Package: anon-apt-sources-list Version: 3:7.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 77 Depends: fasttrack-archive-keyring Homepage: https://github.com/Kicksecure/anon-apt-sources-list Priority: optional Section: misc Filename: pool/main/a/anon-apt-sources-list/anon-apt-sources-list_7.4-1_all.deb Size: 30532 SHA256: aa939354e1744c1683b2d2ff3c4550560ac5f31ce9b45a8ca612f5d80d2cb9bf SHA1: c354d9515137ff739176d0f0a6a730c7e0149a1c MD5sum: 6d02dc64923bfdcdcc0b0230cde2a188 Description: Kicksecure APT and Flatpak Repository Configuration Configuring APT and Flatpak sources: - Includes Debian APT repositories (main, updates, backports, fasttrack, security) - Incorporates Debian APT components (main, contrib, non-free, non-free-firmware) - Integrates the Flathub repository (verified and floss subsets only) . Flatpak: - Official Flathub repository only. - Uses subset verified_floss, which means only verified applications and freedom software can be installed by default. . Provides configuration files: - /etc/apt/sources.list.d/debian.sources for APT sources - /etc/flatpak/remotes.d/flathub.flatpakrepo for Flatpak sources . A Discussion on Distribution Maintenance Strategies: . The more standard way would indeed be populating /etc/apt/sources.list at install or build time and leaving /etc/apt/sources.list.d alone. . The idea of managing /etc/apt/sources.list.d/debian.sources for the user is, the security-focused distribution maintainers can decide when it is a better "change stable to oldstable", "keep wheezy as long as needed to work out [eventual!] issues that would break during upgrade to jessie" and such. Package: anon-connection-wizard Version: 1:10.5-1 Architecture: all Maintainer: iry Installed-Size: 269 Depends: helper-scripts, pkexec, policykit-1-gnome | polkit-1-auth-agent, privleap, python3, python3-pyqt5, python3-stem, python3-yaml, qtwayland5 Recommends: obfs4proxy, tor Homepage: https://www.kicksecure.com/wiki/Anon_Connection_Wizard Priority: optional Section: misc Filename: pool/main/a/anon-connection-wizard/anon-connection-wizard_10.5-1_all.deb Size: 94660 SHA256: 97f766350c0a790cdc7b3a2652751ba42f2607e9cc28ff4f3a57147a2a5e1487 SHA1: 99a764b3fc3aa1368377df33a804d43483dee3fa MD5sum: cdcdc92a5df2db05539c0f4e5aaa6c43 Description: Tor Connection Configuration (ACW) WARNING: Not (yet) a standalone ready to use outside of Whonix: . Creates a Tor settings file: `/usr/local/etc/torrc.d/40_tor_control_panel.conf` . anon-connection-wizard (ACW) is a Tor-launcher-like application that helps users in different Internet environment connect to the Tor network. It helps user to configure Tor to use a proxy and/or Tor bridges. This application is especially useful for system Tor users who would like to run the standalone core Tor with different torified applications. The wizard can be run at any time to change the connection configuration. . Creates a Tor settings file: `/usr/local/etc/torrc.d/40_tor_control_panel.conf` . anon-connection-wizard is produced independently from the Tor anonymity software and carries no guarantee from The Tor Project about quality, suitability or anything else. Package: anon-shared-build-apt-sources-tpo Version: 3:6.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 125 Depends: helper-scripts, gnupg Recommends: deb.torproject.org-keyring Homepage: https://github.com/Kicksecure/anon-shared-build-apt-sources-tpo Priority: optional Section: misc Filename: pool/main/a/anon-shared-build-apt-sources-tpo/anon-shared-build-apt-sources-tpo_6.8-1_all.deb Size: 64676 SHA256: 19326f5b898218458667ad991280445a481cc1cb1c42f3ee906114538dee3e26 SHA1: 04efe4c2385aca5ea26072192bae134a227b3204 MD5sum: dd408e3b03c5ab3edcedde8369a0724f Description: Adds TPO's APT repository to Derivative Linux Distributions Comes with "deb http://deb.torproject.org/torproject.org stable main", The Tor Project's APT signing key. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: apparmor-profile-dist Version: 3:9.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 95 Depends: helper-scripts Replaces: apparmor-profile-anondist Homepage: https://www.kicksecure.com/wiki/Apparmor-profile-everything Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-dist/apparmor-profile-dist_9.8-1_all.deb Size: 35920 SHA256: 298a736e1ec3111f0100669af19138449f78e4e8cf1d6df46460ca3f472c97ad SHA1: caf03508ef8b50a85b3b11e30bd8b4f0961ca4f1 MD5sum: 692265d092b65649949d5d6bb129924d Description: AppArmor Profile for Derivative Linux Distributions Displaces /etc/apparmor.d/abstractions/base with a version, that includes additions required for Derivative Linux Distributions. . Does not depend on AppArmor, so this package can be installed by default on any anonymity distribution by default, without requiring to also have AppArmor installed. Just for the case, AppArmor gets installed later by the user. Package: apparmor-profile-hexchat Version: 3:5.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 60 Depends: apparmor Replaces: apparmor-profile-xchat Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-hexchat/apparmor-profile-hexchat_5.5-1_all.deb Size: 23912 SHA256: cde89ba8fb7e6965feeb7d72c9dedc6f6c602268122981343fb2c906b9702f0e SHA1: c3e19c274b3dea735cd3b598e11db50fc597cb59 MD5sum: b0b3af0563aa9d6afbf41fabb2ecaf69 Description: AppArmor profile for HexChat IRC An AppArmor profile to confine HexChat IRC. This profile is developed by the Whonix team. HexChat IRC is developed by xchat.org / hexchat.github.io. . For better security. Package: apparmor-profile-thunderbird Version: 3:6.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 65 Depends: apparmor Replaces: apparmor-profile-icedove Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-thunderbird/apparmor-profile-thunderbird_6.0-1_all.deb Size: 26952 SHA256: 5262f3782ed6350caf55bbde3ae3f9a1e6eca114a3b7725b7c01b31b212318c1 SHA1: d994c97bb915666c4fbc6c815d1e9bb13ae35bca MD5sum: 86aef72c2bb461797801c33c2a45d58d Description: AppArmor profile for Thunderbird for Debian An AppArmor profile to confine Thunderbird. . This profile is just an extension of the upstream AppArmor Debian profile. The upstream AppArmor upstream profile is the foundation. . Primarily this AppArmor profile makes Debian's AppArmor profile for Thunderbird compatible with Qubes Debian based VMs. . This profile is developed by the Kicksecure team. Thunderbird is developed by mozilla.org. Package: apparmor-profile-torbrowser Version: 3:9.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 74 Depends: apparmor Homepage: https://www.kicksecure.com/wiki/AppArmor Priority: optional Section: misc Filename: pool/main/a/apparmor-profile-torbrowser/apparmor-profile-torbrowser_9.6-1_all.deb Size: 34764 SHA256: 4df74bccdd6cb3a6df8e4e27153fc054709139fb916dabbe62ac4db99d2e2c83 SHA1: 5b2111a250fadc5d379387ad08ecbc71de1c5f0e MD5sum: 4b7468ab4a0ecdb7c1d8b1e186c18698 Description: AppArmor profile for The Tor Browser Bundle (TBB) An AppArmor profile to confine The Tor Browser Bundle (TBB). This profile is developed by the Whonix team. TBB is developed by The Tor Project. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: apparmor-profiles-kicksecure Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: apparmor-profile-hexchat, apparmor-profile-thunderbird, apparmor-profile-torbrowser, apparmor-profiles, apparmor-profiles-extra Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/apparmor-profiles-kicksecure_33.2-1_all.deb Size: 80356 SHA256: 7d102453ada478c2ac98ebdf7637d6c52a48e9f4d09e66d78d198a49014b44f7 SHA1: aa9ab82010bcb88c395283686efaa356f2824ba6 MD5sum: f08c81c3b7ffc00dae917fee9b553fba Description: AppArmor profiles developed by the Kicksecure Team A metapackage, which installs apparmor profiles packages from Debian: . * apparmor-profile * apparmor-profiles-extra . as well as installs apparmor profiles developed by the Kicksecure team: . * apparmor-profile-thunderbird * apparmor-profile-torbrowser * apparmor-profile-hexchat . Increases security. Package: binaries-freedom Version: 0:3.