<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Operating systems on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/operating-systems/</link>
    <description>Recent content in Operating systems on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Mon, 10 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/operating-systems/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Cold wallet: the complete guide, from a scrap of paper to multisig on Qubes OS</title>
      <link>https://arpokrat.com/blog/how-to-build-a-cold-wallet/</link>
      <pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/how-to-build-a-cold-wallet/</guid>
      <description>&lt;p&gt;In 2023, researchers at Kaspersky took apart a Trezor hardware wallet bought from a respectable-looking online marketplace. The device was visually identical to the original, packaging included, and worked normally. It displayed a list of words to copy down, exactly like a genuine one. Except that the list had not been drawn at random by the device: it had been chosen in advance by the attacker, who then only had to wait for the victim to deposit funds. &lt;a href=&#34;https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/&#34;&gt;The full analysis is published on Kaspersky&amp;rsquo;s blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;That story sums up the whole subject. The victim had bought the right product, from the right brand, with the right intentions. What failed was not the hardware, it was the procedure around it.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;A cold wallet is not an object you buy. It is a procedure you apply, and the hardware is only one part of it.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Here are five levels of security, from the simplest to the most demanding. Each one is usable as it stands. At every step, the same question: what did the previous level fail to protect against, and does that risk really apply to you?&lt;/p&gt;
&lt;h2 id=&#34;what-a-cold-wallet-is-without-the-jargon&#34;&gt;What a cold wallet is, without the jargon&lt;/h2&gt;
&lt;p&gt;A cryptocurrency is stored neither in your phone nor in your computer. It is recorded in a public ledger, the &lt;strong&gt;blockchain&lt;/strong&gt;, duplicated across thousands of machines. That ledger links an amount of funds to an &lt;strong&gt;address&lt;/strong&gt;, a long string of characters that acts as a public account number.&lt;/p&gt;
&lt;p&gt;To move those funds, you have to prove you own them. That proof comes from a secret only you hold: the &lt;strong&gt;private key&lt;/strong&gt;. It is never sent anywhere. It is used to place a cryptographic &lt;strong&gt;signature&lt;/strong&gt; on the payment instruction, and the network checks that the signature does indeed match the address concerned.&lt;/p&gt;
&lt;p&gt;All the security therefore comes down to a single point: who has seen the private key.&lt;/p&gt;
&lt;p&gt;On an exchange, that is not you. The platform holds the keys, you hold a row in its database. If it goes bankrupt, if it is hacked, if a regulator freezes accounts, that row is not worth much any more. That is the meaning of the phrase that has been going around for ten years: not your keys, not your coins.&lt;/p&gt;
&lt;p&gt;On a mobile wallet app, you do hold the key, but it was generated on an internet-connected device and it lives on that device. A modern phone runs tens of thousands of lines of code that nobody has audited, and it remains exposed to flaws unknown even to its own manufacturer. The key is safe there as long as nothing goes wrong.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;cold wallet&lt;/strong&gt; turns the logic around. The private key is generated on a device that is not connected to the internet, and it never leaves that device. What moves in and out is only transactions to be signed, going in, and signed transactions, coming out. An attacker with complete control of your connected computer would see transactions go past, but never the key that signs them.&lt;/p&gt;
&lt;p&gt;That is the only distinction that matters. Everything else consists of making it harder and harder to get around.&lt;/p&gt;
&lt;h2 id=&#34;hot-wallet-or-cold-wallet-the-difference&#34;&gt;Hot wallet or cold wallet, the difference&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;hot wallet&lt;/strong&gt; is a wallet whose private key is generated or kept on an internet-connected device, which permanently exposes it to remote attack. A cold wallet generates the key offline and signs offline, so the private key never touches a connected device. The most common confusion concerns the role of the operating system: a phone running an app such as MetaMask is still a hot wallet, even on a hardened and perfectly up-to-date system. What matters is not the general security of the device, it is the presence of a network connection at the precise moment the key is used to sign. Hardening a connected device reduces the probability of a compromise, but it does not change the category the wallet belongs to.&lt;/p&gt;
&lt;h2 id=&#34;what-the-2026-coldcard-affair-teaches-us&#34;&gt;What the 2026 Coldcard affair teaches us&lt;/h2&gt;
&lt;p&gt;One clarification is needed before we get to the levels, and recent events make it impossible to skip.&lt;/p&gt;
&lt;p&gt;At the end of July 2026, manufacturer Coinkite revealed that a defect introduced into the firmware of its Coldcards in March 2021 had affected the generation of certain seeds. This was not a deliberate fallback mechanism: an integration error when moving to a new cryptographic library meant that a macro supposed to disable the software backup generator did not have the expected effect, so the intended hardware generator was in fact bypassed in favour of the platform&amp;rsquo;s generic software generator, which is predictable. The resulting phrases looked perfectly random, but their actual entropy dropped, according to the preliminary estimates published by Coinkite, to around 40 bits on the Mk2 and Mk3 models and around 72 bits on the Mk4, Mk5 and Q, instead of the intended 128 bits. The &lt;a href=&#34;https://blog.coinkite.com/entropy-technical-backgrounder/&#34;&gt;technical backgrounder published by Coinkite&lt;/a&gt; sets out the mechanism precisely.&lt;/p&gt;
&lt;p&gt;From 30 July 2026, in four waves, attackers drained around 1,816 bitcoins spread across more than 5,200 addresses, according to &lt;a href=&#34;https://www.trmlabs.com/resources/blog/the-largest-hardware-wallet-exploit-of-2026-inside-the-usd-116-million-coldcard-hack&#34;&gt;TRM Labs&amp;rsquo; analysis&lt;/a&gt;. At no point did they need to access the victims&amp;rsquo; devices, either physically or remotely. They simply recomputed private keys that had become weak enough to be found by brute force.&lt;/p&gt;
&lt;p&gt;That is the point to hold on to. Those victims had made no mistake. Seed never shared, device never connected, physical backup beyond reproach. None of it helped, because the flaw sat at the moment the key was created, before there was anything to protect at all.&lt;/p&gt;
&lt;p&gt;This affair disqualifies neither Coldcard hardware nor hardware wallets as a category. It was a specific bug, fixed by firmware released the day after the first wave, and migrating to a new seed remains necessary since an update does not repair a key that has already been generated. But it highlights a limit that applies to everything that follows: the five levels in this article explain how to protect a key once it exists, and none of them on its own guarantees that it was correctly generated in the first place. That is precisely the value of open solutions such as SeedSigner, described further down, whose generation code is public and verifiable by anyone, where closed firmware can hide a defect for five years.&lt;/p&gt;
&lt;h2 id=&#34;level-1-the-seed-phrase-on-paper&#34;&gt;Level 1: the seed phrase on paper&lt;/h2&gt;
&lt;p&gt;Memorising a private key is impossible for a human. The &lt;a href=&#34;https://github.com/bitcoin/bips/blob/master/bip-0039.mediawiki&#34;&gt;BIP39&lt;/a&gt; standard, adopted by almost every wallet, works around the problem.&lt;/p&gt;
&lt;p&gt;The wallet draws a very large random number, then translates it into a list of ordinary words taken from a fixed dictionary of 2,048 words: the &lt;strong&gt;seed phrase&lt;/strong&gt;, or recovery phrase. Twelve words correspond to 128 bits of randomness, twenty-four words to 256 bits. From that phrase, the wallet mathematically re-derives all your private keys and all your addresses.&lt;/p&gt;
