemd `getty` service to not clear `tty`. `/lib/systemd/system/getty@tty.service.d/30_debug-misc.conf` . Coredumps are enabled. `/etc/security/limits.d/40_debug-misc.conf` . Coredumps may contain important information such as encryption keys or passwords. Package `security-misc` disables coredumps. Package `debug-misc` re-enables coredumps. . Contains a helper tool to cause a segfault for testing purposes. `segfault-build` creates `segfault-run`. Running `segfault-run` results in `segfault-run` terminating with a segfault. This is useful to test if coredump files are being generated when an application crashes. `/usr/sbin/segfault-build` `/usr/share/debug-misc/segfault.c` . For better usability, to ease debugging in case of issues. . For better security, this package should only be installed on specific machines that require debugging. Unfortunately, security and debugging are conflicting optimization goals. Package: desktop-config-dist Version: 3:10.1-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 140 Conflicts: whonix-xfce-desktop-config Replaces: whonix-xfce-desktop-config Provides: whonix-xfce-desktop-config Homepage: https://github.com/Kicksecure/desktop-config-dist Priority: optional Section: misc Filename: pool/main/d/desktop-config-dist/desktop-config-dist_10.1-1_all.deb Size: 44284 SHA256: 8a99965d33005fd094f83837eafa194a01e590598b9cdece42c5e75cb1d1c0a4 SHA1: 599b51464fce0cb684a5b622f6c53bf982c61634 MD5sum: 15996cd367f04fd5441d8dce3d01f03a Description: Configuration for Derivative Desktop Sets desktop and display setting, wallpaper and desktop icons. Sets icon theme and style. Settings for the default panel aka task bar, like panel position/color/size and panel plugins/shortcuts. . Autologin for user 'user' setting in lightdm. . Live check systray indicator which indicates the status of grub-live, whether the system was booted into persistent or live mode. See also: https://www.kicksecure.com/wiki/grub-live . Adds start menu entries for web browser, terminal emulator, file manager. . Sets Whisker Menu for better usability. . Disable maximize windows when moving to top for better privacy. . Disables thumbnails for better security. . Disables save on exit for better privacy. . Ships `zsh` derivative configuration settings folder `/etc/zsh`. But does not configure `zsh` as default shell. (That is up to package `dist-base-files`.) Package: desktop-config-dist-dependencies Source: desktop-config-dist Version: 3:10.1-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 62 Depends: xfce4-whiskermenu-plugin, xfce4-genmon-plugin, arc-theme, gnome-themes-extra, gnome-themes-extra-data, gtk2-engines-murrine, gnome-colors-common, adwaita-icon-theme Homepage: https://github.com/Kicksecure/desktop-config-dist Priority: optional Section: misc Filename: pool/main/d/desktop-config-dist/desktop-config-dist-dependencies_10.1-1_all.deb Size: 32416 SHA256: 9f5c6488a2dae1b633b9c6ac788368f1d7e5eb451fff12967dccea846e6f974a SHA1: bee90d104053bb4a5f1169c7429a6302ec0691fb MD5sum: 13b4c4698b44d754e755336dbf97723b Description: Dependencies of desktop-config-dist A metapackage with dependencies for package desktop-config-dist. . Only useful for Non-Qubes. Not useful in Qubes. Package: developer-meta-files Version: 3:35.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 296 Depends: python3, bc Homepage: https://github.com/Kicksecure/developer-meta-files Priority: optional Section: misc Filename: pool/main/d/developer-meta-files/developer-meta-files_35.5-1_all.deb Size: 113248 SHA256: e9f0c52ceab5b0d8d1d5ed85145abf0d1853b550f236ef3ff1e0ba66ce502e30 SHA1: e0fca68381856bb1368f269ad6abed63ce1ca766 MD5sum: 8624e2dcbc0c291226b65d434d20022f Description: Linux Distributions Maintenance Helper Scripts Todo . Description Package: dist-base-files Version: 3:11.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 122 Depends: sudo, dpkg-dev, helper-scripts, adduser, zsh, zsh-syntax-highlighting, zsh-autosuggestions Conflicts: anon-base-files Replaces: anon-base-files Provides: anon-base-files Homepage: https://github.com/Kicksecure/dist-base-files Priority: optional Section: misc Filename: pool/main/d/dist-base-files/dist-base-files_11.0-1_all.deb Size: 42576 SHA256: c07915d3be08f658a5eac7dcf6bf2506bf6f2c5ad4b33a14effe650ba4e091d4 SHA1: 0fc834928e9f9acf0648ee4c9bcadc25bfca6510 MD5sum: 48b85710bf46a18a2c60b0a1d8e985d5 Description: base files for distributions Creates user `user` with empty password (passwordless) (not in Qubes). That is if user `user` is not existing yet. And if it does create user `user` it also locks the root account. Therefore root account locking effectively only happens in new builds not having user `user` already created. . Adds user `user` to groups `cdrom`, `audio`, `dip`, `sudo`, `plugdev`. . Ships a systemd unit file dist-skel-first-boot.service which runs `/usr/libexec/helper-scripts/first-boot-skel` (part of helper-scripts) package. . Simplifies sudo default lecture to only showing the default password once. . Creates version file `/var/lib/dist-base-files/build_version`. . Default shell: Sets default shell for user `user` to `zsh`. (Unless file `/etc/no-shell-change` exists.) `debian/dist-base-files.postinst` . This package gets installed by default in both, Kicksecure and Whonix. Package: dummy-dependency Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Provides: firefox-esr, qubes-core-agent-passwordless-root, tb-default-browser, tb-starter, tb-updater Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency_30.7-1_all.deb Size: 76028 SHA256: 077da821286efe0e66be08515f58180c5c9821633330bd24989ab0b32fe00fe7 SHA1: f0a6bab3f571fe604f80fde02c2d52593f07696a MD5sum: ac2bb82da31e011222c8b870caba47a7 Description: dummy package to satisfy architecture specific dependencies A metapackage, which satisfies the dependency on: . - tb-updater - tb-starter - tb-default-browser - qubes-core-agent-passwordless-root - firefox-esr . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-apparmor-profiles-kicksecure Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Provides: apparmor-profiles-kicksecure Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-apparmor-profiles-kicksecure_30.7-1_all.deb Size: 75964 SHA256: db82c6af46c7a7973273fbd888a47c9dfb3b725770a67b37b135bbdfacad3539 SHA1: 8089cc5396edb6880a4215a46bad3137bdf57af6 MD5sum: 3dc57e4f2f6cb5a45aa232739a28faa3 Description: dummy package apparmor-profiles-kicksecure A metapackage, which satisfies the dependency on apparmor-profiles-kicksecure. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-bindp Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Provides: bindp Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-bindp_30.7-1_all.deb Size: 75956 SHA256: a006a30a97a2e8a83d45ddc51e9b327ac09c94ba2e21160a14c7fe4bd98dfbff SHA1: 0c625b00688347cb1702b84459a9bfc23dd7f833 MD5sum: bc73e266def33a3289cd12674782a0da Description: dummy package to satisfy architecture specific dependency bindp A metapackage, which satisfies the dependency on bindp. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-electrum Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Replaces: dummy-dependency-hardened-electrum Provides: dummy-dependency-hardened-electrum, electrum Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-electrum_30.7-1_all.deb Size: 75972 SHA256: 04e870f2c58fea032ba83a05190c322b42b43c11e774de31d7a239f5e03af7d2 SHA1: 6ee3fc3d403325a072c6f2fc1a966490b9114d7c MD5sum: e0a53649a779e8e9f054e3dc13186ec6 Description: dummy package to satisfy architecture specific dependency electrum A metapackage, which satisfies the dependency on electrum. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-hardened-malloc Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Provides: hardened-malloc Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-hardened-malloc_30.7-1_all.deb Size: 75972 SHA256: b0610495f3a28a685c3eed27e70c9e83165c928e149432720f8baf06f5de5626 SHA1: bb4ff2895482d06daf8f1c631f53ee6527c566ad MD5sum: 878332aca40ad60186584e30abcb67b8 Description: dummy package to satisfy architecture specific dependency hardened-malloc A metapackage, which satisfies the dependency on: . hardened-malloc . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-kloak Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Provides: kloak Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-kloak_30.7-1_all.deb Size: 75952 SHA256: 760bc778492d8c4a21e173b4e08050653523697e0945f53c59da012a5e28877e SHA1: 6a374bb775ed8c6510c18b88baa585464914e74d MD5sum: 6de166fafd127af8a209b3f427817448 Description: dummy package to satisfy architecture specific dependency kloak A metapackage, which satisfies the dependency on kloak. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-tirdad Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Provides: tirdad Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-tirdad_30.7-1_all.deb Size: 75956 SHA256: 65b8235e17d11e30783f490242c6e7e3ace3e63a947ce4a35ba1fdacc7095efc SHA1: 320beb7fa9b645fd056f92acf430d52b6c97307a MD5sum: 1f506032fe4c7926da7ae8856d64a0b9 Description: dummy package to satisfy architecture specific dependency tirdad A metapackage, which satisfies the dependency on tirdad. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: dummy-dependency-xorg-vm Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Provides: xserver-xorg-video-vmware Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-xorg-vm_30.7-1_all.deb Size: 75956 SHA256: 91eb57bf2664a77f47a2ba79d606b3a0690587ffca4036256e171d4450fb1261 SHA1: 9de1e6586fa2dfe2883348ca87bf0303cb4f6f6f MD5sum: ddc8e1e05b0bcfb047be1988db7744b1 Description: dummy dependency xserver-xorg-video-vmware A metapackage, which satisfies the dependency on xserver-xorg-video-vmware. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: genmkfile Version: 3:15.