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 31 Depends: fuse Homepage: https://github.com/Kicksecure/binaries-freedom Priority: optional Section: misc Filename: pool/main/b/binaries-freedom/binaries-freedom_3.3-1_all.deb Size: 11256 SHA256: 4f15f98eeded72e6f3fb11e8ac35ff178daf199e9d1e40c2e345d743d2cdffb8 SHA1: 44fd15e99f54a64915e3077725e22d2211d6518d MD5sum: 1bfff5aa44643bc8e79203beedadfce8 Description: Freedom Software Binaries This is an empty package at this time. . https://forums.whonix.org/t/policy-for-inclusion-of-compiled-software/6635 Package: bindp Version: 3:3.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 27 Homepage: https://github.com/Kicksecure/bindp Priority: optional Section: misc Filename: pool/main/b/bindp/bindp_3.9-1_all.deb Size: 13456 SHA256: 7a9399f12a1c4ec084fc6e5298e504ced332a44e95884c36613b089926caa5a1 SHA1: 797544f19cf3101145f5dcce882c547713b94682 MD5sum: 25295346d7a60555f643df8303d2fa9d Description: Binding specific IP and Port for Linux Running Application This package is probably most useful for Anonymity Distributions. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: bootclockrandomization Version: 3:7.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 88 Depends: msgcollector Homepage: https://www.kicksecure.com/wiki/Boot_Clock_Randomization Priority: optional Section: misc Filename: pool/main/b/bootclockrandomization/bootclockrandomization_7.2-1_all.deb Size: 31016 SHA256: 92b0a260810a0a24af491915c7dd150cdc40a2db0365b3da779fdd2fc8c57147 SHA1: dd26f267700b9e9855c060831fccb8e6f957c21f MD5sum: c34b2f31226cb446eaa91d7180af2077 Description: Randomizes clock when systems boots Randomizes clock at boot time. Moves clock a few seconds and nanoseconds to past or future. Useful in context of anonymity/privacy/Tor. . This is useful to enforce the design goal, that the host clock and Gateway/Workstation clock should always slightly differ (even before secure timesync succeeded!) to prevent time based fingerprinting / linkablity issues. . Runs before Tor / sdwdate (if installed). . See also: https://www.whonix.org/wiki/Dev/TimeSync Package: browser-choice Version: 3:1.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 255 Depends: python3, tb-updater, tb-starter Homepage: https://www.kicksecure.com/wiki/browser-choice Priority: optional Section: admin Filename: pool/main/b/browser-choice/browser-choice_1.1-1_all.deb Size: 56452 SHA256: 059750b631cada4fdb6638d06f33b47fd47715c129feb3522d6ef927221ea32f SHA1: 87ea0152f82bfcdf51e967e612be0277c29d3110 MD5sum: 2ce33f137b3c9c105c6cb0803ac4029e Description: browser selection installer dialog A graphical interface that allows users to select and manage browsers. . Features a plugin-based design and multiple install types. Package: calamares-settings-debian Version: 13.1.6-1 Architecture: all Maintainer: Jonathan Carter Installed-Size: 225 Depends: calamares, rsync, cryptsetup, libglib2.0-bin, keyutils, pkexec, qml-module-qtquick-window2, qml-module-qtquick2, dconf-gsettings-backend | gsettings-backend Provides: calamares-settings Homepage: https://salsa.debian.org/live-team/calamares-settings-debian Priority: optional Section: utils Filename: pool/main/c/calamares-settings-debian/calamares-settings-debian_13.1.6-1_all.deb Size: 129340 SHA256: 3ff040056e9c9189e270aa23a1c8fc55d6d56939e57220b843cf74118798d1e8 SHA1: 199393af56404a62a88d7b4b0204f28dfac29021 MD5sum: 0ac6f698ddac7310c32d16c632df537b Description: Debian theme and settings for the Calamares Installer Calamares is a generic installer framework for Linux distributions. By default, it contains a set of boilerplate wording and images. This package provides the latest Debian artwork as well as scripts that supports EFI installations. . It also serves as an example for how derivatives can create their own calamares-settings packages. Package: damngpl Version: 3:4.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 32 Depends: perl Homepage: http://www.finnie.org/software/damngpl/damngpl Priority: optional Section: misc Filename: pool/main/d/damngpl/damngpl_4.5-1_all.deb Size: 13684 SHA256: ce8db4617d0ce2ec6f659de1f6ef1cff8818b3da2fb43b8b92a2f5d88ab0cec0 SHA1: 23143d1b6d9d2b16d61cec3dc8fd8776087e3123 MD5sum: cc0d15c5cb8b7c19744e57f26342007b Description: Extract source package info from Debian status files damngpl will parse a Debian-style /var/lib/dpkg/status file and extract source package information about installed packages. This information can be used in several ways, usually to download source packages. . Multiple input files can be specified on the command line, or piped into standard input if no files are specified. Results are returned to standard output. . The name damngpl was chosen as a tongue-in-cheek description of its purpose (downloading Debian sources for the Finnix project to remain GPL compliant). Please do not send hate mail to the author, thinking he is anti-GPL. He's not. . See also: http://blog.finnix.org/2011/08/21/finnix-and-gpl-compliance/ Package: debug-misc Version: 3:5.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Suggests: systemd-coredump, serial-console-enable Replaces: grub-output-verbose Homepage: https://github.com/Kicksecure/debug-misc Priority: optional Section: misc Filename: pool/main/d/debug-misc/debug-misc_5.1-1_all.deb Size: 27348 SHA256: a630e8afddfbb306bfaa4447228f92b2334639d96cad2763872a2efa3d9ca135 SHA1: 9ea76ed08bbe14bb2ff3f35a21d8f1c847227d3d MD5sum: 5bd51efe16fd0d6ed2bd14f65bd437bb Description: Enables miscellaneous debug settings Ships a `/etc/default/grub.d/45_debug-misc.cfg` configuration file. This removes `quiet`, `loglevel=0`, and `rhgb` from the `GRUB_CMDLINE_LINUX_DEFAULT` variable. It also removes `debugfs=off`, `efi_pstore.pstore_disable=1`, and `erst_disable` from the `GRUB_CMDLINE_LINUX` variable. Finally, it adds `debug=vc` to the `GRUB_CMDLINE_LINUX` variable to enable verbose output during the initial ramdisk boot phase. . Undo debugging related `sysctl` settings by package `security-misc`. . Enables persistent systemd journal log. . Disables `/usr/lib/systemd/coredump.conf.d/30_security-misc.conf` by package `security-misc` using `debian/debug-misc.links` by creating a symlink from `/etc/systemd/coredump.conf.d/30_security-misc.conf` to `/dev/null`. . Disables `/usr/lib/systemd/pstore.conf.d/30_security-misc.conf` by package `security-misc` using `debian/debug-misc.links` by creating a symlink from `/etc/systemd/pstore.conf.d/30_security-misc.conf` to `/dev/null`. . Disables `panic-on-oops`, `remove-system.map` by package `security-misc`. . `config-package-dev` `hide` `/etc/sysctl.d/30_silent-kernel-printk.conf` which kernel.printk to default as if security-misc would not have lowered verbosity. . Configure systemd `getty` service to not clear `tty`. `/lib/systemd/system/getty@tty.service.d/30_debug-misc.conf` . Coredumps are enabled. `/etc/security/limits.d/40_debug-misc.conf` . Coredumps may contain important information such as encryption keys or passwords. Package `security-misc` disables coredumps. Package `debug-misc` re-enables coredumps. . Contains a helper tool to cause a segfault for testing purposes. `segfault-build` creates `segfault-run`. Running `segfault-run` results in `segfault-run` terminating with a segfault. This is useful to test if coredump files are being generated when an application crashes. `/usr/sbin/segfault-build` `/usr/share/debug-misc/segfault.c` . For better usability, to ease debugging in case of issues. . For better security, this package should only be installed on specific machines that require debugging. Unfortunately, security and debugging are conflicting optimization goals. Package: desktop-config-dist Version: 3:13.1-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 270 Depends: python3, dconf-gsettings-backend | gsettings-backend Homepage: https://github.com/Kicksecure/desktop-config-dist Priority: optional Section: misc Filename: pool/main/d/desktop-config-dist/desktop-config-dist_13.1-1_all.deb Size: 68560 SHA256: 9d106d53ec1afd1fb535edc7a7bd7eb2ba4c2215d651f35b9919a66f046d7c97 SHA1: ea6738e951f743c4d729bde30a97aa42326df5f4 MD5sum: 99ce5340a5a3ccf91764461ebc0b4b05 Description: Configuration