&lt;p&gt;The central consequence: the phrase is the wallet. If your device burns, you type the words into any other compatible wallet and you get your funds back exactly as they were. If someone reads those words, they need nothing else. Not your device, not your PIN.&lt;/p&gt;
&lt;p&gt;What makes the phrase impossible to guess is the amount of randomness it contains, not its apparent length. Same reasoning as for a password, set out in detail in our article on &lt;a href=&#34;https://arpokrat.com/blog/password-entropy-shannon-security/&#34;&gt;entropy and the science behind your security&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In practice, you write the words down by hand, in order and numbered, on a medium that passes through no device at all. Never a photo, a screenshot, a text file, a synchronised password manager, or an email to yourself. Anything that touches an online service takes the phrase out of the offline domain, and the cold wallet no longer exists.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What this level does not protect against.&lt;/strong&gt; Paper burns, does not survive water damage, fades, gets lost. It can be read in seconds by whoever opens the wrong drawer. Above all, it constitutes a &lt;strong&gt;single point of failure&lt;/strong&gt;, an expression that will come back throughout this article: a single element whose loss or compromise is enough to carry everything away.&lt;/p&gt;
&lt;p&gt;The immediate improvement is inexpensive: engrave the phrase on a &lt;strong&gt;metal backup&lt;/strong&gt;, a stainless steel plate with stamped letters or inserted tiles, of which &lt;a href=&#34;https://cryptosteel.com/&#34;&gt;Cryptosteel&lt;/a&gt; and Billfodl are the best known examples. Steel survives a house fire and a flood. That settles accidental destruction, not theft.&lt;/p&gt;
&lt;h2 id=&#34;level-2-the-off-the-shelf-hardware-wallet&#34;&gt;Level 2: the off-the-shelf hardware wallet&lt;/h2&gt;
&lt;p&gt;Level 1 assumes you generated the seed phrase somewhere. If you did it in a mobile app before copying it down, your phrase existed on a connected device, and the paper merely backed up a secret that was already exposed.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;hardware wallet&lt;/strong&gt; fixes that problem at the root. It is a small dedicated device, with no browser and no third-party apps, whose only job is to generate the seed phrase, keep it in a secure chip and sign transactions. It plugs into your computer, but the key never leaves the chip. The computer sends a transaction to be signed, the device displays the amount and the destination address on its own screen, you confirm with a button, it returns a signature.&lt;/p&gt;
&lt;p&gt;That screen is the essential point, and it is often misunderstood. If malware on your PC swaps the destination address at the moment of sending, the device&amp;rsquo;s screen will display the real destination, the attacker&amp;rsquo;s. It is your last independent point of verification. You have to read it, every single time.&lt;/p&gt;
&lt;p&gt;The reference devices are &lt;a href=&#34;https://www.ledger.com/&#34;&gt;Ledger&lt;/a&gt;, &lt;a href=&#34;https://trezor.io/&#34;&gt;Trezor&lt;/a&gt; and &lt;a href=&#34;https://coldcard.com/&#34;&gt;Coldcard&lt;/a&gt;, the last of which specialises in Bitcoin.&lt;/p&gt;
&lt;h3 id=&#34;vigilance-about-provenance&#34;&gt;Vigilance about provenance&lt;/h3&gt;
&lt;p&gt;Here we are back at the counterfeit wallet from the start of this article.&lt;/p&gt;
&lt;p&gt;Buy only directly from the manufacturer&amp;rsquo;s website, or from a reseller officially listed by them. Never on a general marketplace, never second-hand, never a device received as a gift. Between the factory and your hands, an intermediary can open a device, replace its contents and close it up neatly. On delivery, check the seal and the absence of any signs of opening, following the authentication procedure published by the manufacturer.&lt;/p&gt;
&lt;p&gt;Above all, remember the rule that on its own neutralises the most common attack: a new hardware wallet must make you generate a seed phrase, it must never supply you with a ready-made one. A device that arrives with a phrase already written in the box, or that asks you to enter a phrase provided to you, is compromised. No exceptions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What this level does not protect against.&lt;/strong&gt; You are now trusting a manufacturer on the quality of its randomness generator and on the integrity of its firmware, the software embedded in the device. That firmware is generally proprietary, at least in part, and therefore unverifiable on your side. Reasonable trust, justified for the vast majority of people, but trust nonetheless. And the seed phrase remains a single point of failure.&lt;/p&gt;
&lt;h2 id=&#34;level-3-the-dedicated-air-gapped-computer&#34;&gt;Level 3: the dedicated air-gapped computer&lt;/h2&gt;
&lt;p&gt;If you do not want to trust any manufacturer, there is still the option of doing everything yourself on generic hardware, with open, audited software. That is the principle of the &lt;strong&gt;air-gapped&lt;/strong&gt; machine, literally separated by a gap of air: a computer that has never been and never will be connected to a network.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Take a machine dedicated to this single purpose. An old laptop will do, and a model with no built-in wireless chip is ideal.&lt;/li&gt;
&lt;li&gt;Reinstall a clean system, a mainstream Linux distribution for instance, from an image whose cryptographic fingerprint you have verified.&lt;/li&gt;
&lt;li&gt;Neutralise networking at the lowest possible level. Physically removing the Wi-Fi card, often a small card slotted in under a hatch, is better than disabling it in the settings. Never plug in an Ethernet cable. A software switch can be undone by software, a missing component can undo nothing.&lt;/li&gt;
&lt;li&gt;Install a reference software wallet, &lt;a href=&#34;https://sparrowwallet.com/&#34;&gt;Sparrow&lt;/a&gt; or &lt;a href=&#34;https://electrum.org/&#34;&gt;Electrum&lt;/a&gt;, transferring the installer by USB stick and verifying its signature.&lt;/li&gt;
&lt;li&gt;Generate the seed phrase on that machine, offline, and back it up as in level 1.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;To spend, the flow goes through a standard format, the &lt;strong&gt;PSBT&lt;/strong&gt; (Partially Signed Bitcoin Transaction). It is a file containing every detail of a transaction, apart from the signature. On the connected computer, you prepare the transaction and export that file. You carry it to the offline machine by USB stick or by QR code displayed on screen and read by a camera. The offline machine signs it, you bring the signed file back by the same route, and the connected computer broadcasts it to the network.&lt;/p&gt;
&lt;p&gt;The only channel between the two worlds is a file you carry by hand. It is slow, and that is precisely the point.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What this level does not protect against.&lt;/strong&gt; The USB stick becomes your weak point: it is an active medium, capable of introducing code. The offline system is also still a general-purpose operating system, large and hard to audit. Discipline matters too: the temptation to plug in that network cable just once for an update wipes out the whole arrangement in one go.&lt;/p&gt;
&lt;h2 id=&#34;level-4-the-open-source-diy-signer-seedsigner&#34;&gt;Level 4: the open source DIY signer, SeedSigner&lt;/h2&gt;
&lt;p&gt;&lt;a href=&#34;https://seedsigner.com/&#34;&gt;SeedSigner&lt;/a&gt; pushes the logic of level 3 to its conclusion: a minimal device, built by you, whose behaviour is verifiable, and which keeps nothing.&lt;/p&gt;
&lt;p&gt;The central component is a &lt;strong&gt;Raspberry Pi Zero version 1.3&lt;/strong&gt;. That detail is not incidental, it is the heart of the arrangement. The Pi Zero 1.3 has neither Wi-Fi nor Bluetooth at the hardware level: the radio chips are not present on the board. This is not a Raspberry Pi 5, nor a Pi Zero W, nor a Pi Zero 2, all of which carry wireless connectivity. The official documentation is explicit, version 1.3 is the one that offers the best guarantee of network isolation.&lt;/p&gt;
&lt;p&gt;The difference from a software switch is fundamental. Wi-Fi disabled in a setting rests on the promise of one piece of software that another piece of software can break. A chip that was never soldered onto the board cannot be reactivated by any code, any flaw, any booby-trapped update. You are no longer trusting a configuration, you are observing a physical absence.&lt;/p&gt;