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 153 Depends: make, dpkg-dev, devscripts, strip-nondeterminism, sudo, perl, rsync, python3 Homepage: https://github.com/Kicksecure/genmkfile Priority: optional Section: misc Filename: pool/main/g/genmkfile/genmkfile_15.1-1_all.deb Size: 55280 SHA256: c6c4e71a206f25d8270f8662a6def44fa5003480cbd6d3daa99fa9c08db1c333 SHA1: 1785fea6c12194e80ba36d94b9b28172e482230f MD5sum: 2d317723c682a448de0dbb414d12bfde Description: Generic Makefile Makes packaging simpler. No more need to manually maintain 'make install' targets or distribution specific install files such as debian/pkg-name.install. . Files in etc/... in root source folder will be installed to /etc/..., files in usr/... will be installed to /usr/... and so forth. This should make renaming, moving files around, packaging, etc. very simple. Packaging of most packages can look very similar. . Provides common make targets such as 'make install', 'make dist', 'make installsim', 'make installcheck', 'make uninstall', 'make uninstallcheck', 'make distclean'. . Very extensible through file ./make-helper-overrides.bsh or folder ./make-helper-overrides.d. By using overrides, any make target can be easily extended using pre or post hooks or replaced. Override files which are executable will be used. Override files which are not executable will be skipped. . Contains a minimal Makefile while the heavy lifting is done by a bash script make-helper.bsh. . Building for multiple platforms possible, example: export make_cross_build_platform_list="i386 amd64" . Can call with lintian (static analysis tool for Debian packages). By default it will be using lintian if installed while failing open (non-zero exit code). lintian can be disabled. export make_use_lintian=false Or can be configured to fail closed (non-zero exit code). export make_use_lintian=true . Can build packages without chroot using debuild (default) or inside chroot using cowbuilder. To enable cowbuilder, use: export make_use_cowbuilder=true . Supports signing packages using debsign. (sign a Debian .changes and .dsc file pair using GPG) export make_use_debsign=true Package: gpg-bash-lib Version: 3:4.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 646 Homepage: https://github.com/Kicksecure/gpg-bash-lib Priority: optional Section: libs Filename: pool/main/g/gpg-bash-lib/gpg-bash-lib_4.5-1_all.deb Size: 490216 SHA256: 88bf1bad852a7a2f157da8343d1df8e0a93eb2cc3c5861a72e72952c74d32572 SHA1: 9ed1dd0668ad67babbf1ef3eb549b8d242e1e6a8 MD5sum: 6b536f52b9a62ee5312ea300bcc88d7c Description: gpg bash library Abstracts file verification into common functions. Allows detecting of stale files, i.e. detection downgrade or indefinite freeze attacks by implementing a valid-until like mechanism. . Internally parses gpg's --status-file output. . For better security. Package: grub-live Version: 3:5.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 63 Depends: grub-live-initramfs-tools | grub-live-dracut Provides: boot-live, grub-live-boot Homepage: https://github.com/Kicksecure/grub-live Priority: optional Section: misc Filename: pool/main/g/grub-live/grub-live_5.6-1_all.deb Size: 24524 SHA256: 61b75a8934d5a142d41281cb43f0fc7328f9af785f769a571ab222acfde9b725 SHA1: 8b9ea39c3c3d6fc87e772ef7eef773bbec632c94 MD5sum: 3bc263ca50f4b4b6bb4d8074b8f65661 Description: grub live boot menu entry Allows booting the system in live mode. Meaning, no persistent modifications will be written to the disk. All changes stay in RAM. . Adds a grub live boot menu entry. . Existing grub boot entries stay unmodified. . No claims are made with regard to anti forensics. Package: grub-live-dracut Source: grub-live Version: 3:5.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 51 Depends: dracut Provides: boot-live, grub-live-boot Homepage: https://github.com/Kicksecure/grub-live Priority: optional Section: misc Filename: pool/main/g/grub-live/grub-live-dracut_5.6-1_all.deb Size: 22244 SHA256: be5eed7fe91d52813dfb6436c8bdabcdaf06eef1efa02be37e02fce84493a020 SHA1: 494f871ce75ff307c8156c168b7389cd3d824358 MD5sum: 60de4844330c3455c88549c662f34c2f Description: grub live dracut dependencies Dracut version metapackage for grub-live. . See also the package grub-live. Package: grub-live-initramfs-tools Source: grub-live Version: 3:5.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 51 Depends: live-boot, live-tools Provides: boot-live, grub-live-boot Homepage: https://github.com/Kicksecure/grub-live Priority: optional Section: misc Filename: pool/main/g/grub-live/grub-live-initramfs-tools_5.6-1_all.deb Size: 22264 SHA256: 67b0ac795735a1415804158566cf2dcddd37943c538ec9063add19b118cf429f SHA1: 5b61da72944698a5340a8ce30d9c9802cb1fc514 MD5sum: ecde24be4c5797860a84ecdb90d3732e Description: grub live initramfs-tools dependencies initramfs-tools version metapackage for grub-live . See also grub-live package. Package: hardened-kernel Version: 3:4.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 474 Depends: build-essential, libssl-dev, libncurses-dev, fakeroot, libelf-dev, bison, flex, gcc-12-plugin-dev, curl, bc, kmod, cpio Homepage: https://www.kicksecure.com/wiki/Hardened-kernel Priority: optional Section: misc Filename: pool/main/h/hardened-kernel/hardened-kernel_4.7-1_all.deb Size: 157576 SHA256: d7c4ad2fcecca09a1d4089f73378269bed96a073ad797695f82eeb73d42c65a7 SHA1: f89b0cb1507000a08940eb0027d2f248a0b66ed2 MD5sum: 8c46c9b71b8ba3c000327650d64d8a79 Description: Hardened Kernel for Host and VMs This is a hardened kernel configuration for Whonix / Kicksecure. hardened-vm-kernel is designed specifically for virtual machines and hardened-host-kernel is designed for hosts. . Both configs try to have as many hardening options enabled as possible and have little attack surface. hardened-vm-kernel only has support for VMs and all other hardware options are disabled to reduce attack surface and compile time. . During installation of hardened-vm-kernel, it compiles the kernel on your own machine and does not use a pre-compiled kernel. This ensures the kernel symbols in the compiled image are completely unique which makes it far harder for kernel exploits. This is possible due to hardened-vm-kernel having only VM config options enabled which drastically reduces compile time. . During installation of hardened-host-kernel, the kernel is not compiled on your machine and it uses a pre-compiled kernel. This is because the host kernel needs most hardware options enabled to support most devices which makes compilation take a very long time. . The VM kernel is more secure than the host kernel due to having less attack surface and not being pre-compiled but if you want more security for the host, it is recommended to edit the hardened host config, enable only the hardware options you need and compile the kernel yourself. This makes the security of the host and VM kernel comparable. . Both configs were based on the default Debian config. . These kernels use the linux-hardened patch for further hardening. Custom hardening patches should be sent there. . This only supports LTS kernels as they have the least attack surface (stable kernels have more code and more bugs) and the best stability. . Build script /usr/share/hardened-vm-kernel/build does not run automatic yet. . Kernel does not get installed automatic yet. . See also development discussion: http://forums.whonix.org/t/kernel-recompilation-for-better-hardening Package: helper-scripts Version: 3:23.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 331 Depends: sudo, python3, python3-stem, python3-scapy, python3-yaml, bubblewrap, moreutils Replaces: anon-shared-helper-scripts, anon-ws-leaktest, curl-scripts, python-guimessages, python3-guimessages Homepage: https://github.com/Kicksecure/helper-scripts Priority: optional Section: misc Filename: pool/main/h/helper-scripts/helper-scripts_23.5-1_all.deb Size: 109132 SHA256: eb66cca3399a9861237ed901edcb8c95573b40cb0877dbe919067e9ddf028606 SHA1: 8fa84e39d678a3a62f1c407e766e401ba6e8ad07 MD5sum: 1d39cb20b25e515fcbb2a075cb0f6d19 Description: Helper scripts useful for Linux Distributions Contains a script for curl progress bar in terminal. Includes another script to convert curl exit codes to curl status messages. Implemented in bash. Common code that can be used by other scripts. . Library that can be used by other (anonymity related) packages that want to programmatically get information about states of Tor. Common code, that is often required. Includes bash and Python helper scripts. . Leak Test for Anonymity Distribution Workstations Integrated leak test. Needs to be manually run. See: https://www.whonix.org/wiki/Dev/Leak_Tests . Translatable GUI Messages Generic modules guimessage.py and translations.py. Called with two parameters: .yaml file path and yaml section. Return translations according to distribution local language (Python 'locale'). . Provides the ld-system-preload-disable wrapper to disable /etc/ld.so.preload per application via bubblewrap. Useful if hardened_malloc is being globally preloaded and needs to be disabled for some applications. Package: icon-pack-dist Version: 3:4.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 2696 Conflicts: anon-icon-pack Replaces: anon-icon-pack Provides: anon-icon-pack Homepage: https://github.com/Kicksecure/icon-pack-dist Priority: optional Section: misc Filename: pool/main/i/icon-pack-dist/icon-pack-dist_4.4-1_all.deb Size: 1478216 SHA256: 252814bef6c607acf880542f3b2f35ef167fa9e2bfbfb413e9883b8733756983 SHA1: cdd7bb994b890274e1f7aa0b11a88d383dc37c28 MD5sum: fda034651a6e8ac5a3d4702556379167 Description: Icon Pack for Derivative Distributions Contains icons, that are used by other derivative distribution specific packages. Others are welcome to use these icons according to their Free licenses as well. Package: initializer-dist Version: 3:6.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 70 Depends: psmisc, debsums, damngpl Conflicts: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Replaces: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Provides: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Homepage: https://www.kicksecure.com/wiki/Verifiable_Builds Priority: optional Section: misc Filename: pool/main/i/initializer-dist/initializer-dist_6.8-1_all.deb Size: 29460 SHA256: 22312c463e548e9023e072e2e60dd1f1d9a93d8e1eac31dfb0340464ecbf1d5c SHA1: 99b7a2e0242af7a3af92d941ac88f556c45f7b9e MD5sum: d20489314a382526b800dd82380c7090 Description: Initializes Linux distributions, Release Upgrades and Legacy Contains a chroot-scripts-post.d script, that cleans up temporary files, logs. . Deletes random seeds. Since these should not be included in a redistributed image. Also sometimes called 'golden' image. . - /var/lib/urandom/random-seed - /var/lib/systemd/random-seed - /var/lib/random-seed - See also: https://systemd.io/RANDOM_SEEDS.html Package: kicksecure-base-files Version: 3:7.