for Derivative Desktop Sets desktop and display setting, wallpaper and desktop icons. Sets icon theme and style. Settings for the default panel aka task bar, like panel position/color/size and panel plugins/shortcuts. . Autologin for user 'user' setting in lightdm. . Live check systray indicator which indicates the status of grub-live, whether the system was booted into persistent or live mode. See also: https://www.kicksecure.com/wiki/grub-live . Adds start menu entries for web browser, terminal emulator, file manager. . Sets Whisker Menu for better usability. . Disable maximize windows when moving to top for better privacy. . Disables thumbnails for better security. . Disables save on exit for better privacy. . Ships `zsh` derivative configuration settings folder `/etc/zsh`. But does not configure `zsh` as default shell. (That is up to package `dist-base-files`.) Package: desktop-config-dist-dependencies Source: desktop-config-dist Version: 3:13.1-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 68 Depends: gnome-colors-common, adwaita-icon-theme Homepage: https://github.com/Kicksecure/desktop-config-dist Priority: optional Section: misc Filename: pool/main/d/desktop-config-dist/desktop-config-dist-dependencies_13.1-1_all.deb Size: 39264 SHA256: 5f4861eae62992ff68a651d498583be7b37ff8140cccceee82c3aa580aa4b0d6 SHA1: e60d0c1f649d39852a7b656e6af9d7cd26c50392 MD5sum: 08eafc350c60542c630428afb4010491 Description: Dependencies of desktop-config-dist A metapackage with dependencies for package desktop-config-dist. . Only useful for Non-Qubes. Not useful in Qubes. Package: developer-meta-files Version: 3:44.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 391 Depends: python3, bc, jq Homepage: https://github.com/Kicksecure/developer-meta-files Priority: optional Section: misc Filename: pool/main/d/developer-meta-files/developer-meta-files_44.8-1_all.deb Size: 143196 SHA256: 7996d5c71e783d3015745f15794149bc44ea3ac15c91b8f0d402ab53616ffb66 SHA1: 08800d346e7059b85ee38762239ee2cb34eb07f1 MD5sum: 9e231b28b9652e717aaf5eda46490366 Description: Linux Distributions Maintenance Helper Scripts Todo . Description Package: dist-baremetal-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: nvme-cli, tirdad Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-baremetal-cli_33.2-1_all.deb Size: 80280 SHA256: acf15cc6bf0e879a9fc7abb0045e83bab919fe02334c768ae4e44ad75cb8cbd4 SHA1: d4c22feab4168c7bbf6cf8ecef3d1b54c2ed8d48 MD5sum: b7dabf4629b80bb6bcc85357cb958e9e Description: All systems, physical hardware, command-line packages For all hardened systems. . For physical hardware. . Provides packages for basic command-line-only installations. Package: dist-base-files Version: 3:14.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 685 Pre-Depends: zsh Depends: sudo, dpkg-dev, helper-scripts, adduser, moreutils, xz-utils, zsh-syntax-highlighting, zsh-autosuggestions, systemd-repart Conflicts: anon-base-files, diverts-etc++grub.d++10+-+linux Replaces: anon-base-files Provides: anon-base-files, diverts-etc++grub.d++10+-+linux Homepage: https://github.com/Kicksecure/dist-base-files Priority: optional Section: misc Filename: pool/main/d/dist-base-files/dist-base-files_14.5-1_all.deb Size: 191804 SHA256: 7114c71833d0ef458fbac316ffa62b222266231fec3f27905485259c176a6872 SHA1: 4a79b608a73e19aa659e5f7491495f0d8a058d3b MD5sum: cbbad43c6a6bb35cd9cf3155c2145b3b Description: base files for distributions Grub config for more organized boot menu. "Normal" boot options are on top. "Advanced" boot options (for older kernel versions) have been moved to the bottom. . Creates user `user` with empty password (passwordless) (not in Qubes). That is if user `user` is not existing yet. And if it does create user `user` it also locks the root account. Therefore root account locking effectively only happens in new builds not having user `user` already created. . Creates system groups: * console * ssh . Ships a systemd unit file dist-skel-first-boot.service which runs `/usr/libexec/helper-scripts/first-boot-skel` (part of helper-scripts) package. . Simplifies sudo default lecture to only showing the default password once. . Creates version file `/var/lib/dist-base-files/build_version`. . Default shell: Sets default shell for user `user` to `zsh`. (Unless file `/etc/no-shell-change` exists.) `debian/dist-base-files.postinst` . Provides common files for derivative GRUB themes. . This package gets installed by default in both, Kicksecure and Whonix. Package: dist-general-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: apparmor-profile-dist, apt-transport-tor, apt-utils, bootclockrandomization, ca-certificates, dialog, dist-base-files, gawk, init, initializer-dist, locales, menu, repository-dist, sdwdate, security-misc, setup-dist, sudo, timesanitycheck, usbguard, usrmerge, apparmor-profiles-kicksecure | dummy-dependency-apparmor-profiles-kicksecure, apparmor-utils, bash-completion, boot-info-script, btrfs-progs, bzip2, curl, debian-keyring, dbus-user-session, distro-info-data, bind9-dnsutils | dnsutils, e2fsprogs, eject, file, haveged, hunspell-en-us, iotop, iproute2, iputils-ping, jitterentropy-rngd, less, libblockdev-crypto3, libpam-tmpdir, lsof, man-db, most, nano, net-tools, openvpn, 7zip, pciutils, pcmciautils, procps, secure-delete, sensible-utils, strace, sysfsutils, systemcheck, torsocks, traceroute, udisks2, unzip, usability-misc, usbutils, vim, xz-utils, zip, codecrypt, diceware, dirmngr, equivs, extrepo, fuse, gpg, gpg-agent, makepasswd, pwgen, htop, pv, cryptsetup, dmsetup, udev, anon-apt-sources-list, tor Breaks: kicksecure-default-applications-cli, kicksecure-dependencies-cli, kicksecure-dependencies-system, kicksecure-recommended-cli Replaces: kicksecure-default-applications-cli, kicksecure-dependencies-cli, kicksecure-dependencies-system, kicksecure-recommended-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-general-cli_33.2-1_all.deb Size: 80864 SHA256: 701e8be96262500f56c3e51c2baee5512edaa9097d2323d8a35cf8205af37136 SHA1: 086df446c0010ba7fc3e887903c6ef741705e928 MD5sum: ebf2f826f50dc3e3d20692b08f4daafe Description: All systems, all hardware, command-line packages For all hardened systems. . For all hardware platforms. . Provides packages for basic command-line-only installations. Package: dist-general-gui-all Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: desktop-config-dist, gtk2-engines-pixbuf, libgl1-mesa-dri, mesa-vulkan-drivers, upower, libfuse2t64, mate-polkit, xdg-desktop-portal, msgcollector-gui, repository-dist-wizard, sdwdate-gui, setup-wizard-dist, mesa-utils, open-link-confirmation, accountsservice, icon-pack-dist, libasound2t64 Breaks: kicksecure-desktop-applications-recommended, kicksecure-desktop-environment-essential-gui Replaces: kicksecure-desktop-applications-recommended, kicksecure-desktop-environment-essential-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-general-gui-all_33.2-1_all.deb Size: 80492 SHA256: 7fdb8b603161f4161960ece18e19f8bc1da7be4972fbf2108385643e0b80daaa SHA1: f186644383f9840831c4a2ec39ff971fb18dffa8 MD5sum: 2994e4126717003265a5bc51d36e32e2 Description: All systems, all hardware, GUI packages For all hardened systems. . For all hardware platforms. . Provides packages for all graphical desktop installations. Package: dist-general-gui-lxqt Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: dummy-dependency-sway, dummy-dependency-lxqt-policykit, featherpad, gnome-keyring, lxqt-about, lxqt-admin, desktop-file-utils, lxqt-themes, lxqt-system-theme, lxqt-config, lxqt-notificationd, lxqt-globalkeys, lxqt-qtplugin, pcmanfm-qt, qterminal, qtxdg-tools, lxqt-openssh-askpass, lxqt-sudo, papirus-icon-theme, qps, qt6-svg-plugins, qt6-translations-l10n, qt6-wayland, xdg-desktop-portal-gtk, xdg-desktop-portal-lxqt, gvfs, pkexec, polkitd, sysmaint-panel, discover, hwinfo, laptop-detect, lm-sensors, lshw, psensor, gparted, smart-notifier, lxqt-archiver Breaks: kicksecure-desktop-applications-lxqt, kicksecure-desktop-environment-essential-lxqt, kicksecure-shared-host-lxqt Replaces: kicksecure-desktop-applications-lxqt, kicksecure-desktop-environment-essential-lxqt, kicksecure-shared-host-lxqt Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-general-gui-lxqt_33.2-1_all.deb Size: 80612 SHA256: b176a803da46852d1807738bb1068a65ee57fe105815ab7c17791d5678680ffc SHA1: d7dd22876374300d19e5c843e5971a6331fa0143 MD5sum: 4163eecd10dbdb4b4fb2d23d3863cd4f Description: All systems, all hardware, LXQt GUI packages For all hardened systems. . For all hardware platforms. . Provides packages for LXQt graphical desktop installations. Package: dist-nonqubes-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: dracut, systemd-cryptsetup, acpi-support, console-common, console-setup, grub-live-dracut | grub-live-boot | boot-live, kbd, keyboard-configuration, swap-file-creator, tirdad, smartmontools Breaks: non-qubes-enhancements-cli Replaces: non-qubes-enhancements-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-nonqubes-cli_33.2-1_all.deb Size: 80420 SHA256: ee802117d0dcbe8236bd61f70ed028e4c73fddaca733cc6ba7cc43946a4433c8 SHA1: 90de515407d2368a4b53227164a8ac2571a48d37 MD5sum: f0669c36a581ba721848bd6a97240c2e Description: All systems, not Qubes VMs, command-line packages For all hardened systems. . For machines other than Qubes virtual machines. . Provides packages for basic command-line-only installations. Package: dist-nonqubes-gui-all Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: rads, desktop-config-dist-dependencies, labwc, waybar, gsmartcontrol Breaks: non-qubes-audio, non-qubes-enhancements-gui Replaces: non-qubes-audio, non-qubes-enhancements-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-nonqubes-gui-all_33.2-1_all.deb Size: 80376 SHA256: e567ed7acb4314c5f72ea6a40b937c3f28bd85992ee4e3b0496097e59d49d4cf SHA1: 5c2c61f9ca194102b3267312e630c6d17438064c MD5sum: 1a1db2907095922962e05d4230a0b06a Description: All systems, not Qubes VMs, GUI packages For all hardened systems. . For machines other than Qubes virtual machines. . Provides packages for all graphical desktop installations. Package: dist-nonqubes-gui-lxqt Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: swayidle, swaylock, greetd, wlgreet, lxqt-powermanagement, lxqt-panel, lxqt-runner, lxqt-session, lxqt-wayland-session, swaybg, wdisplays, flameshot, xdg-desktop-portal-wlr Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-nonqubes-gui-lxqt_33.2-1_all.deb Size: 80400 SHA256: 9267bd3a22431693ed41f504ed267a83541fbc8afdf7df9a704b89a06571b6c3 SHA1: 227271d5dfa2a23302d571946465f3a3d79e6b44 MD5sum: 4d6b1ec24cf967b2c696f3e0bb9f25f7 Description: All systems, not Qubes VMs, LXQt GUI packages For all hardened systems. . For machines other than Qubes virtual machines. . Provides packages for LXQt graphical desktop installations. Package: dist-qubes-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: qubes-core-agent-networking, qubes-input-proxy-sender, qubes-kernel-vm-support, qubes-usb-proxy, qubesdb-vm, vm-config-dist Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-qubes-cli_33.2-1_all.deb Size: 80340 SHA256: 82a6fbe7349364eced509ee0498f66750122c4547312f3fa10e09cd32f10c037 SHA1: 52609a238c594c6376ea072eb3ee3c62830ddcf9 MD5sum: 595a2dbe60718a5c9e7bd83fd02b8457 Description: All systems, Qubes VMs, command-line packages For all hardened systems. . For Qubes virtual machines. . Provides packages for basic command-line-only installations. Package: dist-qubes-gui-lxqt Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: qubes-core-agent-thunar Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-qubes-gui-lxqt_33.2-1_all.deb Size: 80300 SHA256: 5a135993a3d1242d23583143452532c848a06f10d5a17f146f86c3ebd2262acd SHA1: 44359014a9a4aabcd348e8341703520d4b48993f MD5sum: 152bd5749f5972ea8fec65be649a4b2f Description: All systems, Qubes VMs, LXQt GUI packages For all hardened systems. . For Qubes virtual machines. . Provides packages for LXQt graphical desktop installations. Package: dist-vm-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: vm-config-dist Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dist-vm-cli_33.2-1_all.deb Size: 80272 SHA256: ff18037b1e8cc0013451a26844f09a0d185bbd6686efe859081724a273ef1ba5 SHA1: 462f9ed144afe07317cf57a91660cf26d69fa416 MD5sum: 5a24d62b7f3e9a70bb41338484713664 Description: All systems, VMs, command-line packages For all hardened systems. . For non-Qubes virtual machines. . Provides packages for basic command-line-only installations. Package: dummy-dependency Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Provides: browser-choice, firefox-esr, qubes-core-agent-passwordless-root, tb-default-browser, tb-starter, tb-updater Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency_33.2-1_all.deb Size: 80380 SHA256: 7410a34b4be7fbe34b95a6faf3b52cd0b7ec3ebfd3953721faea85b976858150 SHA1: 64364322793186566484405dcd89f51f007b7858 MD5sum: 1c2bfb6ca1667c1772cde6f730b33792 Description: dummy package to satisfy architecture specific dependencies A metapackage, which satisfies the dependency on: . - tb-updater - tb-starter - tb-default-browser - qubes-core-agent-passwordless-root - firefox-esr . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-apparmor-profiles-kicksecure Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Provides: apparmor-profiles-kicksecure Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-apparmor-profiles-kicksecure_33.2-1_all.deb Size: 80304 SHA256: 2221ac39be8cc2b5499011677bbdd5e8f8195302d90be1a2c1e3a000197d615f SHA1: e151dcf7b3b8ac7b54465bf5da3282c251b88315 MD5sum: 42343730344a4ea038c8de4cf31b05a1 Description: dummy package apparmor-profiles-kicksecure A metapackage, which satisfies the dependency on apparmor-profiles-kicksecure. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-bindp Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Provides: bindp Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-bindp_33.2-1_all.deb Size: 80280 SHA256: 9b83d22c4b5a3f8b43886b2db3c3bccd08f9a6060beb1601b30840d1245a2315 SHA1: ed367cbc92a0f48c012c25d761835c6fd1b6ce09 MD5sum: 738a446b77b36c6441ecb609b1e3c3fa Description: dummy package to satisfy architecture specific dependency bindp A metapackage, which satisfies the dependency on bindp. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-electrum Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Replaces: dummy-dependency-hardened-electrum Provides: dummy-dependency-hardened-electrum, electrum Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-electrum_33.2-1_all.deb Size: 80308 SHA256: 47d6b5649ebe6259cd743915c0b915324c40982cf16d9c9fe5c2633a9d133206 SHA1: f29a6822cb44ca4b94f39af2f06937a3f2b385dc MD5sum: 42f9224e109bd81f2748ba54b71ba728 Description: dummy package to satisfy architecture specific dependency electrum A metapackage, which satisfies the dependency on electrum. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-hardened-malloc Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Provides: hardened-malloc Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-hardened-malloc_33.2-1_all.deb Size: 80304 SHA256: 41ddb9503476159246c9fc28436d4da79fda4fe8bb0120792414eae74fee1dc6 SHA1: 45aa644bddd03db086ada9e9657a9c2a73fbfc73 MD5sum: ca72ed28d2768cbcacd1abd5dc6f3060 Description: dummy package to satisfy architecture specific dependency hardened-malloc A metapackage, which satisfies the dependency on: . hardened-malloc . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-kloak Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Provides: kloak Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-kloak_33.2-1_all.deb Size: 80284 SHA256: 7d16133559d9df7ed49ceeedb8df9faace64aac82c405237c53c34233ef1c203 SHA1: dda867f5746f7fb2f7d229690872d46dd69815e8 MD5sum: 5cf48949571cbafd1c267da0c7afe1d4 Description: dummy package to satisfy architecture specific dependency kloak A metapackage, which satisfies the dependency on kloak. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-lxqt-policykit Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Conflicts: lxqt-policykit Provides: lxqt-policykit Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-lxqt-policykit_33.2-1_all.deb Size: 80344 SHA256: 8a9d3fe44b0fac4c8c3609a4b39a6a8489dd4f70bfef95448fcb35748ef56942 SHA1: 47166e0a0f8ed3c19c27fe9759a251c8790c27a5 MD5sum: aaee5562be40a0b740081b1bbb8226dc Description: dummy package lxqt-policykit A metapackage, which satisfies the dependency on lxqt-policykit. Because lxqt-policykit is buggy. Bugs out on pam-info stdout/stderr output. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-sway Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Provides: sway Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-sway_33.2-1_all.deb Size: 80292 SHA256: dd0f9305653116cd0bead640453aae6acb5d7bc97659562e1407cc8f38466db9 SHA1: aa1dd449fbb6f3b617af30536ada052931f1c2ff MD5sum: 4d72a566cb8f258b87fc41e82bdcc10b Description: dummy package sway A metapackage, which satisfies the dependency on sway. Used to install wlgreet without sway. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-tirdad Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Provides: tirdad Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-tirdad_33.2-1_all.deb Size: 80288 SHA256: ca901e201d5a008e841004d72990cf4461ad9719537e04132843db0606a3bea3 SHA1: ffeaa06fb8429384c56699f4687d344593fc2827 MD5sum: 348dfb0c0823824598f5842e575b8cae Description: dummy package to satisfy architecture specific dependency tirdad A metapackage, which satisfies the dependency on tirdad. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: dummy-dependency-xorg-vm Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Provides: xserver-xorg-video-vmware Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/dummy-dependency-xorg-vm_33.2-1_all.deb Size: 80300 SHA256: 5218cd993325d45779a63f67e99be01ee7a1fd993de25df564bab090a3a8ad8f SHA1: fa0bc534ad50fe926514875a2524bc1535731073 MD5sum: 4694c3d328152d9dc98270b73ba0a082 Description: dummy dependency xserver-xorg-video-vmware A metapackage, which satisfies the dependency on xserver-xorg-video-vmware. . This package cannot provide a real implementation of that package. It is only a dummy to satisfy the dependency. Package: genmkfile Version: 3:16.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 161 Depends: make, dpkg-dev, devscripts, moreutils, safe-rm, strip-nondeterminism, sudo, perl, rsync, python3 Homepage: https://github.com/Kicksecure/genmkfile Priority: optional Section: misc Filename: pool/main/g/genmkfile/genmkfile_16.7-1_all.deb Size: 59724 SHA256: 66687abf522fcc7bbef6d956aabd049d8971ccc6140f774ec0826fcf0be936a1 SHA1: 5057926a5c15d62769dfd50dc066d93585210c16 MD5sum: 98bc07b9a53c4875a3ed8b72682085a3 Description: Generic Makefile Makes packaging simpler. No more need to manually maintain 'make install' targets or distribution specific install files such as debian/pkg-name.install. . Files in etc/... in root source folder will be installed to /etc/..., files in usr/... will be installed to /usr/... and so forth. This should make renaming, moving files around, packaging, etc. very simple. Packaging of most packages can look very similar. . Provides common make targets such as 'make install', 'make dist', 'make installsim', 'make installcheck', 'make uninstall', 'make uninstallcheck', 'make distclean'. . Very extensible through file ./make-helper-overrides.bsh or folder ./make-helper-overrides.d. By using overrides, any make target can be easily extended using pre or post hooks or replaced. Override files which are executable will be used. Override files which are not executable will be skipped. . Contains a minimal Makefile while the heavy lifting is done by a bash script make-helper.bsh. . Building for multiple platforms possible, example: export make_cross_build_platform_list="i386 amd64" . Can call with lintian (static analysis tool for Debian packages). By default it will be using lintian if installed while failing open (non-zero exit code). lintian can be disabled. export make_use_lintian=false Or can be configured to fail closed (non-zero exit code). export make_use_lintian=true . Can build packages without chroot using debuild (default) or inside chroot using cowbuilder. To enable cowbuilder, use: export make_use_cowbuilder=true . Supports signing packages using debsign. (sign a Debian .changes and .dsc file pair using GPG) export make_use_debsign=true Package: gpg-bash-lib Version: 3:5.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 647 Homepage: https://github.com/Kicksecure/gpg-bash-lib Priority: optional Section: libs Filename: pool/main/g/gpg-bash-lib/gpg-bash-lib_5.0-1_all.deb Size: 490628 SHA256: 6b2a2684f808c3522e79434bcb377da737c61c53f63401a1066aca70c9b781e7 SHA1: 5d2511eed24a84be4f5f6d52de645c3a1cf664f1 MD5sum: 30a4926af8d54df910323f1e39ca0caf Description: gpg bash library Abstracts file verification into common functions. Allows detecting of stale files, i.e. detection downgrade or indefinite freeze attacks by implementing a valid-until like mechanism. . Internally parses gpg's --status-file output. . For better security. Package: grub-live Version: 3:9.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 109 Homepage: https://github.com/Kicksecure/grub-live Priority: optional Section: misc Filename: pool/main/g/grub-live/grub-live_9.9-1_all.deb Size: 35860 SHA256: 84120091466fee117b03b8cd8ae6b8fdf5433fe65df966a3cfd1e39eca91219c SHA1: 49b3bc8bb54e9d22939389f87684d12c8eb5232d MD5sum: 4e54eec08b91ba57b6f5d33660cbc7b6 Description: grub live boot menu entry Base grub-live package. You probably do not want to install this directly, install grub-live-dracut instead. . Allows booting the system in live mode. Meaning, no persistent modifications will be written to the disk. All changes stay in RAM. . Adds a grub live boot menu entry. . Existing grub boot entries stay unmodified. . No claims are made with regard to anti forensics. Package: grub-live-dracut Source: grub-live Version: 3:9.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 62 Depends: grub-live, dracut Provides: boot-live, grub-live-boot Homepage: https://github.com/Kicksecure/grub-live Priority: optional Section: misc Filename: pool/main/g/grub-live/grub-live-dracut_9.9-1_all.deb Size: 30212 SHA256: 6332543ead50b828d603d3f8a73c9706c4d5a8b265ad6523916c7f0297c6cd41 SHA1: c467ea8883c9f3db365023819bb2dced1ec40ad5 MD5sum: 6b8f6e6c8803a9df2a68e05a6919c696 Description: grub live dracut dependencies Dracut version metapackage for grub-live. . See also the package grub-live. Package: hardened-kernel Version: 3:5.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 474 Depends: build-essential, libssl-dev, libncurses-dev, fakeroot, libelf-dev, bison, flex, gcc-12-plugin-dev, curl, bc, kmod, cpio Homepage: https://www.kicksecure.com/wiki/Hardened-kernel Priority: optional Section: misc Filename: pool/main/h/hardened-kernel/hardened-kernel_5.1-1_all.deb Size: 158144 SHA256: fadaa1d9155e8873fe483ea82cad25e5965d71f92f2894e94ad92c1bc55a7ce2 SHA1: ce0b41ba1325056a08b6079daab5da1c103f99f7 MD5sum: 2db5760827514a696b6e53067583342e Description: Hardened Kernel for Host and VMs This is a hardened kernel configuration for Whonix / Kicksecure. hardened-vm-kernel is designed specifically for virtual machines and hardened-host-kernel is designed for hosts. . Both configs try to have as many hardening options enabled as possible and have little attack surface. hardened-vm-kernel only has support for VMs and all other hardware options are disabled to reduce attack surface and compile time. . During installation of hardened-vm-kernel, it compiles the kernel on your own machine and does not use a pre-compiled kernel. This ensures the kernel symbols in the compiled image are completely unique which makes it far harder for kernel exploits. This is possible due to hardened-vm-kernel having only VM config options enabled which drastically reduces compile time. . During installation of hardened-host-kernel, the kernel is not compiled on your machine and it uses a pre-compiled kernel. This is because the host kernel needs most hardware options enabled to support most devices which makes compilation take a very long time. . The VM kernel is more secure than the host kernel due to having less attack surface and not being pre-compiled but if you want more security for the host, it is recommended to edit the hardened host config, enable only the hardware options you need and compile the kernel yourself. This makes the security of the host and VM kernel comparable. . Both configs were based on the default Debian config. . These kernels use the linux-hardened patch for further hardening. Custom hardening patches should be sent there. . This only supports LTS kernels as they have the least attack surface (stable kernels have more code and more bugs) and the best stability. . Build script /usr/share/hardened-vm-kernel/build does not run automatic yet. . Kernel does not get installed automatic yet. . See also development discussion: http://forums.whonix.org/t/kernel-recompilation-for-better-hardening Package: helper-scripts Version: 3:35.