&lt;p&gt;The rest comes down to three parts: a 1.3 inch WaveShare screen at 240 by 240 pixels with its buttons, a camera module compatible with the Pi Zero, and a microSD card. Less than 50 dollars of components, with no soldering at all.&lt;/p&gt;
&lt;p&gt;All communication goes through QR codes, in both directions. The connected wallet, Sparrow for example, displays the PSBT as a QR code, animated if the transaction is large. The SeedSigner&amp;rsquo;s camera reads it. The device displays the transaction details on its screen, you confirm, it signs, then displays the signed transaction as a QR code in turn, which you capture with the connected computer&amp;rsquo;s webcam. No data cable, no USB stick, no network. Light is the only channel.&lt;/p&gt;
&lt;p&gt;The device is also &lt;strong&gt;stateless&lt;/strong&gt;. It never stores the key permanently: the seed phrase is entered at the start of each session, lives only in RAM while in use, and disappears when the power goes off. The microSD card contains nothing but the software. An attacker who steals your switched-off SeedSigner steals nothing but a fifteen-euro Raspberry Pi.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The flip side of openness.&lt;/strong&gt; There is no longer a manufacturer to trust, but there is no longer one to guarantee anything either. Before writing the software to the microSD card, you have to verify its authenticity yourself. The project publishes on its &lt;a href=&#34;https://github.com/SeedSigner/seedsigner/releases&#34;&gt;GitHub releases page&lt;/a&gt; the image file together with a manifest and the signature of that manifest. Verification combines a GPG signature, which proves the release really comes from the developers, and a SHA256 fingerprint check, which proves the file has not been altered since. It has to be done before you even mount the image, because some systems modify it on opening and cause the check to fail. If it fails, you do not flash.&lt;/p&gt;
&lt;p&gt;One functional limitation to note: SeedSigner is a Bitcoin project, it does not cover other chains.&lt;/p&gt;
&lt;h2 id=&#34;level-5-the-vault-vm-on-qubes-os&#34;&gt;Level 5: the Vault VM on Qubes OS&lt;/h2&gt;
&lt;p&gt;Level 3 separates two worlds by an unplugged cable. That is a guarantee you maintain manually, day after day, and it rests on your discipline.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.qubes-os.org/&#34;&gt;Qubes OS&lt;/a&gt; offers something else: a separation imposed by the architecture of the system. Qubes compartmentalises your activities into distinct virtual machines, called qubes, isolated by a hypervisor. We placed it alongside the other systems in our &lt;a href=&#34;https://arpokrat.com/blog/os-comparison-security-privacy-windows-macos-linux-qubes/&#34;&gt;comparison of security-focused operating systems&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;Vault VM&lt;/strong&gt; is created with no network interface at all. This is not a cosmetic setting: the virtual machine has no virtual network card whatsoever, no driver, no stack, nothing to enable. It has physically no way of emitting a packet, whatever code runs inside it. That is the VM that holds the seed phrase and runs Sparrow offline.&lt;/p&gt;
&lt;p&gt;A second VM, connected this time, runs Sparrow in watch-only mode, with the public keys alone. It sees the balance and the history, knows how to build transactions, but is incapable of signing one.&lt;/p&gt;
&lt;p&gt;The transfer happens exclusively by file, using the internal &lt;code&gt;qvm-copy&lt;/code&gt; tool. The unsigned PSBT goes from the connected VM to the Vault, the Vault signs it, the signed file comes back by the same mechanism. No shared network, no common folder, no automatic clipboard.&lt;/p&gt;
&lt;p&gt;Two things make this superior to a simple isolated PC. First, the isolation no longer depends on you: on a classic air-gapped machine, the air gap is a property of your behaviour, it holds as long as nobody plugs in a cable. Under Qubes, the isolation is enforced by the hypervisor, below the VM, out of reach of whatever runs inside. Malware that gained full powers inside the Vault would still have no network hardware to drive. Second, reversibility: qubes are based on templates, and if you suspect a compromise, you destroy the VM and recreate it clean in a few minutes. On a dedicated computer, the same doubt requires a full reinstall.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What this level does not protect against.&lt;/strong&gt; It is the most solid arrangement on this list, and it retains exactly the weakness of the first: there is still only one seed phrase. A fire that destroys your backup, physical coercion applied to you, a handling mistake, and everything is lost or everything is taken. Software isolation, however perfect, changes none of that.&lt;/p&gt;
&lt;h2 id=&#34;multisig-changing-the-nature-of-the-problem&#34;&gt;Multisig: changing the nature of the problem&lt;/h2&gt;
&lt;p&gt;The five previous levels all improve the same thing, the protection of a single secret. &lt;strong&gt;Multisig&lt;/strong&gt;, or multiple signature, asks a different question: what if we stopped having a single secret?&lt;/p&gt;
&lt;p&gt;The principle is written into the rules of the network. Instead of tying the funds to a single key, you tie them to a group of keys, with a threshold. In &lt;strong&gt;2 of 3&lt;/strong&gt;, three keys exist and two are needed to spend. In &lt;strong&gt;3 of 5&lt;/strong&gt;, five keys exist, three are needed. Each key is generated independently, on a different device, ideally of a different kind, and kept in a different place: a Coldcard at home, a SeedSigner with someone you trust, a key in a bank vault.&lt;/p&gt;
&lt;p&gt;What that changes is clear-cut. A burglar who finds one backup gets nothing. A fire that destroys one location does not destroy your funds, you reconstitute with the remaining keys. A defect discovered at one manufacturer is not enough, since your other keys come from elsewhere. Someone threatening you physically runs into the fact that you cannot, alone and on the spot, produce what they are asking for.&lt;/p&gt;
&lt;p&gt;The single point of failure disappears in both directions at once, against loss and against theft. None of the previous levels achieves that result, including the Qubes arrangement.&lt;/p&gt;
&lt;p&gt;The flip side is operational complexity. You have to back up not only the seeds, but also the &lt;strong&gt;wallet descriptor&lt;/strong&gt;, a file describing the structure of the arrangement and the public keys that make it up. Without it, recovering your funds becomes very difficult even with the required number of seeds. A badly documented multisig is more dangerous than a simple hardware wallet properly mastered.&lt;/p&gt;
&lt;h2 id=&#34;the-rules-that-apply-at-every-level&#34;&gt;The rules that apply at every level&lt;/h2&gt;
&lt;p&gt;Hardware takes up most of the discussion, whereas real losses most often come from elsewhere.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Spread your backups geographically.&lt;/strong&gt; Two copies of the same seed in two drawers of the same house amount to one copy in the face of a fire or water damage. The risk is not only theft. Separate the locations, bearing in mind that every additional copy improves your resistance to loss and degrades your resistance to theft. It is a trade-off, not an optimal setting.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Test with a small amount.&lt;/strong&gt; Send the equivalent of a few euros, check it arrives, then wipe the wallet and restore it entirely from your backup. A working receipt proves nothing about restoration, and it is restoration that will save you one day. A word copied wrong, a reversed order, an incomplete backup: all things that only come to light at that moment, and it is better to find out with ten euros at stake.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Stay discreet.&lt;/strong&gt; Technical security has no effect on social engineering or on targeted physical theft. Do not mention publicly that you hold cryptocurrencies, not on social media, not at the restaurant, not to distant acquaintances. The best arrangement in the world does not protect someone who is known to have something worth taking.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Plan for inheritance.&lt;/strong&gt; This is the most neglected point, and it is irreversible. A well-secured cold wallet is designed so that nobody but you can get into it. In the event of death or incapacity, that property turns against your heirs and the funds are lost for good. Several approaches exist: encrypted documentation entrusted to a trusted third party or lodged with a notary, a multisig arrangement including a key held by an heir, or a dead man&amp;rsquo;s switch mechanism that releases information in the absence of any sign of life. Each carries legal and tax implications that vary from country to country. Document the technical intent, and have the implementation framed by a legal professional.&lt;/p&gt;