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 149 Depends: less, sudo Conflicts: diverts-etc++issue, diverts-etc++motd, diverts-etc++skel++.bashrc Provides: diverts-etc++issue, diverts-etc++motd, diverts-etc++skel++.bashrc Homepage: https://github.com/Kicksecure/kicksecure-base-files Priority: optional Section: misc Filename: pool/main/k/kicksecure-base-files/kicksecure-base-files_7.6-1_all.deb Size: 27744 SHA256: fbdcc084f617e95897c8402e9e8cf0ff1a16b01fa4b632db804093db709f1864 SHA1: 510e9ed3df591d082cc13f043fc403d8459eee21 MD5sum: 07ae6f1acc150ab6adae8d09550a7fc3 Description: Kicksecure base system miscellaneous files This package contains several important miscellaneous files, such as /etc/issue, /etc/motd, /etc/dpkg/origins/kicksecure, /etc/skel/.bashrc, /usr/bin/kicksecure, and others. . Sets the KICKSECURE environment variable to 1 as well. Package: kicksecure-cli Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: anon-apt-sources-list, dosfstools, kicksecure-base-files, kicksecure-default-applications-cli, kicksecure-dependencies-cli, kicksecure-recommended-cli, lvm2, ntfs-3g, obfs4proxy Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-cli_30.7-1_all.deb Size: 75948 SHA256: 890a4b360c0f4b9d1e5ecea150d2c322353da12877473c506ca02ab41807754e SHA1: f5ffcf9872cd330c3cda26536bca183ba441cf3a MD5sum: c17a7c5089e2b85c1f9a2f660a77cfd8 Description: Kicksecure command line interface CLI A metapackage, which installs packages, for Kicksecure CLI. . Do not remove. Package: kicksecure-cli-host Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: kicksecure-cli, kicksecure-cli-host-packages-recommended, kicksecure-dependencies-system, non-qubes-enhancements-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-cli-host_30.7-1_all.deb Size: 75920 SHA256: cb6e50ca415ef834173be01dbad044b08ca5c8eeb52104bef55107f25d89b17c SHA1: b31a82fb77cd988386c4abc7cae1d858f2b75df3 MD5sum: f985a318a0bceb92a401fb372249fe8b Description: Kicksecure Host command line interface CLI A metapackage, which installs packages, for Kicksecure CLI Host. . Do not remove. Package: kicksecure-cli-host-packages-recommended Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: tirdad Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-cli-host-packages-recommended_30.7-1_all.deb Size: 75932 SHA256: 279a9b76896873555ac4658b00a92de4c1db54e8a645ef4775ed412721ebab93 SHA1: fd22c029c264e38a06dac14037cd92859f8f6f6b MD5sum: f5b99cfa7acc8830f3fbc7edbbbf6a49 Description: Recommended Kicksecure Host CLI Packages A metapackage, which installs packages, which are recommended for Kicksecure CLI Host. . Not useful to have inside Qubes. . Safe to remove, if you know what you are doing. Package: kicksecure-cli-vm Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: kicksecure-cli, kicksecure-dependencies-system, kicksecure-network-conf, non-qubes-enhancements-cli, vm-config-dist Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-cli-vm_30.7-1_all.deb Size: 75984 SHA256: b28bbbc2731176c35e73e89033f9d33daaea220b1fe17ceadf904cefbfd8398d SHA1: 64299abe9c04dbc29626d08e5550fccf7afdfa9b MD5sum: ffebf0cd4f3546374bdff23adeed6d8f Description: Kicksecure command line interface CLI VMs A metapackage, which installs packages, for Kicksecure CLI Virtual Machines. . Not suitable for Qubes since it depends on packages not yet compatible with Qubes. . Do not remove. Package: kicksecure-default-applications-cli Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: catfish, codecrypt, diceware, dirmngr, equivs, extrepo, flatpak, fuse, gpg, gpg-agent, magic-wormhole, makepasswd, pwgen Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-default-applications-cli_30.7-1_all.deb Size: 76008 SHA256: 3bba44d616b5fe96d046483f9475d748a26218011cf81f64b994981d1ecd9fe5 SHA1: 38b5548ff96ef8ba1d229e620e09559237240718 MD5sum: 47fc275aa5dc816f708e152879b37508 Description: Default applications packages for Kicksecure A metapackage, which includes default packages to ensure, Kicksecure useful recommended tools are installed. . Safe to remove, if you know what you are doing. Package: kicksecure-dependencies-cli Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: apparmor-profile-dist, apt-transport-tor, apt-utils, bootclockrandomization, ca-certificates, desktop-config-dist, dialog, dist-base-files, gawk, init, initializer-dist, locales, menu, repository-dist, sdwdate, security-misc, setup-dist, sudo, timesanitycheck, usrmerge Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-dependencies-cli_30.7-1_all.deb Size: 76060 SHA256: cbe41647578ccb74dd2481b66c13138e32a6cef6ebb87eee44646bbee9981e96 SHA1: a1c2e01ffc4cfac59e8705f8af9282be288eaf3b MD5sum: a7861a2e280f7d1609033f69a59bf37b Description: Dependencies for hardened systems CLI A metapackage, which installs command line interface (CLI) packages which should be installed on hardened systems. . Do not remove. Package: kicksecure-dependencies-system Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: dracut | linux-initramfs-tool | initramfs-tools Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-dependencies-system_30.7-1_all.deb Size: 75948 SHA256: 3c4d9472484a2d7c525505664721f3e343e69088668dabfb6ea3ebe50fe99a3b SHA1: 361029d49c3c10bd5a2c8343d0ef2730d62bbd00 MD5sum: 86cea8f65471bda60682c718ed191953 Description: System for hardened systems A metapackage, which installs system packages which should be installed on hardened systems. . Currently only depends on boot process related dependencies. . Do not remove. Package: kicksecure-desktop-applications-recommended Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: electrum | dummy-dependency-electrum, firefox-esr | dummy-dependency, gpa, hunspell-en-us, keepassxc, kicksecure-welcome-page, msgcollector-gui, repository-dist-wizard, ristretto, sdwdate-gui, setup-wizard-dist, tumbler, vlc Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-desktop-applications-recommended_30.7-1_all.deb Size: 76032 SHA256: 86e2e45d9b7086dd4197b581b985989415f6814c683ad33525e85008fcc62d27 SHA1: 4e2fe399af98b68f0561e5f802ff493d47355696 MD5sum: 47d42f690575ef53dd0d2a75d3b9461a Description: Kicksecure Recommended Desktop Applications A metapackage, which installs recommended packages, for graphical user interface (GUI) Kicksecure. . Do not remove. Package: kicksecure-desktop-applications-xfce Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: gvfs, libexo-2-0, lxqt-sudo, mousepad, p7zip-full, pkexec, policykit-1-gnome, polkitd, thunar, thunar-archive-plugin, thunar-volman, unar, unzip, xarchiver, xfce4-terminal, xz-utils, zip Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-desktop-applications-xfce_30.7-1_all.deb Size: 76032 SHA256: 7d83d53da56f6f72785c8d2249f5ac65812540c9820bdfa494be3731a5d79ac2 SHA1: f128ab79aa74ffa2fdf8d22e9cd01d31e92b60bf MD5sum: 02b84979c3cd1354a67886244701c625 Description: Recommended applications for hardened Xfce desktop GUI A metapackage, which installs minimal, yet complete enough to contain the very basics, Xfce applications. . Safe to remove. Package: kicksecure-desktop-environment-essential-gui Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: desktop-config-dist, desktop-config-dist-dependencies, gtk2-engines-pixbuf, libgl1-mesa-dri, mesa-vulkan-drivers, upower, x11-xserver-utils, xdg-desktop-portal, xserver-xorg, xserver-xorg-video-fbdev, xserver-xorg-video-vesa, xserver-xorg-video-vmware | dummy-dependency-xorg-vm Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-desktop-environment-essential-gui_30.7-1_all.deb Size: 76044 SHA256: cc07906c6d98272f9d8fc99541be854547f074766bfb65ae28dc8223675874d8 SHA1: e05defc22d85d8ffc4687a4aef46109568c7a53a MD5sum: 9afbc657d08bf9ed55b35f3b7d42b055 Description: Desktop Depends GUI A metapackage, which installs dependencies for desktop environments, such as KDE, GNOME, etc. . kicksecure-desktop-environment-essential-xfce depends on this package. Package: kicksecure-desktop-environment-essential-xfce Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: accountsservice, gnome-brave-icon-theme, gnome-keyring, kicksecure-desktop-environment-essential-gui, lightdm, xdg-desktop-portal-gtk, xfce4 Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-desktop-environment-essential-xfce_30.7-1_all.deb Size: 76008 SHA256: 04407d23595b5088045dbc6a83ca19dc2ae208e9a8f173bcd7511bab067c1783 SHA1: c31b2f071c6ea4e5c790a9cd7552c958e3286810 MD5sum: 03a828f3230ebf65c4d1a4ba082501a2 Description: Recommended applications for hardened Xfce Desktop Environment A metapackage, which installs minimal, yet complete enough to contain a very basic Xfce Desktop Environment. . Safe to remove. Package: kicksecure-network-conf Version: 3:6.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 74 Depends: network-manager, iw, wpasupplicant, netbase, wireless-tools Homepage: https://github.com/Kicksecure/kicksecure-network-conf Priority: optional Section: misc Filename: pool/main/k/kicksecure-network-conf/kicksecure-network-conf_6.4-1_all.deb Size: 22228 SHA256: 786cf37f6488fedd5c312ba87feed93052e68b4794774730ce553ed112749fc5 SHA1: b5b5be536595e6457c7e4405477d3b4a2d2b7673 MD5sum: a72f3accb088e64d865de7671d5f6b48 Description: Network Configuration for Kicksecure CLI Disables systemd Predictable Network Interface Names. . Disables systemd-resolved during boot unless file /etc/dns-enable exists. . Disables systemd-resolved fallback DNS (which by default is set to Google). . Disables NetworkManager hostname management (useful in redistributed Kicksecure VMs). Package: kicksecure-network-conf-gui Source: kicksecure-network-conf Version: 3:6.