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 625 Depends: sudo, python3, python3-stem, python3-scapy, python3-yaml, bubblewrap, moreutils, equivs, safe-rm Breaks: usability-misc (<< 3:29.1-1) Replaces: anon-shared-helper-scripts, anon-ws-leaktest, curl-scripts, python-guimessages, python3-guimessages, usability-misc (<< 3:29.1-1) Homepage: https://github.com/Kicksecure/helper-scripts Priority: optional Section: misc Filename: pool/main/h/helper-scripts/helper-scripts_35.5-1_all.deb Size: 188580 SHA256: 6a13a6aa6ddab970860ff39c9b161f21040684773eed6265f7475e2339ef0a5a SHA1: a71b9f5802534f181ebda7535afa73c3cd67a979 MD5sum: c79722ce4409fbef3f9cbcc257d1c93d Description: Helper scripts useful for Linux Distributions Contains a script for curl progress bar in terminal. Includes another script to convert curl exit codes to curl status messages. Implemented in bash. Common code that can be used by other scripts. . Library that can be used by other (anonymity related) packages that want to programmatically get information about states of Tor. Common code, that is often required. Includes bash and Python helper scripts. . Leak Test for Anonymity Distribution Workstations Integrated leak test. Needs to be manually run. See: https://www.whonix.org/wiki/Dev/Leak_Tests . Translatable GUI Messages Generic modules guimessage.py and translations.py. Called with two parameters: .yaml file path and yaml section. Return translations according to distribution local language (Python 'locale'). . Provides the ld-system-preload-disable wrapper to disable /etc/ld.so.preload per application via bubblewrap. Useful if hardened_malloc is being globally preloaded and needs to be disabled for some applications. . Provides the dummy-dependency script for quickly creating and installing dummy packages for working around package dependencies. . Provides apt-get-noninteractive that is a simple wrapper around apt-get, that sets all required environment variables to make it interactive as well as to prevent systemd service starts and restarts during apt-get. Package: helper-scripts-tests Source: helper-scripts Version: 3:35.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 125 Depends: helper-scripts, git, python3-pytest, pylint, mypy, black, ncurses-term Homepage: https://github.com/Kicksecure/helper-scripts Priority: optional Section: misc Filename: pool/main/h/helper-scripts/helper-scripts-tests_35.5-1_all.deb Size: 92244 SHA256: be5e10a709b19f22dec1b973cc83e9ce9f326035d988bc3adc5e8f53a0eae232 SHA1: 7de0389769a81e165fb5f082625c619e8b972517 MD5sum: 5a8a552af9aafeeeb6a906c85847f7e5 Description: Helper scripts test packages This is a dependency package for tests. Package: icon-pack-dist Version: 3:5.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 2526 Conflicts: anon-icon-pack Replaces: anon-icon-pack Provides: anon-icon-pack Homepage: https://github.com/Kicksecure/icon-pack-dist Priority: optional Section: misc Filename: pool/main/i/icon-pack-dist/icon-pack-dist_5.0-1_all.deb Size: 1438624 SHA256: 9bba4461e990a5fdddc82e9e67f7d9890aa11f13f8a2a8d2899fe0681c6e5fea SHA1: fec545f7f533fb950337e1b3c9010b4b2dc0f9c0 MD5sum: 4f08c22521795c5d130f5d5058f8a58e Description: Icon Pack for Derivative Distributions Contains icons, that are used by other derivative distribution specific packages. Others are welcome to use these icons according to their Free licenses as well. Package: initializer-dist Version: 3:8.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 81 Depends: psmisc, debsums, damngpl, safe-rm Conflicts: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Replaces: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Provides: anon-shared-build-remember-sources, anon-shared-build-sanity-checks, whonix-initializer Homepage: https://www.kicksecure.com/wiki/Verifiable_Builds Priority: optional Section: misc Filename: pool/main/i/initializer-dist/initializer-dist_8.1-1_all.deb Size: 33960 SHA256: 7d2eac108002e53ea13a3c44b32b55a474cec1e81fa7d319b750c87089cd23ef SHA1: 7fda6e2dc7d4e5a088ff7e2d4658524e724f138c MD5sum: bc92a550591dc50caa5c51a8bc25729b Description: Initializes Linux distributions, Release Upgrades and Legacy Contains a chroot-scripts-post.d script, that cleans up temporary files, logs. . Deletes random seeds. Since these should not be included in a redistributed image. Also sometimes called 'golden' image. . - /var/lib/urandom/random-seed - /var/lib/systemd/random-seed - /var/lib/random-seed - See also: https://systemd.io/RANDOM_SEEDS.html Package: kicksecure-baremetal-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Breaks: kicksecure-cli-host, kicksecure-cli-host-packages-recommended Replaces: kicksecure-cli-host, kicksecure-cli-host-packages-recommended Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-baremetal-cli_33.2-1_all.deb Size: 80296 SHA256: 48de9fc62e446d274db4091d30cd721c18dbec3efe528205f6dc28c15b9ad815 SHA1: 2e73ae6baca6622fcc06d70a9805df0fc931c566 MD5sum: 9f9cecf299035141cc4ad336ac775d2c Description: Kicksecure systems, physical hardware, command-line packages For Kicksecure systems. . For physical hardware. . Provides packages for basic command-line-only installations. Package: kicksecure-baremetal-gui-lxqt Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: kicksecure-baremetal-cli, kicksecure-nonqubes-gui-lxqt, kicksecure-nonqubes-gui-all, kicksecure-nonqubes-cli, kicksecure-general-gui-lxqt, kicksecure-general-gui-all, kicksecure-general-cli, dist-baremetal-cli, dist-nonqubes-gui-lxqt, dist-nonqubes-gui-all, dist-nonqubes-cli, dist-general-gui-lxqt, dist-general-gui-all, dist-general-cli Breaks: kicksecure-lxqt-host Replaces: kicksecure-lxqt-host Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-baremetal-gui-lxqt_33.2-1_all.deb Size: 80356 SHA256: 89d6ad61a7cd12d0f70f6bc5daa4b0a984c1c0ca55b5bea39cb88f278046d5c9 SHA1: f9b2a22080507bd57f23e452af3c6d491f1e15f2 MD5sum: cca676993ee0d7e5f58a2f239fcfaeae Description: Kicksecure systems, physical hardware, LXQt GUI packages For Kicksecure systems. . For physical hardware. . Provides packages for LXQt graphical desktop installations. Package: kicksecure-baremetal-server Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: kicksecure-baremetal-cli, kicksecure-nonqubes-cli, kicksecure-general-cli, dist-baremetal-cli, dist-nonqubes-cli, dist-general-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-baremetal-server_33.2-1_all.deb Size: 80288 SHA256: f9a9cf9652a1f707997375a23b248b1c7524294f1aba35dfc3b0e6c878483b15 SHA1: cc3f16536b83f7015b0243de22f286f172528d17 MD5sum: ab93d9bfdb8a9852616dfb5295766993 Description: Kicksecure systems, physical hardware, server packages For Kicksecure systems. . For physical hardware. . Provides packages for server installations. Package: kicksecure-base-files Version: 3:9.