&lt;h2 id=&#34;what-this-says-about-arpokrats-approach&#34;&gt;What this says about Arpokrat&amp;rsquo;s approach&lt;/h2&gt;
&lt;p&gt;The thread running through these five levels is not increasing sophistication. It is the progressive reduction in the number of actors you have to trust without being able to verify. The exchange demands total trust. The hardware wallet reduces it to one manufacturer. The SeedSigner replaces it with a verification you carry out yourself. The Qubes arrangement shifts the guarantee from behaviour to architecture. Multisig removes it from every element taken in isolation.&lt;/p&gt;
&lt;p&gt;That is the logic governing the design of our products. A guarantee that rests on a promise is not a guarantee, it is a commitment. A structural guarantee holds even when whoever built it changes their mind or receives a court order. A service that does not hold your keys cannot hand them over, whatever pressure is applied: that is the principle underlying &lt;a href=&#34;https://arpokrat.com/blog/arpokrat-swap-privacy-crypto-exchange/&#34;&gt;Arpokrat Swap&lt;/a&gt;. The question becomes more concrete as the regulatory framework evolves, as shown by our analysis of the &lt;a href=&#34;https://arpokrat.com/blog/monero-zcash-banned-eu-amlr-2027/&#34;&gt;European restrictions on Monero and Zcash planned for 2027&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;There is no such thing as a good level of security in general. There is a level proportionate to what you hold and to who could reasonably target you.&lt;/p&gt;
&lt;p&gt;A few hundred euros on a hardware wallet bought from the manufacturer, with a seed engraved on metal and stored away from your home, is a perfectly serious configuration. It already puts you above the overwhelming majority of cryptocurrency holders and protects you from the scenarios that actually cause losses. Nobody needs a multisig on Qubes for that. The complex arrangement is justified when the sum would make a targeted attack worthwhile, or when your situation attracts particular attention.&lt;/p&gt;
&lt;p&gt;The right question is therefore not how far up to go, but which of your current assumptions is the most fragile. For most people it is not the hardware: it is a single backup stored in a single place, a restoration never tested, or an inheritance never considered. Those three points cost nothing to fix, and they matter more than moving from one level to the next.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>Which operating system for your security and privacy? Windows, macOS, Linux, Tails, Whonix and Qubes OS compared</title>
      <link>https://arpokrat.com/blog/os-comparison-security-privacy-windows-macos-linux-qubes/</link>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/os-comparison-security-privacy-windows-macos-linux-qubes/</guid>
      <description>&lt;p&gt;Choosing an operating system is not merely a matter of interface preference or software compatibility. It is also — and increasingly so — a security and privacy decision. Each OS collects data differently, exposes different attack surfaces, and offers a highly variable level of control to the user. This comparison analyzes the main systems on the market exclusively through this lens, from the most widely used to the most specialized.&lt;/p&gt;
&lt;h2 id=&#34;the-central-criterion-who-controls-your-system&#34;&gt;The central criterion: who controls your system?&lt;/h2&gt;
&lt;p&gt;Before diving into the details of each OS, one structuring principle: the security of an operating system fundamentally depends on who holds the code and what architectural decisions were made at design time. A proprietary closed-source OS (Windows, macOS) delegates that trust to its publisher. An open-source OS delegates that trust to the community auditing the code. An OS designed for compartmentalized security (Qubes OS) starts from the assumption that no component of the system should be entirely trusted.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;windows-11&#34;&gt;Windows 11&lt;/h2&gt;
&lt;h3 id=&#34;data-collection-and-telemetry&#34;&gt;Data collection and telemetry&lt;/h3&gt;
&lt;p&gt;Windows 11 is the most widely used desktop OS in the world, and also one of those that collects the most data by default. Microsoft divides its telemetry into two official categories:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Required data&lt;/strong&gt; (cannot be disabled on Home and Pro editions): hardware configuration, device identifiers, error and stability reports, update and driver data. This data is transmitted to Microsoft regardless of user preferences.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Optional data&lt;/strong&gt;: usage behavior, application interactions, personalization data. Can be disabled in settings, but is automatically re-enabled during certain major updates.&lt;/p&gt;
&lt;p&gt;Windows 11 24H2 introduced several new collection layers tied to AI:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Windows Recall&lt;/strong&gt;: takes a screenshot every five seconds to create a searchable timeline of everything you have done on your machine. Can be disabled, but is enabled by default and linked to access rights that can be extended by other applications&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Copilot&lt;/strong&gt;: every query is transmitted to Microsoft servers, including screenshots, selected text, and the context of open applications&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Defender Cloud Protection&lt;/strong&gt;: sends hashes of suspicious files and behavioral data to the Microsoft cloud for analysis&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The conclusion documented by numerous independent technical sources is unequivocal: it is impossible to fully disable Windows 11 telemetry on Home and Pro editions. The only way to achieve this is to use an Enterprise or Education edition, apply specific group policies, or resort to third-party tools such as O&amp;amp;O ShutUp10++ or WPD, with the stability risks that may entail.&lt;/p&gt;
&lt;h3 id=&#34;attack-surface-and-security&#34;&gt;Attack surface and security&lt;/h3&gt;
&lt;p&gt;Windows 11 is the target of the vast majority of malware, ransomware, and exploits available worldwide, proportional to its market share. Microsoft has introduced significant security mechanisms (mandatory TPM 2.0, Secure Boot, VBS, Credential Guard), but these operate within a monolithic model: a compromise of the kernel or a privileged system service affects the entire environment.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security/privacy verdict:&lt;/strong&gt; the most exposed system in this comparison, telemetry that cannot be fully disabled, trust model entirely delegated to Microsoft and US jurisdiction.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;macos&#34;&gt;macOS&lt;/h2&gt;
&lt;h3 id=&#34;data-collection-and-telemetry-1&#34;&gt;Data collection and telemetry&lt;/h3&gt;
&lt;p&gt;Apple has built part of its marketing image on privacy. The technical reality is more nuanced.&lt;/p&gt;
&lt;p&gt;macOS collects significantly less data than Windows by default, but collection remains real and partially non-disableable:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Gatekeeper and OCSP verification&lt;/strong&gt;: every time an application is opened, macOS performs an online check with Apple servers to confirm the application has not been revoked. This request transmits information about the opened application and the device&amp;rsquo;s IP address. No native setting allows disabling these checks without breaking the security chain&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;macOS Analytics&lt;/strong&gt;: collects data on system usage, disableable in System Preferences &amp;gt; Privacy &amp;gt; Analytics&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Apple application telemetry&lt;/strong&gt;: Maps, Siri, App Store, and other built-in Apple applications each maintain their own collection with rotating identifiers, independently of the system analytics setting&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For users who want to go further, security experts recommend using an application firewall (Little Snitch or LuLu, which is open source and free) to monitor and block outgoing connections on a per-application basis.&lt;/p&gt;