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 48 Depends: network-manager-gnome Homepage: https://github.com/Kicksecure/kicksecure-network-conf Priority: optional Section: misc Filename: pool/main/k/kicksecure-network-conf/kicksecure-network-conf-gui_6.4-1_all.deb Size: 18868 SHA256: 71b93d49913676712677eda7f1f43455d55bc0fc631b500aa58efa7ad2822bca SHA1: 725be503327b4d6c9b0d1e31d59f35f1b8c2590c MD5sum: e117f3ee697301dc2aaef2292ee2ed35 Description: Network Configuration for Kicksecure GUI A metapackage with dependencies recommended for a Kicksecure GUI for networking. . See also kicksecure-network-conf. Package: kicksecure-packages-dependencies-pre Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Depends: dist-base-files, kicksecure-network-conf Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-packages-dependencies-pre_30.7-1_all.deb Size: 75936 SHA256: b188db85127daad322006a7a6bfbe96d0a8879d4d0468542bde43a7717cf4a51 SHA1: dcde369458422a4a67693b21b49558f14cbb53d1 MD5sum: 65efbf3e087a288d9c6d55e971aec55b Description: Dependencies for Kicksecure that changes network related files A metapackage, which installs packages which Kicksecure depends on. Can not be merged into another package due to conflicts with chroot build process. . Do not remove. Package: kicksecure-qubes-cli Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: kicksecure-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-qubes-cli_30.7-1_all.deb Size: 75964 SHA256: 0f98abc410263f06d2c56a3a8ea71b6c681cc7322d5dad87b39c09654e98a830 SHA1: 30c519f7126f56943110815f4c48b4b959edd8cb MD5sum: 84edda10b4c8050898f70797d221e21d Description: Default packages for Kicksecure-Qubes CLI A metapackage, which installs packages, for Kicksecure on Qubes without recommended GUI applications. . Currently only depends on kicksecure-cli but useful for future maintenance in case Qubes specific changes will be required. . Do not remove. Package: kicksecure-qubes-gui Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: kicksecure-desktop-applications-recommended, kicksecure-desktop-applications-xfce, kicksecure-qubes-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-qubes-gui_30.7-1_all.deb Size: 75920 SHA256: 2588f466a764d44444dde0d8724eabad26b66572079985560517dd1fcb899a0a SHA1: e5ad13e124cf9b2de76c28eac9da4e31bd4dad7c MD5sum: 548783b6b45200a7901adf0dee2f80b7 Description: Default packages for Kicksecure-Qubes GUI A metapackage, which installs packages, for Kicksecure on Qubes including recommended GUI applications. . Do not remove. Package: kicksecure-recommended-cli Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: apparmor-profiles-kicksecure | dummy-dependency-apparmor-profiles-kicksecure, apparmor-utils, bash-completion, boot-info-script, bzip2, curl, debian-keyring, dbus-user-session, distro-info-data, dnsutils, e2fsprogs, eject, file, haveged, iotop, iproute2, iputils-ping, jitterentropy-rngd, less, libblockdev-crypto2, libpam-tmpdir, lsof, man-db, mesa-utils, most, nano, net-tools, open-link-confirmation, openvpn, pciutils, pcmciautils, procps, secure-delete, sensible-utils, strace, sysfsutils, systemcheck, torsocks, traceroute, udisks2, usability-misc, usbutils Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-recommended-cli_30.7-1_all.deb Size: 76208 SHA256: 5d08a8973ce22a67be0184f3b213604f772c3bf35ab53ed40c82ead605a1e62f SHA1: 5fcbd7a0a5f6a0a53d38c7410bebb7f16fe3b58f MD5sum: 0c291035dae5277e0ec84a0823bf31ef Description: Recommended packages for Kicksecure A metapackage, which includes recommended packages to ensure, Kicksecure standard tools are available. . Safe to remove, if you know what you are doing. Package: kicksecure-shared-host-cli Source: kicksecure-meta-packages Version: 3:27.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 67 Pre-Depends: legacy-dist Depends: tirdad Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-shared-host-cli_27.1-1_all.deb Size: 61216 SHA256: e0ce351bb4b7d040cc7e3c889ffb54fe5fb8ee3df37be2451d11b2f5d67842a6 SHA1: e732b0744e139822eb70bcfd34906bcb208cc76f MD5sum: 0e0289a22f7f1e4f5b02f458d3e7f0e9 Description: Kicksecure Shared Host CLI A metapackage, which installs packages, which are recommended for Kicksecure CLI Host. . Safe to remove, if you know what you are doing. Package: kicksecure-shared-host-xfce Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: ddrescueview, discover, gddrescue, gnome-disk-utility, gnome-system-monitor, gparted, grub-live | grub-live-boot | boot-live, gsmartcontrol, hwinfo, icon-pack-dist, non-qubes-enhancements-gui, laptop-detect, lm-sensors, lshw, non-qubes-audio, nvme-cli, psensor, pv, sdwdate-gui, smart-notifier, smartmontools, xfce4-power-manager, xfce4-screenshooter, xfce4-xkb-plugin, xscreensaver Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-shared-host-xfce_30.7-1_all.deb Size: 76160 SHA256: d4bbddfecdf6335fc19bd4cace12d8d2173082b32b96d618ef4f0041f55deb27 SHA1: 2ad9238dca34ec96f2779b06b4bc30587fe13221 MD5sum: c6da3ff91302003bd4a5a227fbfa3f19 Description: Kicksecure Shared Host Xfce GUI A metapackage, which installs packages, which are recommended for Kicksecure Xfce Host as well as a Whonix-Host with a graphical user interface (GUI). . Safe to remove, if you know what you are doing. Package: kicksecure-welcome-page Version: 3:6.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 989 Depends: fonts-roboto-fontface, libjs-jquery Homepage: https://github.com/Kicksecure/kicksecure-welcome-page Priority: optional Section: misc Filename: pool/main/k/kicksecure-welcome-page/kicksecure-welcome-page_6.8-1_all.deb Size: 902784 SHA256: 97665bc91180edba5fe18755693cc605534b954ac3eb9f9ca13a2a8194d2f4d7 SHA1: 687d78a55096da54448ab76c7af4e919aca3ee22 MD5sum: 988e0a6844423f07bb2cc59b3c09f891 Description: Local Browser Homepage for Kicksecure Kicksecure specific browser start page. . Contains Kicksecure logo and Kicksecure links. . Safe to remove, if you know what you are doing. Package: kicksecure-xfce Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: kicksecure-cli, kicksecure-desktop-applications-xfce, kicksecure-desktop-environment-essential-xfce Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-xfce_30.7-1_all.deb Size: 75884 SHA256: e4eefaa64413fc94b355af78980979ca728fcf9287b28f313c6fab6c03111e06 SHA1: 58b8e71232e8e4d3e259c04c7933a54d26bd023d MD5sum: 6dd842937ef2e97faacfd958b54ae4c9 Description: Kicksecure Xfce GUI A metapackage, which installs packages, for Kicksecure Xfce. . Do not remove. Package: kicksecure-xfce-host Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: kicksecure-cli-host, kicksecure-desktop-applications-recommended, kicksecure-network-conf, kicksecure-network-conf-gui, kicksecure-shared-host-xfce, kicksecure-xfce Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-xfce-host_30.7-1_all.deb Size: 75916 SHA256: c9cc2077139efbb5ed565a38ac25b7737ffcd9814225f325fb432db8ad251483 SHA1: c3772227ea09282ff1284efb860349ac7662dc95 MD5sum: 4a86834c3aea384b0b79870b0f86d8c1 Description: Kicksecure Host Xfce GUI A metapackage, which installs packages, for Kicksecure Xfce Host. . Do not remove. Package: kicksecure-xfce-vm Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: kicksecure-cli-vm, kicksecure-desktop-applications-recommended, kicksecure-network-conf-gui, kicksecure-xfce, non-qubes-audio, non-qubes-enhancements-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-xfce-vm_30.7-1_all.deb Size: 75984 SHA256: ff12c8eb3a4afb7e0cfca62e676e4ecc01d65e84490a10f24e82e7f615ef15a3 SHA1: ce503a609034e6f6fd18cc2830e89dd17ce4c47f MD5sum: 4527401044b50518b2c6054463c5bd2a Description: Kicksecure Xfce GUI for VMs A metapackage, which installs packages, for Kicksecure Xfce in Virtual Machines. . Not suitable for Qubes since it depends on packages not yet compatible with Qubes. . Do not remove. Package: legacy-dist Version: 3:15.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 126 Depends: helper-scripts, apt-forktracer, deborphan Conflicts: vbox-disable-timesync, whonix-legacy Replaces: vbox-disable-timesync, whonix-legacy Provides: vbox-disable-timesync, whonix-legacy Homepage: https://github.com/Kicksecure/legacy-dist Priority: optional Section: misc Filename: pool/main/l/legacy-dist/legacy-dist_15.4-1_all.deb Size: 48660 SHA256: d017ca9edc7bb62f7c9817b511347a2cdf41f819f756e6cb011260261c0a15ad SHA1: 25539142f27d59e8e4fa7cff44c5bac56d7f79ca MD5sum: 3ab4fe742f27734e28a2893a49859135 Description: Prepare older Build Versions of Whonix for Upgrade Applies fixes required for upgrading from for example Whonix 8.x to Whonix 9.x etc. . Upgrades from Whonix 7.x or older versions is unsupported. . Safe to remove. Package: libvirt-dist Version: 3:10.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 141 Depends: adduser, qemu-kvm, libvirt-daemon-system, libvirt-clients, virt-manager, gir1.2-spiceclientgtk-3.0, dnsmasq-base, helper-scripts, msgcollector Conflicts: whonix-libvirt Replaces: whonix-libvirt Provides: whonix-libvirt Homepage: https://github.com/Kicksecure/libvirt-dist Priority: optional Section: misc Filename: pool/main/libv/libvirt-dist/libvirt-dist_10.3-1_all.deb Size: 53460 SHA256: d5a2fb9034390be3c7f51aa9e9cfe059fb432763aa1b2a00220f21f98e32e61e SHA1: 98f6ff975150eda4b316ba9dd9919c67fc94161c MD5sum: 6e495f4f43e0ac951e94db7a92d327ba Description: Whonix Libvirt XML Files for KVM and QEMU Libvirt XML files for Whonix-Gateway, Whonix-Workstation, Whonix-Custom-Workstation and Whonix's internal network. . Whonix-Host grub branding, motd and issue banner. . Whonix-Host boot popup. . See also: - https://www.kicksecure.com/wiki/KVM - https://www.kicksecure.com/wiki/QEMU Package: live-config-dist Version: 3:6.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 280 Depends: helper-scripts, pkexec, rsync, libglib2.0-bin, xdg-user-dirs Homepage: https://github.com/Kicksecure/live-config-dist Priority: optional Section: misc Filename: pool/main/l/live-config-dist/live-config-dist_6.5-1_all.deb Size: 140688 SHA256: e17aa8ab3b18901574965e88e3d3607d776a6bbb7dcb1d72a4539ac4ea615fef SHA1: bf6635ae66e8ab8ab86ccfd71fa0571bf35b3d4a MD5sum: 6b25585f98999f6da05da4ac5a3b7172 Description: calamares-settings-kicksecure and maybe calamares-settings-whonix Installed in Host ISO Live. . Supposed to be removed in Host installed. . Kernel parameters required for Live ISO. Package: lkrg Version: 0.9.6.2-1 Architecture: all Maintainer: Mikhail Morfikov Installed-Size: 16 Depends: lkrg-dkms (= 0.9.6.2-1) Homepage: https://lkrg.org Priority: optional Section: kernel Filename: pool/main/l/lkrg/lkrg_0.9.6.2-1_all.deb Size: 9300 SHA256: 06099d7d14880eca02ea4e8355f25c9664668ed8420c956051bb61541958f41f SHA1: 77f32a0334d6359a084ddd96d6e0f2bed6c7c4ae MD5sum: 75c8c83ff7bbc8eb47ce425bebd69b13 Description: Linux Kernel Runtime Guard (LKRG) LKRG performs runtime integrity checking of the Linux kernel and detection of security vulnerability exploits against the kernel. . LKRG is a kernel module (not a kernel patch), so it can be built for and loaded on top of a wide range of mainline and distros' kernels, without needing to patch those. . That is only a dependency package to install the LKRG kernel module and also some systemd service in order to help to manage loading/unloading the module at system boot/shutdown. Package: lkrg-dkms Source: lkrg Version: 0.9.6.2-1 Architecture: all Maintainer: Mikhail Morfikov Installed-Size: 787 Depends: dkms (>= 2.1.0.0) Recommends: lkrg-systemd (= 0.9.6.2-1) Homepage: https://lkrg.org Priority: optional Section: kernel Filename: pool/main/l/lkrg/lkrg-dkms_0.9.6.2-1_all.deb Size: 103928 SHA256: 858cedaefb1958b7966548f5d5f5990835d09965c415c8f6bd4039d589919503 SHA1: ba764d1501476e67904976cfbb64aa7630fb182f MD5sum: 45700ff02b87e317c1bebf8b12dd191b Description: Linux Kernel Runtime Guard (LKRG) Source Code and DKMS LKRG performs runtime integrity checking of the Linux kernel and detection of security vulnerability exploits against the kernel. . LKRG is a kernel module (not a kernel patch), so it can be built for and loaded on top of a wide range of mainline and distros' kernels, without needing to patch those. . This package uses DKMS to automatically build the LKRG kernel module. Package: lkrg-systemd Source: lkrg Version: 0.9.6.2-1 Architecture: all Maintainer: Mikhail Morfikov Installed-Size: 24 Depends: lkrg-dkms (= 0.9.6.2-1), systemd Homepage: https://lkrg.org Priority: optional Section: kernel Filename: pool/main/l/lkrg/lkrg-systemd_0.9.6.2-1_all.deb Size: 10196 SHA256: 575d2ef015a44056b11b894004ee5e026361ff44a894628c197d18d435b48cc9 SHA1: 78f3ebfdc801a3510a1104f8783389578d9514d1 MD5sum: 70d7d1e11516ccf08559234cec2cfeec Description: Systemd integration for Linux Kernel Runtime Guard (LKRG) LKRG performs runtime integrity checking of the Linux kernel and detection of security vulnerability exploits against the kernel. . LKRG is a kernel module (not a kernel patch), so it can be built for and loaded on top of a wide range of mainline and distros' kernels, without needing to patch those. . This package provides systemd integration for the LKRG kernel module. Package: mediawiki-shell Version: 3:3.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 132 Depends: helper-scripts, jq, retry, python3 Homepage: https://github.com/Kicksecure/mediawiki-shell Priority: optional Section: misc Filename: pool/main/m/mediawiki-shell/mediawiki-shell_3.1-1_all.deb Size: 38276 SHA256: 354b3d6a6e200c07de02d76c51e996b9473b0e70589d9a0c44c1b55d3b8ac096 SHA1: 62da3398e20e65458372c946381b68b954b91af5 MD5sum: b8561112ddb2ca7947ab4cd2aa9175ba Description: bash shell scripts for usage of MediaWiki API Description here. . TODO Package: msgcollector Version: 3:11.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 223 Depends: python3, sudo, inotify-tools, procps, init-system-helpers (>= 1.52) Conflicts: diverts-etc++bash.bash+-+logout Provides: diverts-etc++bash.bash+-+logout Homepage: https://github.com/Kicksecure/msgcollector Priority: optional Section: misc Filename: pool/main/m/msgcollector/msgcollector_11.5-1_all.deb Size: 63384 SHA256: 1982fe1937e0a92922b0be692d68f3a9619b5c61766326c968c85d555b82eb19 SHA1: 1fa49a3b51bffc2409747240f9b162605d95f341 MD5sum: cb2fe875fc256f5d60d7e6df7826e9f4 Description: Command Line Interface Messages Toolkit Library A programming library providing an application programming interface (API) that allows the programmer to output colored text in terminal user interfaces (CLI). . Applications can send messages to msgcollector which it collects and dispatches once instructed to do so by the application. . For clarity and avoidance of confusion, msgcollector does not collect any data. Applications that do not use msgcollector do not interact with msgcollector. It is roughly in the same category as ncurses but has of course much less and very different features. . For graphical user interface (GUI) support also install package msgcollector-gui. Package: msgcollector-gui Source: msgcollector Version: 3:11.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 70 Depends: msgcollector, wmctrl, python3-pyqt5, qtwayland5, zenity, libnotify-bin | kde-baseapps-bin, mate-notification-daemon, x11-utils, gnome-colors-common Homepage: https://github.com/Kicksecure/msgcollector Priority: optional Section: misc Filename: pool/main/m/msgcollector/msgcollector-gui_11.5-1_all.deb Size: 41588 SHA256: 0405bdf7b959b33fb151a092de57926961426b4e0fb229fcdee4e046812c6865 SHA1: dd67aa82fb33833243c763c271bcc899edf37748 MD5sum: 0e7694a35bac9af1a232e3569ee4813b Description: Graphical User Interface Toolkit Library A programming library providing an application programming interface (API) that allows the programmer to output colored text in graphical user interfaces (GUI). . Applications can send messages to msgcollector which it collects and dispatches once instructed to do so by the application. . For clarity and avoidance of confusion, msgcollector does not collect any data. Applications that do not use msgcollector do not interact with msgcollector. It is roughly in the same category as Qt or GDK but has of course much less and very different features. . A metapackage that installs required dependencies for graphical user interface support. Package: non-qubes-audio Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: libasound2, pavucontrol, pipewire-audio | pulseaudio, pipewire-pulse | pulseaudio, rtkit | pulseaudio, wireplumber | pipewire-media-session-pulseaudio | pulseaudio Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/non-qubes-audio_30.7-1_all.deb Size: 76028 SHA256: a90db897d37e26494315dba5ff95c1d0b83fa27038c613c0746d87d9aa8a23a8 SHA1: bb55e803c20c1608651d3135448d57dad2a95a04 MD5sum: 1e8300a0ab1beb86ada01251cdc03ae6 Description: Recommended packages for Audio Support in non-Qubes A metapackage, which includes recommended packages which are useful to provide audio support. . These are not useful in Qubes, since Qubes already has its own native audio implementation. . Safe to remove, if you know what you are doing. Package: non-qubes-enhancements-cli Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: acpi-support, console-common, console-setup, cryptsetup, dmsetup, grub-live | grub-live-boot | boot-live, kbd, keyboard-configuration, libzulucrypt-plugins, swap-file-creator, tirdad, udev, zulucrypt-cli Replaces: non-qubes-vm-enhancements-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/non-qubes-enhancements-cli_30.7-1_all.deb Size: 76112 SHA256: a85797e2c4a639f0a74dff22c77108752bcecc8573fadb55ae9af85b0fb46d49 SHA1: 4f1dba78ed048f82732e1d88058c9776f0e3c210 MD5sum: 4a2cfaac2894ada0cfb7ae3b7e8c0f35 Description: Recommended packages for terminal based machines (CLI) A metapackage, which includes recommended packages which are useful within CLI based non-Qubes machines. . These are not useful in Qubes, since Qubes already has native implementations for those. . Safe to remove, if you know what you are doing. Package: non-qubes-enhancements-gui Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: non-qubes-enhancements-cli, rads, zulucrypt-gui Replaces: non-qubes-vm-enhancements-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/non-qubes-enhancements-gui_30.7-1_all.deb Size: 76020 SHA256: 12483c80745384df67d73dc1da3cfc66d78170a7d9fef884f2bc1a7a8cdefc59 SHA1: b985563e6606d4d489e371bdd7f4ac57075e9891 MD5sum: fa726fc0c24b4ad75d08969567f642a9 Description: Recommended packages for graphical systems (GUI) A metapackage, which includes recommended packages which are useful within GUI based non-Qubes machines. . These are not useful in Qubes, since Qubes already has native implementations for those. . Safe to remove, if you know what you are doing. Package: non-qubes-vm-enhancements-cli Source: kicksecure-meta-packages Version: 3:29.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 101 Pre-Depends: legacy-dist Depends: acpi-support, console-common, console-setup, cryptsetup, dmsetup, grub-live | grub-live-boot | boot-live, kbd, keyboard-configuration, libzulucrypt-plugins, swap-file-creator, tirdad, udev, vm-config-dist, zulucrypt-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/non-qubes-vm-enhancements-cli_29.2-1_all.deb Size: 73472 SHA256: a9949552a4e77f94af5d6987298fc2f36b78c83c763cc1359a28386606066acd SHA1: 59b3f08eadcc764f34d92ebb89d25f50d9ce2139 MD5sum: 41d83db9863583fa67073bea617418eb Description: Recommended packages for terminal based VMs CLI A metapackage, which includes recommended packages which are useful within CLI based non-Qubes virtual machines. These are not useful in Qubes, since Qubes already has native implementations for those. . Safe to remove, if you know what you are doing. Package: non-qubes-vm-enhancements-gui Source: kicksecure-meta-packages Version: 3:29.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 101 Pre-Depends: legacy-dist Depends: non-qubes-vm-enhancements-cli, rads, zulucrypt-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/non-qubes-vm-enhancements-gui_29.2-1_all.deb Size: 73376 SHA256: beea8bd21259ab33f5a1b5ad29b5be960699c80219311613e3ebf483cdc4bf41 SHA1: cd51a40bd331058b9f4e20296c46c34211d52d96 MD5sum: 6b49ba396464d00eaa1789613a541a68 Description: Recommended packages for graphical VMs GUI A metapackage, which includes recommended packages which are useful within GUI based non-Qubes virtual machines. These are not useful in Qubes, since Qubes already has native implementations for those. . Safe to remove, if you know what you are doing. Package: open-link-confirmation Version: 3:6.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 87 Depends: sensible-utils, icon-pack-dist, msgcollector, xdg-utils Recommends: tb-starter, tb-updater, tb-default-browser Homepage: https://github.com/Kicksecure/open-link-confirmation Priority: optional Section: misc Filename: pool/main/o/open-link-confirmation/open-link-confirmation_6.2-1_all.deb Size: 29900 SHA256: 91daba198a9432b5ea4325a1c5af5b949eb2426e5fe46e1c97a31c121eace4a5 SHA1: 66eeb46136374cfe73316ac2a6284e9d7702cf2f MD5sum: 205c9024fe38f1a420b839a414d01a6b Description: Asks for confirmation before opening links Asks before a link is (accidentally) opened in a browser. Links are opened in x-www-browser. . Currently only the Tor Browser starter from the tb-starter package (by Whonix developers) supports using open-link-confirmation. Shell wrappers could be written to support other browsers as well. . On an Anonymity Gateway (when the anon-gw-base-files package is installed), it honors the $EDITOR environment variable (falls back to kwrite if unset), asks if a file should be opened in an editor before opening it and informs, that opening links on a Gateway is unsupported for security reasons. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: orca-screen-reader-support Source: kicksecure-meta-packages Version: 3:30.