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 2653 Depends: less, sudo Conflicts: diverts-etc++issue, diverts-etc++motd, diverts-etc++skel++.bashrc Provides: diverts-etc++issue, diverts-etc++motd, diverts-etc++skel++.bashrc Homepage: https://github.com/Kicksecure/kicksecure-base-files Priority: optional Section: misc Filename: pool/main/k/kicksecure-base-files/kicksecure-base-files_9.1-1_all.deb Size: 2569552 SHA256: 25dc064cc99d18c92e917480b1eda1eef7c5bf84333f4a01f895f4f4fbbccef4 SHA1: 475b38bf67f838a2ea0382b780256a4d9b9bd0a2 MD5sum: def3a1f5006f1e5a45cf6dd696462e4c Description: Kicksecure base system miscellaneous files This package contains several important miscellaneous files, such as /etc/issue, /etc/motd, /etc/dpkg/origins/kicksecure, /etc/skel/.bashrc, /usr/bin/kicksecure, and others. . Sets the KICKSECURE environment variable to 1 as well. Package: kicksecure-general-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: dosfstools, kicksecure-base-files, lvm2, ntfs-3g, obfs4proxy, gddrescue Breaks: kicksecure-cli Replaces: kicksecure-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-general-cli_33.2-1_all.deb Size: 80320 SHA256: 9bc10bed6029209545ecbf46bbf36029ad26b3178a8738f944962a663b68743a SHA1: 2651a8d5b92196aeea3ea325d227b8cd00c1dfb8 MD5sum: fbe469afc3bfe7f89db9ea977f263bcd Description: Kicksecure systems, all hardware, command-line packages For Kicksecure systems. . For all hardware platforms. . Provides packages for basic command-line-only installations. Package: kicksecure-general-gui-all Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: browser-choice | dummy-dependency, flatpak, keepassxc, kicksecure-welcome-page, lximage-qt, vlc, ddrescueview, pipewire-audio | pulseaudio, pipewire-pulse | pulseaudio, wireplumber | pulseaudio, rtkit | pulseaudio, catfish, electrum | dummy-dependency-electrum Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-general-gui-all_33.2-1_all.deb Size: 80396 SHA256: 28261c04bf1502ff4874e5e38604055c72f69a2782868a7788108442e304db8d SHA1: 5e25eb6e1375215cc8ebeac711d9081018a6b902 MD5sum: 111ea935996a5ce8e2d8a05907d6a753 Description: Kicksecure systems, all hardware, GUI packages For Kicksecure systems. . For all hardware platforms. . Provides packages for all graphical desktop installations. Package: kicksecure-general-gui-lxqt Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: network-manager-applet, nm-connection-editor Breaks: kicksecure-lxqt Replaces: kicksecure-lxqt Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-general-gui-lxqt_33.2-1_all.deb Size: 80324 SHA256: e1d18e90289e479ef00b7e9f9ccf0c9ecf6fb305698541b5e672a5f02eedc9d8 SHA1: 2e1b112ca124501d96c953a89ee0aff1ab7c4c7d MD5sum: 20090d73e7d60bf8cd3a0a8be4645312 Description: Kicksecure systems, all hardware, LXQt GUI packages For Kicksecure systems. . For all hardware platforms. . Provides packages for LXQt graphical desktop installations. Package: kicksecure-network-conf Version: 3:6.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 75 Depends: network-manager, iw, wpasupplicant, netbase, wireless-tools, wireless-regdb Homepage: https://github.com/Kicksecure/kicksecure-network-conf Priority: optional Section: misc Filename: pool/main/k/kicksecure-network-conf/kicksecure-network-conf_6.9-1_all.deb Size: 22864 SHA256: 655af1aaae912f74335aee678a10f8b122945b75a6d6fb33dc4785a8024a60f8 SHA1: 51384d44e39eb647f6d4e4d7c37c833fbd65abb6 MD5sum: 859df84ecaccfd70f9e928054a131392 Description: Network Configuration for Kicksecure CLI Disables systemd Predictable Network Interface Names. . Disables systemd-resolved during boot unless file /etc/dns-enable exists. . Disables systemd-resolved fallback DNS (which by default is set to Google). . Disables NetworkManager hostname management (useful in redistributed Kicksecure VMs). Package: kicksecure-network-conf-gui Source: kicksecure-network-conf Version: 3:6.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 49 Depends: network-manager-gnome Homepage: https://github.com/Kicksecure/kicksecure-network-conf Priority: optional Section: misc Filename: pool/main/k/kicksecure-network-conf/kicksecure-network-conf-gui_6.9-1_all.deb Size: 19488 SHA256: 2ed67ecfc4e6d8d74360d83e3e0c30f970a33a8a62c103143af034ed76223402 SHA1: 26149acd768ae533e766b34a5a9fe6d2d73b9f80 MD5sum: 608af953ef551749d55fa14c8b21b762 Description: Network Configuration for Kicksecure GUI A metapackage with dependencies recommended for a Kicksecure GUI for networking. . See also kicksecure-network-conf. Package: kicksecure-nonqubes-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: kicksecure-network-conf Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-nonqubes-cli_33.2-1_all.deb Size: 80288 SHA256: 65291092350fd5fa2e70788083023da3d833f4bb83064f36d8b8081a4c04fb5b SHA1: 4afad3050620311788fbeb7da7221a3bfb006006 MD5sum: e03d1db10fa8e9843fb3373dde023bf3 Description: Kicksecure systems, not Qubes VMs, command-line packages For Kicksecure systems. . For machines other than Qubes virtual machines. . Provides packages for basic command-line-only installations. Package: kicksecure-nonqubes-gui-all Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: kicksecure-network-conf-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-nonqubes-gui-all_33.2-1_all.deb Size: 80300 SHA256: 45067d25cca3e4917e13bbffe7aeb2846987a11fff6c5cf2ee8287f084fd581b SHA1: 54b31c4c5f7671d2a9d694388cf5b0a323388870 MD5sum: 211123b593ce18767cd0694e29194eaa Description: Kicksecure systems, not Qubes VMs, GUI packages For Kicksecure systems. . For machines other than Qubes virtual machines. . Provides packages for all graphical desktop installations. Package: kicksecure-nonqubes-gui-lxqt Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: pavucontrol-qt Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-nonqubes-gui-lxqt_33.2-1_all.deb Size: 80296 SHA256: 3355acc1cdec4e8b58c81830e48436032c57f941cd663b9d6dd7ee4e45378d8e SHA1: 2038d10308277d3ae555a0ecf603609404119cca MD5sum: 6f6bbd4149ac01b4edb2fb7ab9adef63 Description: Kicksecure systems, not Qubes VMs, LXQt GUI packages For Kicksecure systems. . For machines other than Qubes virtual machines. . Provides packages for LXQt graphical desktop installations. Package: kicksecure-packages-dependencies-pre Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Depends: dist-base-files, kicksecure-network-conf Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-packages-dependencies-pre_33.2-1_all.deb Size: 80316 SHA256: 4ae97fef4b7af7406ba81aa0c4c51cdf8118550647629f83730117b5b6d88a4f SHA1: 763a2c0ac1760aae12452ae6ea2a6dff1a6f91fd MD5sum: 50c95aba0dbfd45f0024b9b56665b2c3 Description: Dependencies for Kicksecure that changes network related files A metapackage, which installs packages which Kicksecure depends on. Can not be merged into another package due to conflicts with chroot build process. Package: kicksecure-qubes-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: qubes-gpg-split, qubes-img-converter, qubes-pdf-converter Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-qubes-cli_33.2-1_all.deb Size: 80296 SHA256: 0dd2b193443ce90b740879974cce5525fb072abc50e0ca36db779d230a21503f SHA1: 3dff0dba4a94b590b9d6ef246ed7e017e858c8b8 MD5sum: 1de359da6e681cee9154c0d3a4393290 Description: Kicksecure systems, Qubes VMs, command-line packages For Kicksecure systems. . For Qubes virtual machines. . Provides packages for basic command-line-only installations. Package: kicksecure-qubes-gui-all Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: pipewire-qubes Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-qubes-gui-all_33.2-1_all.deb Size: 80284 SHA256: 8ad6e926ec9574915d8a34445cc938bb2cf758485c5cfe3cd6c9aa80872ad015 SHA1: b40b599fe4ce8b19e577236c3d6b154d0f08bf6f MD5sum: 3ffb95e5bc6ad0de0d363ac0c2ef82b1 Description: Kicksecure systems, Qubes VMs, GUI packages For Kicksecure systems. . For Qubes virtual machines. . Provides packages for all graphical desktop installations. Package: kicksecure-qubes-gui-lxqt Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: kicksecure-qubes-gui-all, kicksecure-qubes-cli, kicksecure-general-gui-lxqt, kicksecure-general-gui-all, kicksecure-general-cli, dist-qubes-gui-lxqt, dist-qubes-cli, dist-general-gui-lxqt, dist-general-gui-all, dist-general-cli Breaks: kicksecure-qubes-gui Replaces: kicksecure-qubes-gui Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-qubes-gui-lxqt_33.2-1_all.deb Size: 80332 SHA256: db5f9fbe20cb9f374164e9fce0860ae2b11119702f650558f6261fb1e3580e7b SHA1: 74155cbabb56cdd0b9838d9ff113c85f83eed147 MD5sum: 48e5db2524a8ec1e049b6928eef87eca Description: Kicksecure systems, Qubes VMs, LXQt