&lt;h3 id=&#34;attack-surface-and-security-1&#34;&gt;Attack surface and security&lt;/h3&gt;
&lt;p&gt;macOS benefits from several robust security mechanisms: System Integrity Protection (SIP), which protects system files as read-only; Kernel Integrity Protection at the hardware level on Apple Silicon chips; sandboxing of App Store applications; and the Secure Enclave on recent machines. The relationship with an Apple ID is the primary vector for personal data collection.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security/privacy verdict:&lt;/strong&gt; better than Windows on default telemetry, but still subject to non-disableable OCSP checks, US jurisdiction, and Apple&amp;rsquo;s closed model. Difficult to audit independently.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;linux-general-purpose-distributions&#34;&gt;Linux (general-purpose distributions)&lt;/h2&gt;
&lt;p&gt;Linux is not a single operating system but a kernel upon which very different distributions are built. From a security and privacy standpoint, they share a common foundation but diverge on several points.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Ubuntu&lt;/strong&gt; is the most popular distribution for beginners. It sparked controversy in 2012 by sending local search queries to Amazon servers — behavior that has since been removed. Ubuntu maintains its own usage data collection (whoopsie, ubuntu-report), which is disableable, and tightly integrates Snap repositories controlled by Canonical Ltd.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Debian&lt;/strong&gt; is the base upon which Ubuntu is built, without the layers added by Canonical. Governed by a non-profit community project with a strict commitment to free software, it collects no telemetry by default. Its conservative update policy is generally preferable in terms of attack surface.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fedora&lt;/strong&gt;, sponsored by Red Hat (an IBM subsidiary), is technically modern with a fast update cycle. No telemetry by default, but the relationship with Red Hat/IBM introduces a corporate dependency worth noting.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Linux Mint&lt;/strong&gt;, derived from Ubuntu, is designed for users coming from Windows. It has removed the most controversial Ubuntu components (Snap is absent by default) and introduces no telemetry of its own.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Arch Linux&lt;/strong&gt; targets advanced users with a minimalist philosophy: the user installs only what they need. No telemetry, rolling release updates, and total freedom of customization.&lt;/p&gt;
&lt;h3 id=&#34;what-linux-fundamentally-offers&#34;&gt;What Linux fundamentally offers&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Open and auditable source code&lt;/strong&gt;: any security researcher can inspect the kernel and main component code&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No imposed telemetry&lt;/strong&gt;: no major distribution forces non-disableable data collection&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Stricter permissions model&lt;/strong&gt; by default: use of a root account separate from daily actions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduced attack surface&lt;/strong&gt;: Linux is less targeted by mass malware&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Security/privacy verdict:&lt;/strong&gt; clearly superior to Windows and macOS on data collection. No general-purpose distribution protects against a compromised application spreading across the entire system.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;tails-os&#34;&gt;Tails OS&lt;/h2&gt;
&lt;h3 id=&#34;philosophy-amnesia-as-protection&#34;&gt;Philosophy: amnesia as protection&lt;/h3&gt;
&lt;p&gt;Tails, an acronym for &lt;em&gt;The Amnesic Incognito Live System&lt;/em&gt;, is a Debian-based operating system that merged with the Tor Project in 2024. Its philosophy is radically different from all other OSes: rather than attempting to secure a persistent environment, it eliminates all persistence by default. &lt;strong&gt;Tails exists only for the duration of a session.&lt;/strong&gt;&lt;/p&gt;
&lt;h3 id=&#34;technical-architecture&#34;&gt;Technical architecture&lt;/h3&gt;
&lt;p&gt;Tails runs entirely from a USB drive (8 GB minimum) and operates entirely in RAM. When you shut it down, no trace remains on the host machine: no temporary files, no history, no credentials, no forensic artifacts on the PC&amp;rsquo;s hard drive. It does not matter if that PC is compromised at the software level: Tails never writes to its disk.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Tor by default and without exception&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;All network traffic in Tails is systematically routed through the Tor network. If an application attempts to establish a direct connection bypassing Tor, Tails blocks it. It is not possible to use Tails to browse without Tor, even by mistake.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Encrypted persistent storage (optional)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;By default, Tails forgets everything on each shutdown. For users who need to retain certain data between sessions, Tails offers a &lt;strong&gt;Persistent Storage&lt;/strong&gt;: an encrypted volume (LUKS) created on the USB drive itself, protected by a passphrase. The user chooses precisely what is stored there: certain files, application configurations, PGP keys, etc. This persistent storage does not change the amnesic nature of Tails with respect to the host machine — it only affects what is retained on the USB drive between sessions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Pre-installed tools&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Tails comes with a set of pre-configured tools: Tor Browser, an encrypted email client, a file encryption tool (Kleopatra/GnuPG), secure messaging clients, and LibreOffice for office tasks. No additional software needs to be installed for common high-security use.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;2026 technical note:&lt;/strong&gt; Tails 7.7 added a notification for outdated Secure Boot certificates, as Microsoft&amp;rsquo;s 2011 keys are beginning to expire in June 2026. Users whose UEFI firmware has not been updated may no longer be able to boot Tails on certain machines.&lt;/p&gt;
&lt;h3 id=&#34;what-tails-protects-against-and-what-it-does-not&#34;&gt;What Tails protects against and what it does not&lt;/h3&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Threat&lt;/th&gt;
					&lt;th&gt;Tails Protection&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;Forensic analysis of the host disk after seizure&lt;/td&gt;
					&lt;td&gt;Total: the host disk is never touched&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Network surveillance (IP, sites visited)&lt;/td&gt;
					&lt;td&gt;Strong via Tor, but depends on Tor&amp;rsquo;s robustness&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Persistent malware on the host machine&lt;/td&gt;
					&lt;td&gt;Bypassed: Tails does not use the installed system&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;BIOS/UEFI malware (compromised firmware)&lt;/td&gt;
					&lt;td&gt;None: Tails cannot protect against the firmware of the machine being used&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Human error (logging into a personal account)&lt;/td&gt;
					&lt;td&gt;None: if you log into Gmail under Tails, you de-anonymize the session&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Compromise of software during the session&lt;/td&gt;
					&lt;td&gt;Limited to the current session, destroyed on shutdown&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&#34;honest-limitations&#34;&gt;Honest limitations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Tails is not suitable for everyday use: the lack of persistence means reconfiguring the environment on every boot&lt;/li&gt;