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 103 Pre-Depends: legacy-dist Depends: gstreamer1.0-plugins-good, libatk-adaptor, libgail-common, non-qubes-audio, orca, python3-gst-1.0, sound-icons, speech-dispatcher-espeak-ng, xbrlapi Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/orca-screen-reader-support_30.7-1_all.deb Size: 76008 SHA256: dc88ff48705bb33d213da02594eeaf555735afe24b3caf4c15dc19cc9cb31232 SHA1: da33c4413029021f9e68aa3e6faf91ca16ccf637 MD5sum: f951c5ee27479e5ff0bc22911813c87a Description: dependencies for the orca screen reader A metapackage, which includes depencency packages for the orca screen reader. . Safe to remove if its removal does not remove another metapackage, which is not safe to remove. Package: rads Version: 3:7.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 111 Depends: systemd Homepage: https://www.kicksecure.com/wiki/RAM_Adjusted_Desktop_Starter Priority: optional Section: misc Filename: pool/main/r/rads/rads_7.2-1_all.deb Size: 34736 SHA256: c5c4eb52aabb77a3b939761d9603c8e6b5d525a059d2019ee2db32a162ccddd7 SHA1: 18a4365295514955f6a2dda212995f066d486a33 MD5sum: 1f53a3253b7760768ccb05489d9f32cd Description: RAM Adjusted Desktop Starter If there is more than X MB RAM in total, the desktop environment will be started. . If less than X MB RAM in total (for example, only 196 MB RAM in total), no desktop environment will be started. . This should be quite convenient, because users with low RAM could reduce Y MB and even if they sometimes wanted to configure/check something, they could assign 512 RAM and automagically boot into the graphical desktop. There are also many settings in /etc/rads.d/ (stackable) to configure this feature, so if you want, you can also add a lot RAM, but not boot into a desktop environment, or use different display managers and so on. . Most useful in virtual machines. Package: ram-wipe Version: 3:2.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 101 Depends: helper-scripts, dracut, kexec-tools Homepage: https://github.com/Kicksecure/ram-wipe Priority: optional Section: misc Filename: pool/main/r/ram-wipe/ram-wipe_2.8-1_all.deb Size: 24312 SHA256: b4b2a53efd5144066ec7d7ad426f2414b242915564fd8a3ec8ca629d97b2fb5e SHA1: 1eb022d4f18a043b9d21442a00d2af1bfaf715cb MD5sum: dcf1591ba9aad46bdd39f0deefe5657d Description: Wipe RAM on shutdown and reboot A dracut module that wipes RAM on shutdown and reboot. . Not implemented for initramfs. Package: repository-dist Version: 3:11.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 191 Depends: helper-scripts, lsb-release, python3:any Homepage: https://www.kicksecure.com/wiki/Project-APT-Repository Priority: optional Section: misc Filename: pool/main/r/repository-dist/repository-dist_11.2-1_all.deb Size: 102932 SHA256: cec81cc62cd5e9d11932fdc84eeb6b9eb3ef17150559737031f0f650f14a3cc5 SHA1: a977235cd8ce778ffbfbaa4687367d8a875fac40 MD5sum: 6876371cfa2ca93acd09653534fdca73 Description: Derivative APT Repository Command Line Interface (CLI) This tool can always be used to enable either Derivative's stable, testers or developers repository or to disable Derivative's repository. . Derivative's APT Repository is not enabled by default. Some users prefer this for trust/security reasons. . On first boot of Derivative, the Derivative Repository Tool gets automatically started by setup-dist. The user is free to either leave Derivative's repository disabled or to configure it as desired. . Technically speaking, this tool creates or deletes file `/etc/sources.list.d/derivative.list`. . Using APT `signed-by`. Package: repository-dist-wizard Source: repository-dist Version: 3:11.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 69 Depends: pkexec, python3-pyqt5, python3:any, qtwayland5 Homepage: https://www.kicksecure.com/wiki/Project-APT-Repository Priority: optional Section: misc Filename: pool/main/r/repository-dist/repository-dist-wizard_11.2-1_all.deb Size: 36644 SHA256: ad61e7dd810dd723f5c88267e3a48a6a93664a3447b450b3f764c20186d992fe SHA1: 822114d13745a38a421f72dad01f62b17814e0e9 MD5sum: 488eba4ace38f9e25e87993cd0e7242b Description: Derivative APT Repository Graphical User Interface (GUI) This tool can always be used to enable either Derivative's stable, testers or developers repository or to disable Derivative's repository. . This is a metapackage depending on the required packages for the GUI (Graphical User Interface). Package: ro-mode-init Version: 3:2.8-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 60 Depends: live-boot, live-boot-initramfs-tools, live-tools Conflicts: grub-default-live, grub-live Replaces: grub-default-live, grub-live Provides: boot-live Homepage: https://github.com/Kicksecure/ro-mode-init Priority: optional Section: misc Filename: pool/main/r/ro-mode-init/ro-mode-init_2.8-1_all.deb Size: 19004 SHA256: 25f626fc9873ebbaf06d53f745b5918d62519bf0c27e0fa4c45ac33adc609ec0 SHA1: a848ea36168f059ba2c0e1beb98f00f0bf4ec521 MD5sum: 92a9416b15691d729af03ddb6aeac9b9 Description: Detects read-only disks and automatically enables live-boot Allows booting the system in live mode. Meaning, no persistent modifications will be written to the disk. All changes stay in RAM. . No claims are made with regard to anti forensics. Package: sandbox-app-launcher Version: 0:6.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 131 Depends: sudo, bubblewrap, apparmor, libseccomp-dev, helper-scripts, dbus-x11 Homepage: https://www.kicksecure.com/wiki/Sandbox-app-launcher Priority: optional Section: misc Filename: pool/main/s/sandbox-app-launcher/sandbox-app-launcher_6.6-1_all.deb Size: 48376 SHA256: 5d2321904e83310698a1730f0bd919f87d5b6e7dbc81ff3f0d603ad8d319bd77 SHA1: cf837cdb2e3469381c9a2345c892d0500a686515 MD5sum: 51b74b9c6fa87389b7e428b698e2a923 Description: application launcher to start apps in a restrictive sandbox sandbox-app-launcher runs each app as its own user, in a bubblewrap sandbox and confined by apparmor. . The directory, `/shared`, is shared across all app sandboxes to transfer files across. . This implements a permissions system to configure what apps can access. There are currently 5 available permissions: . * Network access . * Webcam access . * Microphone access . * Shared storage access (read-only or read-write) . * Dynamic native code execution . All apps the user installs will be automatically configured to run in the sandbox and a prompt will ask the user which permissions they wish to grant the application (not implemented yet). . Currently a WIP and not for actual use. Package: sdwdate Version: 3:23.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 338 Depends: sudo, bc, helper-scripts, adduser, gcc, libc6-dev, python3-stem, python3-dateutil, python3-socks, python3-sdnotify, python3-requests, python3, tor, python3:any Recommends: timesanitycheck, bootclockrandomization Conflicts: time-daemon Provides: time-daemon Homepage: https://www.kicksecure.com/wiki/Sdwdate Priority: optional Section: misc Filename: pool/main/s/sdwdate/sdwdate_23.7-1_all.deb Size: 146848 SHA256: 08a570db911d1443faaaf97b19fa990e14e6df32673186d20fb136aa88414c3e SHA1: 2e60bad13051fa927e5e56cb69d90d2c9757629b MD5sum: 4d9d923d51623ed7307a09c013bb4cdb Description: Secure Distributed Network Time Synchronization Time keeping is crucial for security, privacy, and anonymity. Sdwdate is a Tor friendly replacement for rdate and ntpdate that sets the system's clock by communicating via onion encrypted TCP with Tor onion webservers. . At randomized intervals, sdwdate connects to a variety of webservers and extracts the time stamps from http headers (RFC 2616). Using sclockadj option, time is gradually adjusted preventing bigger clock jumps that could confuse logs, servers, Tor, i2p, etc. . This package contains the sdwdate time fetcher and daemon. No installation on remote servers required. To avoid conflicts, this daemon should not be enabled together with ntp or tlsdated. Package: sdwdate-gui Version: 1:10.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 239 Depends: sudo, python3, python3-pyqt5, qtwayland5, helper-scripts, sdwdate, adduser Homepage: https://www.kicksecure.com/wiki/sdwdate-gui Priority: optional Section: misc Filename: pool/main/s/sdwdate-gui/sdwdate-gui_10.2-1_all.deb Size: 90160 SHA256: 48ceba52b3331d7aeefb4227fc90874a2181cd697eabc0613f46e8f62c4c24fc SHA1: eb34453cf02d063484af59b38a6d169a35ec61da MD5sum: 92305dcf2d1faa8ddfabc6c1519bce1a Description: Sdwdate Monitor sdwdate-gui is a systray icon monitor for sdwdate: checks sdwdate's status and modify the tray icon accordingly. In addition, it allows the user to restart sdwdate and view the log. Package: security-misc Version: 3:40.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 565 Depends: adduser, apparmor-profile-dist, dmsetup, helper-scripts, libcap2-bin, libglib2.0-bin, libpam-modules-bin, libpam-runtime, libpam-umask, python3, secure-delete, sudo, dconf-gsettings-backend | gsettings-backend Replaces: anon-gpg-tweaks, swappiness-lowest, tcp-timestamps-disable Homepage: https://www.kicksecure.com/wiki/Security-misc Priority: optional Section: misc Filename: pool/main/s/security-misc/security-misc_40.4-1_all.deb Size: 197148 SHA256: 77d38a7fbba4016c8e6213947f0d3dbc2615f5a777aa22524d4f15792a934c73 SHA1: ff742e17d4955cdc75e3b41d6876d021ebc57212 MD5sum: db61cfc16c548ebb45662ea60a0ee51d Description: Enhances Miscellaneous Security Settings https://github.com/Kicksecure/security-misc/blob/master/README.md . https://www.kicksecure.com/wiki/Security-misc . Discussion: . Happening primarily in Whonix forums. https://forums.whonix.org/t/kernel-hardening/7296 Package: serial-console-enable Version: 3:4.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 61 Homepage: https://github.com/Kicksecure/serial-console-enable Priority: optional Section: misc Filename: pool/main/s/serial-console-enable/serial-console-enable_4.1-1_all.deb Size: 17528 SHA256: bca714e19b0cb79468a7a4e5c21d1c773f50f565adc050a051eee9bf0d3de4c5 SHA1: afcf614e4ebf7b99974a4addcd237c6e1e769e02 MD5sum: cc005f12c21ae426e1b4aeaaab6c6260 Description: Enables serial console Ships a /etc/default/grub.d/30_serial_console.cfg configuration file, that enables serial console. . Enables /lib/systemd/system/getty.target.wants/serial-getty@ttyS0.service by creating a symlink from: /lib/systemd/system/serial-getty@.service to: /lib/systemd/system/getty.target.wants/serial-getty@ttyS0.service . Useful for serial console login such as into Whonix KVM VMs from the host operating system. . Forum discussion: https://forums.whonix.org/t/how-do-i-enter-the-whonix-shell-from-cli/7271 . Safe to remove if you do not require serial console login such as: virsh console vm-name Package: setup-dist Version: 3:10.