&lt;li&gt;A BIOS or firmware-level malware (such as a UEFI-level implant) can potentially compromise a Tails session, because Tails does not control the firmware layer of the machine it runs on&lt;/li&gt;
&lt;li&gt;Logging into a personal account (email, social network) cancels the anonymity of the session, regardless of Tor&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;who-is-it-for&#34;&gt;Who is it for?&lt;/h3&gt;
&lt;p&gt;Journalists working with sources via SecureDrop, activists under surveillance in repressive regimes, and anyone needing a one-off high-sensitivity session on hardware they do not control. Used by Glenn Greenwald and Laura Poitras to process the Snowden documents, recommended by the EFF, the Freedom of the Press Foundation, and the Tor Project.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; a first-choice tool for one-off high-sensitivity sessions. Not a primary everyday OS.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;whonix&#34;&gt;Whonix&lt;/h2&gt;
&lt;h3 id=&#34;philosophy-structural-anonymity-through-network-isolation&#34;&gt;Philosophy: structural anonymity through network isolation&lt;/h3&gt;
&lt;p&gt;Whonix addresses a different question than Tails: rather than erasing all traces after the session, it ensures that malware running in the work environment &lt;strong&gt;structurally cannot know the user&amp;rsquo;s real IP address&lt;/strong&gt;, even if it has root privileges on the work virtual machine.&lt;/p&gt;
&lt;p&gt;Whonix is based on Debian (via KickSecure, a hardened version of Debian developed by the same team) and runs inside a Type 2 hypervisor (VirtualBox, KVM) on any host OS, or natively in Qubes OS as a Type 1.&lt;/p&gt;
&lt;h3 id=&#34;the-two-vm-architecture&#34;&gt;The two-VM architecture&lt;/h3&gt;
&lt;p&gt;The central principle of Whonix is a &lt;strong&gt;strict separation between the network layer and the application layer&lt;/strong&gt;, implemented via two distinct virtual machines:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Whonix-Gateway&lt;/strong&gt; is the first VM. It runs the Tor daemon and serves exclusively as a network gateway. It is the only VM with Internet access. It contains no user applications. Its sole role is to intercept all incoming and outgoing network traffic and force it through Tor.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Whonix-Workstation&lt;/strong&gt; is the second VM. It is the working environment: browser, messaging, file processing, development. It is connected to the Internet only through the internal virtual network pointing to the Whonix-Gateway. It has no direct Internet access, no ability to connect in a way that would bypass the Gateway.&lt;/p&gt;
&lt;p&gt;Here is what happens when a network request is made from the Workstation:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;The application issues a network request&lt;/li&gt;
&lt;li&gt;The Workstation sends it via its internal network interface to the Gateway&lt;/li&gt;
&lt;li&gt;The Gateway intercepts the request and reroutes it through Tor (three successive relays)&lt;/li&gt;
&lt;li&gt;The response returns by the same path in reverse&lt;/li&gt;
&lt;li&gt;The Workstation receives the response without ever having knowledge of the real exit IP address&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;The fundamental guarantee&lt;/strong&gt;: even if malware compromises the Workstation with root privileges, it cannot know the user&amp;rsquo;s real IP address, because the Workstation itself never has access to it. The Workstation only sees the internal IP address of the Gateway.&lt;/p&gt;
&lt;h3 id=&#34;additional-security-mechanisms&#34;&gt;Additional security mechanisms&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Stream isolation&lt;/strong&gt;: Whonix uses separate Tor circuits for different applications (the browser does not use the same circuit as the email client, etc.), which prevents traffic correlation between different activities.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Boot clock randomization&lt;/strong&gt;: the Workstation&amp;rsquo;s system clock is slightly and randomly offset on each boot to prevent timing attacks based on the exact system time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;sdwdate&lt;/strong&gt;: Whonix uses its own time synchronization daemon (sdwdate) that retrieves the time via Tor from onion servers, instead of classic NTP which could leak the IP address.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;AppArmor&lt;/strong&gt;: AppArmor profiles harden the sandboxing of critical applications such as Tor Browser at the system level.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Disposable VMs&lt;/strong&gt;: Whonix supports disposable Workstations (&lt;em&gt;Whonix-Workstation DispVM&lt;/em&gt; in Qubes-Whonix) for one-off tasks without persistence, similar to the Tails approach but within an otherwise persistent environment.&lt;/p&gt;
&lt;h3 id=&#34;the-three-deployment-modes&#34;&gt;The three deployment modes&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Whonix on VirtualBox or KVM (Type 2)&lt;/strong&gt;: the most accessible mode. Both VMs run on an existing host OS (Windows, Linux, macOS). Convenient, but introduces an additional trust layer in the host OS: if the host is compromised, Whonix&amp;rsquo;s protection can be bypassed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Qubes-Whonix (Type 1, recommended)&lt;/strong&gt;: Whonix is natively integrated into Qubes OS as templates. The Gateway becomes a ProxyVM (sys-whonix) and the Workstation an AppQube (anon-whonix). This is the most robust configuration because the isolation relies on the bare-metal Xen hypervisor rather than a Type 2 hypervisor running on a potentially vulnerable host OS. This is the configuration recommended by both projects.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Physical isolation (advanced mode)&lt;/strong&gt;: the Gateway and the Workstation run on two separate physical machines connected by an Ethernet cable. The Workstation has no network card except the one connected to the Gateway. This mode drastically reduces the trust base but requires two dedicated machines.&lt;/p&gt;
&lt;h3 id=&#34;what-whonix-protects-against-and-what-it-does-not&#34;&gt;What Whonix protects against and what it does not&lt;/h3&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Threat&lt;/th&gt;
					&lt;th&gt;Whonix Protection&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;IP address leak from the Workstation&lt;/td&gt;
					&lt;td&gt;Structurally impossible by architecture&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;DNS leaks&lt;/td&gt;
					&lt;td&gt;Impossible: all DNS goes through Tor via the Gateway&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Root malware on the Workstation seeking the real IP&lt;/td&gt;
					&lt;td&gt;None: it will not find it&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Compromise of the Gateway itself&lt;/td&gt;
					&lt;td&gt;Partial: if the Gateway is compromised, the IP can leak&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Host OS compromise (in Type 2 mode)&lt;/td&gt;
					&lt;td&gt;None: a compromised host can observe both VMs&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;De-anonymization through user behavior&lt;/td&gt;
					&lt;td&gt;None: Whonix does not protect against human error&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Forensic analysis of the disk after seizure&lt;/td&gt;
					&lt;td&gt;Partial: Whonix is persistent by default, except for disposable VMs&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&#34;honest-limitations-1&#34;&gt;Honest limitations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Whonix does not erase disk traces: it is persistent by default (unlike Tails). If your machine is seized and host disk encryption is absent or weak, VM data can be recovered&lt;/li&gt;
&lt;li&gt;In Type 2 mode (VirtualBox/KVM on a host OS), Whonix&amp;rsquo;s security is limited by the security of the host OS. A compromised host can potentially observe traffic between the two VMs&lt;/li&gt;
&lt;li&gt;Performance is impacted by double virtualization and routing through Tor: connections are slow, and large downloads are difficult on a daily basis&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;who-is-it-for-1&#34;&gt;Who is it for?&lt;/h3&gt;
&lt;p&gt;Anyone needing a persistent working environment with structural network anonymity: development of sensitive software, extended pseudonymous research, management of multiple distinct digital identities, onion servers. The Qubes-Whonix combination is considered by many security experts to be the most robust anonymous working environment currently available for everyday use.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; the reference OS for structural network anonymity in a persistent environment. Complementary to Tails (which handles one-off sessions), not a competitor.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;qubes-os&#34;&gt;Qubes OS&lt;/h2&gt;
&lt;h3 id=&#34;philosophy-security-through-compartmentalization&#34;&gt;Philosophy: security through compartmentalization&lt;/h3&gt;
&lt;p&gt;Qubes OS represents a fundamentally different approach from all the preceding systems. Whereas other OSes attempt to prevent compromises, Qubes starts from a radically different postulate: &lt;strong&gt;the compromise of certain components is inevitable. The objective is to ensure it cannot spread.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Created in 2012 by security researcher Joanna Rutkowska, Qubes OS is publicly recommended by Edward Snowden, among other security professionals.&lt;/p&gt;
&lt;h3 id=&#34;technical-architecture-1&#34;&gt;Technical architecture&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;The Xen hypervisor as the base layer&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Qubes is not a Linux distribution in the classical sense. It uses the &lt;strong&gt;Xen hypervisor&lt;/strong&gt;, bare-metal virtualization software that runs directly on the hardware without an intermediate host OS, to create lightweight virtual machines called &lt;strong&gt;qubes&lt;/strong&gt;. Isolation between qubes is enforced at the hardware level via &lt;strong&gt;Intel VT-x/VT-d&lt;/strong&gt; and &lt;strong&gt;AMD-Vi (IOMMU)&lt;/strong&gt; technologies, which prevent VMs from accessing the memory or devices of other VMs without explicit permission.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;dom0: the maximum-trust domain&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;At the top of the hierarchy sits &lt;strong&gt;dom0&lt;/strong&gt;, a privileged domain from which the desktop manager is run. dom0 manages the display of all windows from other qubes. For security reasons, dom0 has &lt;strong&gt;no network connection&lt;/strong&gt; and runs no user applications. It serves only to orchestrate display and domain management.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Qubes: airtight compartments&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The user defines as many qubes as needed, each corresponding to a trust context:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A &lt;strong&gt;&amp;ldquo;work&amp;rdquo;&lt;/strong&gt; qube for professional applications&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;&amp;ldquo;personal&amp;rdquo;&lt;/strong&gt; qube for emails and social networks&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;&amp;ldquo;banking&amp;rdquo;&lt;/strong&gt; qube dedicated solely to financial transactions&lt;/li&gt;
&lt;li&gt;An &lt;strong&gt;&amp;ldquo;untrusted&amp;rdquo;&lt;/strong&gt; qube for opening suspicious attachments&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Disposable qubes&lt;/strong&gt; that disappear entirely on closure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Each qube has its own network stack, its own memory space, and its own processes. Malware that compromises the &amp;ldquo;untrusted&amp;rdquo; qube is confined to that qube. It cannot access files in the &amp;ldquo;work&amp;rdquo; qube, nor traverse to other domains.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Visual color coding&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Each window displays a colored border corresponding to the trust level of its qube: red for untrusted domains, green for high-security isolated domains, yellow for semi-trusted domains. This simple visual system allows users to know at all times in which context each action is taking place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Templates and centralized management&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Qubes do not contain their own full OS installation: they share &lt;strong&gt;templates&lt;/strong&gt; (Fedora, Debian, and Whonix by default). Security updates are applied to the template, and all qubes based on that template benefit from them automatically.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;PCI passthrough and hardware isolation&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Whereas classic OSes run hardware drivers in the same space as user applications, Qubes assigns each physical device (network card, USB controller) to a dedicated qube via PCI passthrough. A compromised network driver cannot access data from other qubes.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Whonix integration&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Qubes natively integrates Whonix as templates, allowing the traffic of any qube to be routed through Tor transparently. This is the Qubes-Whonix configuration described in the previous section.&lt;/p&gt;
&lt;h3 id=&#34;what-qubes-actually-protects-against&#34;&gt;What Qubes actually protects against&lt;/h3&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Attack scenario&lt;/th&gt;
					&lt;th&gt;Classic OS&lt;/th&gt;
					&lt;th&gt;Qubes OS&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;Malware in a PDF attachment&lt;/td&gt;
					&lt;td&gt;Potential access to the entire system&lt;/td&gt;
					&lt;td&gt;Confined to the &amp;ldquo;untrusted&amp;rdquo; qube, destroyed on closure&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Web browser exploit&lt;/td&gt;
					&lt;td&gt;Access to user profile, files&lt;/td&gt;
					&lt;td&gt;Confined to the browser qube&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Network driver compromise&lt;/td&gt;
					&lt;td&gt;Access to system memory&lt;/td&gt;
					&lt;td&gt;Confined to the network qube via PCI passthrough&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Stolen PGP key&lt;/td&gt;
					&lt;td&gt;Yes, if the signing software is compromised&lt;/td&gt;
					&lt;td&gt;No, if the key is in a dedicated qube with no network&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Leakage between applications&lt;/td&gt;
					&lt;td&gt;Possible via IPC, shared memory&lt;/td&gt;
					&lt;td&gt;Impossible between distinct qubes&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id=&#34;honest-limitations-2&#34;&gt;Honest limitations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Qubes does not protect against a dom0 compromise&lt;/strong&gt;: if the Xen hypervisor itself is compromised, isolation can be broken (bulletin QSB-115 dated June 9, 2026, regarding vulnerability XSA-491)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No isolation within a single qube&lt;/strong&gt;: two applications in the same qube are not isolated from each other&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Significant hardware requirements&lt;/strong&gt;: processor supporting VT-x/VT-d, minimum 16 GB RAM (32 GB recommended), 32 GB storage. Apple Silicon machines are not supported&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Real learning curve&lt;/strong&gt;: copy-pasting between qubes requires a conscious action, and installing software goes through templates&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&#34;who-is-it-for-2&#34;&gt;Who is it for?&lt;/h3&gt;
&lt;p&gt;Qubes OS is designed for profiles whose threat model includes serious adversaries: journalists working with sensitive sources, lawyers managing confidential files, security researchers, professionals handling industrial or diplomatic secrets.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; the reference standard for personal workstation security against capable adversaries. The Qubes + Whonix combination is considered the most robust environment currently available.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&#34;how-these-systems-combine&#34;&gt;How these systems combine&lt;/h2&gt;