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 138 Depends: helper-scripts, dialog, sudo, menu, python3 Conflicts: whonixsetup Replaces: whonixsetup Provides: whonixsetup Homepage: https://github.com/Kicksecure/setup-dist Priority: optional Section: misc Filename: pool/main/s/setup-dist/setup-dist_10.2-1_all.deb Size: 45720 SHA256: 4131c398f0d7c4b9d7e210af3dcd932e905f92e2acb059cc4a26ebb15ee8a5d9 SHA1: b2080b3d8885c6ca75ba5497ca0de68fd15b6f4e MD5sum: d563807a4cc428189a334125f578e2db Description: First Time Connection Setup Disclaimer. . When the derivative starts for the first time, it won't automatically connect to the public Tor network. This is useful for users who want to hide Tor from their ISP. setup-dist is automatically started, which educates about different methods to connect (public Tor network, bridges, etc.). Package: setup-wizard-dist Version: 3:11.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 130 Depends: setup-dist, python3-yaml, python3-distutils, helper-scripts, python3, x11-xserver-utils Recommends: icon-pack-dist Conflicts: whonix-setup-wizard Replaces: whonix-setup-wizard Provides: whonix-setup-wizard Homepage: https://github.com/Kicksecure/setup-wizard-dist Priority: optional Section: misc Filename: pool/main/s/setup-wizard-dist/setup-wizard-dist_11.1-1_all.deb Size: 55580 SHA256: 6f0bc7c9bcc1e4316c985ce35ea7504f17e9ac5f78ba7f5d2155263f14de32fd SHA1: 6fd8570b9d04e672877132f32597687e8bf4696d MD5sum: 6c985c79cb3a676fcaaea868d72fbca4 Description: First Boot Setup Disclaimer. . When distribution starts for the first time, it won't automatically connect to the public Tor network. This is useful for users who want to hide Tor from their ISP. Anon Connection Wizard is automatically started, which educates about different methods to connect (public Tor network, bridges, etc.). Package: swap-file-creator Version: 3:7.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 82 Depends: helper-scripts, cryptsetup-bin, bc Recommends: haveged, jitterentropy-rngd Homepage: https://www.kicksecure.com/wiki/Swap-file-creator Priority: optional Section: misc Filename: pool/main/s/swap-file-creator/swap-file-creator_7.1-1_all.deb Size: 30516 SHA256: 62a64991f5d48a89095681ae6de17223716e349a5a56e57872ef992093f21301 SHA1: 0a012f66d705e19d254917c8d52d1c07d6c6cbe2 MD5sum: 4dddf3b61be196e315ad42699dfd94e6 Description: Adds encrypted swap file to the system On every boot, creates a new encrypted swapfile with a random key. . Useful for systems with low RAM such as inside virtual machines. . Has an option to shred the swapfile on shutdown. Package: systemcheck Version: 3:30.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 432 Depends: dist-base-files, python3, signify-openbsd, curl, ca-certificates, msgcollector, psmisc, sudo, vrms, libarchive-tools, helper-scripts, net-tools, systemd, adduser, security-misc, spectre-meltdown-checker, apparmor-profile-dist Recommends: icon-pack-dist, msgcollector-gui Conflicts: apparmor-profile-whonixcheck, whonixcheck Replaces: apparmor-profile-whonixcheck, whonixcheck Homepage: https://www.kicksecure.com/wiki/systemcheck Priority: optional Section: misc Filename: pool/main/s/systemcheck/systemcheck_30.6-1_all.deb Size: 139324 SHA256: 2f267210841ac37e08f6389c0324d75729beb3fed21a85d2f08f077a0969dde8 SHA1: f567576874ba388a0294bf4e9086e8ebd64a3c8b MD5sum: 6bc21e58163adb283b080db7fe82175c Description: Anonymity and security check Checks many important aspects for better security. . Only checks things. Does not change things. . Safe to remove. Package: tb-default-browser Version: 3:5.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 78 Depends: tb-starter Recommends: tb-updater, open-link-confirmation Homepage: https://github.com/Kicksecure/tb-default-browser Priority: optional Section: misc Filename: pool/main/t/tb-default-browser/tb-default-browser_5.0-1_all.deb Size: 24052 SHA256: 46f1288f71daacb838d97e21828cd6f3aacf61f666a9a9743767a2975a0dd2ec SHA1: b6993d53bd252cfcd53e3735ad44a0e6efc0eab9 MD5sum: 746a41c51f9e1848b9ce33e9e238784a Description: Configures system to use /usr/bin/torbrowser as default browser Sets /usr/bin/x-www-browser to /usr/bin/torbrowser. . Sets /usr/bin/gnome-www-browser to /usr/bin/torbrowser. . Sets BROWSER environment variable to /usr/bin/x-www-browser by using /etc/profile.d/ and /etc/X11/Xsession.d/ hooks. . Registers of MIME type handlers to 'torbrowser'. . Sets KDE's default browser to x-www-browser. This only takes effect for newly created user accounts. Not for existing user accounts. This is most useful to help Linux distribution maintainers setting divergent defaults. . See also: The Default Browser on Linux Debacle http://blog.codef00.com/2011/02/18/the-default-browser-on-linux-debacle/ . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: tb-starter Version: 3:16.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 165 Depends: msgcollector Recommends: tb-updater, tb-default-browser, open-link-confirmation, icon-pack-dist Provides: torbrowser-launcher Homepage: https://github.com/Kicksecure/tb-starter Priority: optional Section: misc Filename: pool/main/t/tb-starter/tb-starter_16.7-1_all.deb Size: 65096 SHA256: 339b1b7ee154737998f8221c1b131352e812fcb9826e882ec664f21dc17d89dc SHA1: db995c20ca3297a37edc488b2894ae77dd5b3e83 MD5sum: 4c3a4d0caa529d4df23910c0232d37e4 Description: Tor Browser Starter (by Whonix developers) Both, a starter for Tor Browser. Provides security hardening, integration with Debian, Whonix and Qubes. . Starter. . - Tor Browser Starter start menu entry and `/usr/bin/torbrowser` starter. Starts `/home/user/.tb/tor-browser/start-tor-browser`. . When config option tb_hardening=true is set or when using command line option --hardening, firejail will be used. . Uses open-link-confirmation if available. . Prompts to install the browser if not yet installed. . Changes directory into browser directly before startup. . Custom homepage support. . Qubes integration. . Sanity tests: - Aborts if detected being run as root. - Aborts in Qubes TemplateVM. - Aborts in Qubes DVM Template. - Waits for Qubes mount dirs and gui agent being ready. . In Qubes AppVM copies browser from root image to private image at first start. . Tor Browser documentation by Whonix. . - https://www.whonix.org/wiki/Tor_Browser - https://www.whonix.org/wiki/Tor_Browser/Advanced_Users . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: tb-updater Version: 3:35.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 520 Depends: msgcollector-gui, curl, psmisc, gpg-bash-lib, pv, libarchive-tools, sudo, jq, libdbus-glib-1-2, python3 Recommends: tb-starter, icon-pack-dist, helper-scripts Suggests: tb-default-browser, open-link-confirmation Homepage: https://github.com/Kicksecure/tb-updater Priority: optional Section: misc Filename: pool/main/t/tb-updater/tb-updater_35.4-1_all.deb Size: 239040 SHA256: 1f1070663a0bd9f58b96edac7d1716751598b69a342299e692e124c6f49e05cd SHA1: 4bf58e90321c073b8ef0b4c110b7304527cea663 MD5sum: b2302d43ae08d7eb362b3ecf225fb28f Description: Tor Browser Downloader by Whonix developers Automates download and verification of Tor Browser from The Tor Project's website. Useful for initial installation of Tor Browser, clean re-installations of Tor Browser and keeping newly created Qubes AppVMs inherited from updated Qubes TemplateVMs can ship up to date versions of Tor Browsers. . Incapable of preserving of updating and preserving user data. Use Tor Browser's internal updater for that purpose. Notifies about already exiting installations of Tor Browser. Renamed rather than deletes old versions of Tor Browsers to avoid user data loss. . Has a cli and a gui mode. Can auto detect latest version numbers or use user configured version numbers. Comes with a download confirmation screen that lets users choose which version to download. [1] Has a installation confirmation screen [2] that enables users to detect indefinite freeze and rollback attacks. . Integrates well with tb-starter, tb-default-browser and open-link-confirmation package as well as with Qubes. . Without the helper-scripts package installed, the GUI will not move the progress bar. . If you have the helper-scripts package installed, it will show a nicer progress bar when run in terminal and more meaningful curl exit code messages, when curl failed. . When having the helper-scripts package installed (recommended for Anonymity Distributions), Tor Browser Downloader will check, that Tor is enabled, that no package manager is currently running and that Tor finished bootstrapping before download attempts. . Supports being run inside chroot and from Debian maintainer postinst script. . Qubes integration: . - Up-to-date browser versions made available to freshly created AppVMs and DispVMs. - In DispVM mounts browser folder which resides in root image to user home folder rather than copying for faster browser startup. . This package is produced independently of, and carries no guarantee from, The Tor Project. . [1] https://www.whonix.org/wiki/Tor_Browser#Download_Confirmation_Screen [2] https://www.whonix.org/wiki/Tor_Browser#Installation_Confirmation_Screen Package: timesanitycheck Version: 3:6.