&lt;p&gt;It is important to understand that these OSes are not exclusively alternatives to one another: they address different needs and are often combined.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Qubes + Whonix&lt;/strong&gt;: the most robust combination for high-security everyday use. Qubes handles compartmentalization, Whonix handles network anonymity within certain qubes&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Qubes + Tails&lt;/strong&gt;: some advanced users use Qubes as their primary OS and boot Tails from a dedicated qube for particularly sensitive one-off sessions&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Linux + Whonix in VMs&lt;/strong&gt;: an accessible entry point into structural network anonymity without the full complexity of Qubes&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id=&#34;summary-table&#34;&gt;Summary table&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Criterion&lt;/th&gt;
					&lt;th&gt;Windows 11&lt;/th&gt;
					&lt;th&gt;macOS&lt;/th&gt;
					&lt;th&gt;Linux (Debian)&lt;/th&gt;
					&lt;th&gt;Tails&lt;/th&gt;
					&lt;th&gt;Whonix&lt;/th&gt;
					&lt;th&gt;Qubes OS&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;Default telemetry&lt;/td&gt;
					&lt;td&gt;Significant, cannot be fully disabled&lt;/td&gt;
					&lt;td&gt;Moderate, partially non-disableable&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Auditable source code&lt;/td&gt;
					&lt;td&gt;No&lt;/td&gt;
					&lt;td&gt;No&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Data persistence&lt;/td&gt;
					&lt;td&gt;Permanent&lt;/td&gt;
					&lt;td&gt;Permanent&lt;/td&gt;
					&lt;td&gt;Permanent&lt;/td&gt;
					&lt;td&gt;None by default&lt;/td&gt;
					&lt;td&gt;Permanent (VMs)&lt;/td&gt;
					&lt;td&gt;Permanent per qube&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Network anonymity&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;None&lt;/td&gt;
					&lt;td&gt;Strong (Tor enforced)&lt;/td&gt;
					&lt;td&gt;Structural (Tor enforced)&lt;/td&gt;
					&lt;td&gt;Via Whonix integration&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Isolation between applications&lt;/td&gt;
					&lt;td&gt;Weak&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Weak&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Strong (hypervisor)&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Resistance to compromise&lt;/td&gt;
					&lt;td&gt;Weak&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;High (amnesic)&lt;/td&gt;
					&lt;td&gt;High (network isolation)&lt;/td&gt;
					&lt;td&gt;High (compartmentalization)&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Ease of use&lt;/td&gt;
					&lt;td&gt;High&lt;/td&gt;
					&lt;td&gt;High&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Moderate&lt;/td&gt;
					&lt;td&gt;Low to moderate&lt;/td&gt;
					&lt;td&gt;Low&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Required hardware&lt;/td&gt;
					&lt;td&gt;Standard&lt;/td&gt;
					&lt;td&gt;Mac only&lt;/td&gt;
					&lt;td&gt;Standard&lt;/td&gt;
					&lt;td&gt;Standard + USB&lt;/td&gt;
					&lt;td&gt;Standard + RAM&lt;/td&gt;
					&lt;td&gt;x86-64 with VT-d, 16+ GB RAM&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Suitable profile&lt;/td&gt;
					&lt;td&gt;General use&lt;/td&gt;
					&lt;td&gt;General use&lt;/td&gt;
					&lt;td&gt;Intermediate profile&lt;/td&gt;
					&lt;td&gt;One-off sensitive sessions&lt;/td&gt;
					&lt;td&gt;Persistent network anonymity&lt;/td&gt;
					&lt;td&gt;High-security daily use&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;p&gt;Choosing an OS based on security is not a binary decision. It is an alignment between a real threat model and acceptable trade-offs in terms of compatibility and ease of use. For the vast majority of users, a well-configured Linux distribution already offers a level of protection radically superior to Windows 11 or macOS. For high-sensitivity profiles, &lt;a href=&#34;https://tails.boum.org&#34;&gt;Tails&lt;/a&gt;, &lt;a href=&#34;https://www.whonix.org&#34;&gt;Whonix&lt;/a&gt;, and &lt;a href=&#34;https://www.qubes-os.org&#34;&gt;Qubes OS&lt;/a&gt; represent three complementary approaches, each optimized for a distinct threat model.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The Time Bomb: Harvest Now, Decrypt Later and the Zero-Knowledge Imperative</title>
      <link>https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/</link>
      <pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/</guid>
      <description>&lt;p&gt;The dependence of European governments on American cloud infrastructure poses more than just an immediate interception problem. The great revelation, the most devastating threat for decades to come, is what intelligence specialists call the &lt;strong&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later&#34;&gt;HNDL: &amp;ldquo;Harvest Now, Decrypt Later&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; strategy.&lt;/p&gt;
&lt;p&gt;This is not a frontal intrusion, but a silent theft. Intelligence agencies and state adversaries are intercepting and storing immense amounts of encrypted data today, simply because the cost of storage has become negligible.&lt;/p&gt;
&lt;p&gt;They wait patiently for the moment when technological leaps and the unpredictable evolution of computing power will render current cryptographic keys obsolete. What constitutes a protected state secret in 2026 could become an open book in fifteen or twenty years.&lt;/p&gt;
&lt;h2 id=&#34;retroactive-liability-and-temporal-risk&#34;&gt;Retroactive Liability and Temporal Risk&lt;/h2&gt;
&lt;p&gt;The HNDL model introduces a novel concept: delayed legal harm. Traditionally, a breach of secrecy is a static event. With the massive collection of data for future decryption, confidentiality becomes a time-dependent variable.&lt;/p&gt;
&lt;p&gt;To quantify this risk, the HNDL scientific model defines that confidentiality inevitably fails when the required lifespan of the secret exceeds the adversary&amp;rsquo;s decryption horizon. Sectors of critical exposure are currently in a state of latent vulnerability.&lt;/p&gt;
&lt;p&gt;If a state or an organization does not guarantee the absolute sovereignty of its hardware infrastructure, it is practically signing a waiver of long-term confidentiality for its citizens and institutions.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Today&amp;rsquo;s interception is tomorrow&amp;rsquo;s compromise. Turning cloud dependence into a national security debt is a gamble impossible to repay.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;the-arpokrat-antithesis-legal-impossibility-by-code&#34;&gt;The Arpokrat Antithesis: Legal Impossibility by Code&lt;/h2&gt;
&lt;p&gt;Faced with this vulnerability, the industry is responding by creating &lt;a href=&#34;https://arpokrat.com/&#34;&gt;radical digital sovereignty ecosystems&lt;/a&gt;. The Arpokrat model emerges as the perfect antithesis to centralized messaging: this architecture operates on a decentralized network, protected by the very strict &lt;a href=&#34;https://www.edoeb.admin.ch/en/basic-knowledge&#34;&gt;Federal Act on Data Protection (FADP) in Switzerland&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The core logic is one of absolute &lt;em&gt;Privacy by Design&lt;/em&gt;. By removing the need to provide a phone number, the user becomes a simple cryptographic key, devoid of physical identity.&lt;/p&gt;
&lt;p&gt;Legally, this drastically changes the rules of the game. If the &lt;a href=&#34;https://arpokrat.com/infrastructure&#34;&gt;architecture is fundamentally Zero-Knowledge&lt;/a&gt; and non-custodial, the company faces a technical impossibility to comply with foreign warrants.&lt;/p&gt;
&lt;p&gt;This is not civil disobedience against extraterritorial laws, but an unstoppable mathematical and legal safeguard: &lt;strong&gt;what you do not hold cannot be disclosed.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&#34;beyond-encryption-devaluing-the-target-data&#34;&gt;Beyond Encryption: Devaluing the Target Data&lt;/h2&gt;
&lt;p&gt;The true response, natively integrated into the &lt;a href=&#34;https://arpokrat.com/messenger&#34;&gt;Arpokrat messaging app&lt;/a&gt;, is not to bet on eternal mathematics, but to &lt;strong&gt;devalue the data itself&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Without central metadata, without phone numbers, and without IP logs to link a message to a physical individual, the encrypted content loses its strategic value because it becomes unattributable.&lt;/p&gt;
&lt;p&gt;However, software alone can do nothing if the hardware betrays it upstream.&lt;/p&gt;
&lt;p&gt;Ultimately, security in the 21st century requires the independence of the machine itself. Deploying a &lt;a href=&#34;https://arpokrat.com/os&#34;&gt;sovereign de-Googled OS&lt;/a&gt; has become an absolute survival requirement for anyone handling state secrets.&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>