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 77 Homepage: https://www.whonix.org/wiki/Dev/TimeSync Priority: optional Section: misc Filename: pool/main/t/timesanitycheck/timesanitycheck_6.5-1_all.deb Size: 26468 SHA256: d7ebd083f21473868e626e90780d97a103392168c989b571fa4d1ef2cf954d4a SHA1: 7ad92fa7454deb789604afe20aadb616e5680208 MD5sum: 3984f692aca0523cf7c1f3cf9dd0f7ce Description: Checks if the system clock is sane between build timestamp and expiration date Reports, if clock is sane and not slower than build timestamp or faster than expiration date (configurable, default currently set to 17 MAY 2033 10:00:00). . This should catch situations, where the host's clock is too much off (CMOS battery defect, user mistakenly set a very wrong date, etc.), resulting in network time synchronization tools (such as sdwdate) no longer being able to correct the clock; catch eventual bigger bugs in network time synchronization tools; and some types of attacks on network time synchronization. Package: tor Version: 0.4.8.13-2~d12.bookworm+1 Architecture: arm64 Maintainer: Peter Palfrader Installed-Size: 5762 Depends: libc6 (>= 2.34), libcap2 (>= 1:2.10), libevent-2.1-7 (>= 2.1.8-stable), liblzma5 (>= 5.1.1alpha+20120614), libssl3 (>= 3.0.0), libsystemd0, libzstd1 (>= 1.5.2), zlib1g (>= 1:1.1.4), adduser, runit-helper (>= 2.14.0~), lsb-base Recommends: logrotate, tor-geoipdb, torsocks Suggests: mixmaster, torbrowser-launcher, socat, apparmor-utils, nyx, obfs4proxy Conflicts: libssl0.9.8 (<< 0.9.8g-9) Breaks: runit (<< 2.1.2-51~) Homepage: https://www.torproject.org/ Priority: optional Section: net Filename: pool/main/t/tor/tor_0.4.8.13-2~d12.bookworm+1_arm64.deb Size: 1961708 SHA256: 2ef0df8779341caeeaab38a2a1f6822ea4213bee2093d11b8e4031f26605f0f9 SHA1: 4ce5e6b53ae0d14754def8061faaaa6bf7dd9017 MD5sum: f94c97946077721bed260182014c7baf Description: anonymizing overlay network for TCP Tor is a connection-based low-latency anonymous communication system. . Clients choose a source-routed path through a set of relays, and negotiate a "virtual circuit" through the network, in which each relay knows its predecessor and successor, but no others. Traffic flowing down the circuit is decrypted at each relay, which reveals the downstream relay. . Basically, Tor provides a distributed network of relays. Users bounce their TCP streams (web traffic, ftp, ssh, etc) around the relays, and recipients, observers, and even the relays themselves have difficulty learning which users connected to which destinations. . This package enables only a Tor client by default, but it can also be configured as a relay and/or a hidden service easily. . Client applications can use the Tor network by connecting to the local socks proxy interface provided by your Tor instance. If the application itself does not come with socks support, you can use a socks client such as torsocks. . Note that Tor does no protocol cleaning on application traffic. There is a danger that application protocols and associated programs can be induced to reveal information about the user. Tor depends on Torbutton and similar protocol cleaners to solve this problem. For best protection when web surfing, the Tor Project recommends that you use the Tor Browser Bundle, a standalone tarball that includes static builds of Tor, Torbutton, and a modified Firefox that is patched to fix a variety of privacy bugs. Package: tor-control-panel Version: 1:6.4-1 Architecture: all Maintainer: troubadour Installed-Size: 179 Depends: anon-connection-wizard, helper-scripts, pkexec, policykit-1-gnome | polkit-1-auth-agent, python3, python3-ipy, python3-pyqt5, python3-stem, qtwayland5 Recommends: obfs4proxy, tor Homepage: https://www.whonix.org/wiki/Tor-control-panel Priority: optional Section: misc Filename: pool/main/t/tor-control-panel/tor-control-panel_6.4-1_all.deb Size: 67920 SHA256: a8f489ecda36463edf0d2ab120b20625449a1f1701444e4ed42c3c85e9faebde SHA1: b1aaf506a2cbc06438578bc5422fdb696df34332 MD5sum: cc05811d0e768698503d50998376caae Description: Tor Control Graphical User Interface WARNING: Not (yet) a standalone ready to use outside of Whonix: . tor-control-panel is a Tor controller. . tor-control-panel is produced independently from the Tor anonymity software and carries no guarantee from The Tor Project about quality, suitability or anything else. Package: tor-ctrl Version: 3:5.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 75 Depends: tor, netcat-openbsd, xxd Homepage: https://gitweb.torproject.org/torspec.git/tree/control-spec.txt Priority: optional Section: misc Filename: pool/main/t/tor-ctrl/tor-ctrl_5.5-1_all.deb Size: 26652 SHA256: b6aa1262eea60201441b300b8d0e4d8f358e53c1ef6b036771f9dc8a6038c01a SHA1: 6e4c7af0d04a213ee001bed0d20162fc1db8ff21 MD5sum: 1afa21e6ce9e33bfd2a817cdbefd5a20 Description: Tor controller command line tool Command line tool for setting up stream for communication from the Tor Controller's (client) to a Tor process (server). The client send commands using TCP sockets or Unix-domain sockets and receive replies from the server. . https://gitweb.torproject.org/torspec.git/tree/control-spec.txt . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: tor-geoipdb Source: tor Version: 0.4.8.13-2~d12.bookworm+1 Architecture: all Maintainer: Peter Palfrader Installed-Size: 19566 Depends: tor (>= 0.4.8.13-2~d12.bookworm+1) Breaks: tor (<< 0.2.4.8) Replaces: tor (<< 0.2.4.8) Homepage: https://www.torproject.org/ Priority: optional Section: net Filename: pool/main/t/tor/tor-geoipdb_0.4.8.13-2~d12.bookworm+1_all.deb Size: 2415852 SHA256: 8402c2171b54cfc3919803471a06b25871e64b639295bf6ecde8b8c1d25a0dfc SHA1: bd973168ef5d4db605ee665cb7c806ea1e4acee3 MD5sum: 7d1b3bab1ffa3d1c8654559d96880c9d Description: GeoIP database for Tor This package provides a GeoIP database for Tor, i.e. it maps IPv4 addresses to countries. . Bridge relays (special Tor relays that aren't listed in the main Tor directory) use this information to report which countries they see connections from. These statistics enable the Tor network operators to learn when certain countries start blocking access to bridges. . Clients can also use this to learn what country each relay is in, so Tor controllers like arm or Vidalia can use it, or if they want to configure path selection preferences. Package: usability-misc Version: 3:22.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 629 Depends: sudo, policyrcd-script-zg2, adduser, python3, damngpl Replaces: gpl-sources-download, grub-screen-resolution, scurl Homepage: https://github.com/Kicksecure/usability-misc Priority: optional Section: misc Filename: pool/main/u/usability-misc/usability-misc_22.7-1_all.deb Size: 212620 SHA256: 7809ea96d112d2ad6a30c185b9fdfd26451170076caa487857d4587a0036cf37 SHA1: 2c086b628d992f7a0211bb8b41c65837920d7b72 MD5sum: 7802e89329dc363dd4e68883c63f5d42 Description: Misc usability improvements Enables auto login for user `user` in `lightdm`. `/etc/lightdm/lightdm.conf.d/30_autologin.conf` https://www.kicksecure.com/wiki/Desktop#Disable_Autologin . Creates folders /home/user/Downloads and /home/user/Pictures. . Adds user "user" to group libvirt as well as to group kvm. . Ships a file /etc/sudoers.d/user-passwordless that contains comments and "#user ALL=(ALL:ALL) NOPASSWD:ALL". Lets user "user" easily run all commands without password. Disabled (out commented) by default. . Simplifies running OpenVPN as unprivileged user. . Ships a FoxyProxy add-on configuration file for use with Tor Browser. . Provides apt-get-noninteractive that is a simple wrapper around apt-get, that sets all required environment variables to make it interactive as well as to prevent systemd service starts and restarts during apt-get. . Sets mousepad as the default editor for environment variable VISUAL is unset and if mousepad is installed. . Disable sudo default lecture. /etc/sudoers.d/sudo-lecture-disable . Add pwfeedback to sudo Defaults so password asterisks are shown while typing. /etc/sudoers.d/pwfeedback . xfce4-terminal: . * Disables automatic scroll on output when manually scrolled up to make reading output such as "sudo journalctl -f" easier. Automatic scroll on output still happening in default when not manually scrolling up beforehand first. . * Enables unlimited scrollback by default to avoid output from being truncated. . Ships gsudoedit, a wrapper to run sudoedit with a graphical editor. . Bisq workarond "sudo mkdir -p /usr/share/desktop-directories" as per https://github.com/bisq-network/bisq/issues/848 . gpl_sources_download GPL'ed source code of all installed packages. Used damngpl to get a list of all GPL'ed packages, then downloads them using apt-get source. . SSL curl wrapper: Simple wrapper called scurl, that adds "--tlsv1.3 --proto =https" in front of all invocations of "curl" when running "scurl". . Sets 1024x768 as boot screen resolution Ships a /etc/default/grub.d/30_screen_resolution.cfg configuration file, that injects "vga=0x0317" into the GRUB_CMDLINE_LINUX_DEFAULT variable. Package: vm-config-dist Version: 3:10.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 135 Depends: sudo, adduser, p7zip-full Replaces: power-savings-disable-in-vms, shared-folder-help Homepage: https://github.com/Kicksecure/vm-config-dist Priority: optional Section: misc Filename: pool/main/v/vm-config-dist/vm-config-dist_10.5-1_all.deb Size: 40244 SHA256: 41fc4cd7e2f97bdcf23ff80b91cbbc339aca3c60445ffaa4725147e4e28d048a SHA1: d150305c67a4d3949c714c4b16a6a2c1ebe63353 MD5sum: 471286ecd49b36d287b50f807685036b Description: usability enhancements inside virtual machines Sets environment variable `QMLSCENE_DEVICE=softwarecontext` as workaround for "Automatic fallback to softwarecontext renderer". . It is not useful to open a screensaver or to power down the desktop for operating systems that are run inside VMs. There is no real display that could be saved and no real power that could be saved. From usability perspective it also is counter intuitive when looking at the VM window and only seeing a black screen. Therefore it makes sense to disable power savings in VMs. `/etc/X11/Xsession.d/20_kde_screen_locker_disable_in_vms.sh` `/etc/profile.d/20_power_savings_disable_in_vms.sh` `/etc/X11/Xsession.d/20_software_rendering_in_vms.sh` `/usr/share/kde-power-savings-disable-in-vms/kdedrc` `/usr/share/kde-screen-locker-disable-in-vms/kscreenlockerrc` . Disables screen locker when running in VMs because that is not useful either. . Makes setting up a shared folder for virtual machines a bit easier. . * Creates a folder `/mnt/shared` with `chmod 777`, adds a group "vboxsf", adds user "user" to group "vboxsf". Facilitates auto-mounting of shared folders. . * Helps using shared folders with VirtualBox and KVM a bit easier (as in requiring fewer manual steps from the user). . * `/lib/systemd/system/mnt-shared-vbox.service` * `/lib/systemd/system/mnt-shared-kvm.service` . Set screen resolution 1920x1080 by default for VM in VirtualBox and KVM. Workaround for low screen resolution 1024x768 at first boot. When using lower screen resolutions, Xfce will automatically scale down. `/etc/skel/.config/xfce4/xfconf/xfce-perchannel-xml/displays.xml` . Installs VirtualBox guest additions if package `virtualbox-guest-additions-iso` is installed if environment variable `dist_build_virtualbox=true` or if running inside VirtualBox. (`systemd-detect-virt` returning `oracle`) `/usr/bin/vbox-guest-installer`