GUI packages For Kicksecure systems. . For Qubes virtual machines. . Provides packages for LXQt graphical desktop installations. Package: kicksecure-qubes-server Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: kicksecure-qubes-cli, kicksecure-general-cli, dist-qubes-cli, dist-general-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-qubes-server_33.2-1_all.deb Size: 80272 SHA256: 93d291b2c45b7ce9513e408c38c5feacc431963fb67aaa71d11a59a42c2bff94 SHA1: 3ac32db49a4a5661eec4a52cd6cf9669f085fb91 MD5sum: 26bebfdb6f1772c8c09829a8b5c43b14 Description: Kicksecure systems, Qubes VMs, server packages For Kicksecure systems. . For Qubes virtual machines. . Provides packages for server installations. Package: kicksecure-vm-cli Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Breaks: kicksecure-cli-vm Replaces: kicksecure-cli-vm Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-vm-cli_33.2-1_all.deb Size: 80272 SHA256: 4b25165efcda86b7a7b8830aab3ec7772c907b32cbf3f22ce051344cffa3aa7a SHA1: 39bd6faf46a4ea38463a4eba10f6a17085f87704 MD5sum: 5585733398dba6efdc2275e323cd9814 Description: Kicksecure systems, VMs, command-line packages For Kicksecure systems. . For non-Qubes virtual machines. . Provides packages for basic command-line-only installations. Package: kicksecure-vm-gui-lxqt Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: kicksecure-vm-cli, kicksecure-nonqubes-gui-lxqt, kicksecure-nonqubes-gui-all, kicksecure-nonqubes-cli, kicksecure-general-gui-lxqt, kicksecure-general-gui-all, kicksecure-general-cli, dist-vm-cli, dist-nonqubes-gui-lxqt, dist-nonqubes-gui-all, dist-nonqubes-cli, dist-general-gui-lxqt, dist-general-gui-all, dist-general-cli Breaks: kicksecure-lxqt-vm Replaces: kicksecure-lxqt-vm Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-vm-gui-lxqt_33.2-1_all.deb Size: 80356 SHA256: a49d0d08d6e60f29c7026643ea56948b680bba47f747dcdc4872fa6b0ad09fc4 SHA1: 79273386fd62c69cfebe9c080e5e5352a5af715c MD5sum: 7ed076b27a372b9cba2c979db1fc3905 Description: Kicksecure systems, VMs, LXQt GUI packages For Kicksecure systems. . For non-Qubes virtual machines. . Provides packages for LXQt graphical desktop installations. Package: kicksecure-vm-server Source: kicksecure-meta-packages Version: 3:33.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 107 Pre-Depends: legacy-dist Depends: kicksecure-vm-cli, kicksecure-nonqubes-cli, kicksecure-general-cli, dist-vm-cli, dist-nonqubes-cli, dist-general-cli Homepage: https://github.com/Kicksecure/kicksecure-meta-packages Priority: optional Section: metapackages Filename: pool/main/k/kicksecure-meta-packages/kicksecure-vm-server_33.2-1_all.deb Size: 80288 SHA256: 9211e3656a653b01c98d254ebee5cb6a66512bbed2266d4836377add8d925273 SHA1: adefe90535214c5abdb267ec5c4684d1cc3b9d3b MD5sum: 32dee9050f2e6e4a444aa9d9a6d84dcd Description: Kicksecure systems, VMs, server packages For Kicksecure systems. . For non-Qubes virtual machines. . Provides packages for server installations. Package: kicksecure-welcome-page Version: 3:7.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 1012 Depends: fonts-roboto-fontface, libjs-jquery Homepage: https://github.com/Kicksecure/kicksecure-welcome-page Priority: optional Section: misc Filename: pool/main/k/kicksecure-welcome-page/kicksecure-welcome-page_7.5-1_all.deb Size: 922204 SHA256: b7e22aaefa9fbb827401848a4d7aa2d173e0c1ca410d470a8958ec546d8d4ecc SHA1: 7f92376233c2b7af368e0a926317e36499e31d23 MD5sum: 02976cc9b95d4bea8e0a096e1f080512 Description: Local Browser Homepage for Kicksecure Kicksecure specific browser start page. . Contains Kicksecure logo and Kicksecure links. . Safe to remove, if you know what you are doing. Package: legacy-dist Version: 3:17.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 134 Depends: helper-scripts, apt-forktracer Conflicts: vbox-disable-timesync, whonix-legacy Replaces: vbox-disable-timesync, whonix-legacy Provides: vbox-disable-timesync, whonix-legacy Homepage: https://github.com/Kicksecure/legacy-dist Priority: optional Section: misc Filename: pool/main/l/legacy-dist/legacy-dist_17.0-1_all.deb Size: 52796 SHA256: 5a10f5db59dfa5506c72aa42c360d47f66501a521602355f282ae81d68016b8a SHA1: f2571c2bc54c26c27b8a7fa5f6a7ddb10e06f2c3 MD5sum: 6065d4e83a7e27e957712702a7bf510a Description: Prepare older Build Versions of Derivatives for Upgrade Applies fixes required for upgrading from for example version 8.x to version 9.x etc. . Upgrades from version 7.x or older versions is unsupported. . Safe to remove. Package: libvirt-dist Version: 3:11.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 143 Depends: adduser, qemu-kvm, libvirt-daemon-system, libvirt-clients, virt-manager, gir1.2-spiceclientgtk-3.0, dnsmasq-base, helper-scripts, msgcollector Conflicts: whonix-libvirt Replaces: whonix-libvirt Provides: whonix-libvirt Homepage: https://github.com/Kicksecure/libvirt-dist Priority: optional Section: misc Filename: pool/main/libv/libvirt-dist/libvirt-dist_11.4-1_all.deb Size: 55308 SHA256: 7396d5182dbc392397bc996593bd8bdc85549e569acf4d625fa6d7baffc67b3a SHA1: 4e8aa3dd98e927a2b89ed812dfdb7679d35f7407 MD5sum: 6ce195ddc393bab19399962e9a82e2bf Description: Whonix Libvirt XML Files for KVM and QEMU Libvirt XML files for Whonix-Gateway, Whonix-Workstation, Whonix-Custom-Workstation and Whonix's internal network. . Whonix-Host grub branding, motd and issue banner. . Whonix-Host boot popup. . See also: - https://www.kicksecure.com/wiki/KVM - https://www.kicksecure.com/wiki/QEMU Package: live-config-dist Version: 3:8.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 300 Depends: helper-scripts, pkexec, rsync, libglib2.0-bin, xdg-user-dirs, qml6-module-qtquick-window Homepage: https://github.com/Kicksecure/live-config-dist Priority: optional Section: misc Filename: pool/main/l/live-config-dist/live-config-dist_8.8-1_all.deb Size: 146192 SHA256: 379c222a16272cd456ea029cb7b0a7201aa4d26887cf567237365636a39e4ea8 SHA1: 2f7e2534dfea67368d168e70672e1c02cf34ab50 MD5sum: 7c5a819886abb56e00e68412f49a0a50 Description: calamares-settings-kicksecure and maybe calamares-settings-whonix Installed in Host ISO Live. . Supposed to be removed in Host installed. . Kernel parameters required for Live ISO. Package: lxqt-wayland-session Version: 0.2.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 473 Homepage: https://github.com/lxqt/lxqt-wayland-session Priority: optional Section: x11 Filename: pool/main/l/lxqt-wayland-session/lxqt-wayland-session_0.2.2-1_all.deb Size: 341988 SHA256: 2f00ea6343dfa5d03236f44abd55949163f90b8d3654d3b8d0ed388957112f3c SHA1: 6e19cf6647b28cfa95faa39a254d6cf6611bfa45 MD5sum: bafbd304f2964168d7073ad4f3b07fd4 Description: Files needed for the LXQt Wayland Session Files needed for the LXQt Wayland Session: Wayland session start script, its desktop entry for display managers and default configurations for actually supported compositors. Package: mediawiki-shell Version: 3:4.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 144 Depends: helper-scripts, safe-rm, jq, retry, python3 Homepage: https://github.com/Kicksecure/mediawiki-shell Priority: optional Section: misc Filename: pool/main/m/mediawiki-shell/mediawiki-shell_4.4-1_all.deb Size: 42616 SHA256: 491b71517cfdd553a070c6474a3b3008125278f8a6c6c3968c70182cf2d5057f SHA1: 52b4de90816ebdca9902dc7c845349f76855549b MD5sum: f05908ae3264605ca08e98047d080444 Description: bash shell scripts for usage of MediaWiki API Description here. . TODO Package: msgcollector Version: 3:14.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 213 Depends: python3, inotify-tools, procps, safe-rm, moreutils, init-system-helpers (>= 1.52) Conflicts: diverts-etc++bash.bash+-+logout Provides: diverts-etc++bash.bash+-+logout Homepage: https://github.com/Kicksecure/msgcollector Priority: optional Section: misc Filename: pool/main/m/msgcollector/msgcollector_14.8-1_all.deb Size: 67788 SHA256: 17e08a2b5d3ae77101aef85f6bef70079cf863898d20ecfe5702ac14986dfea1 SHA1: 7516d649f5787b3ed18b063832e190cdb832e04c MD5sum: 2541d1f901ccdb6109ccd7ef7efb2329 Description: Command Line Interface Messages Toolkit Library A programming library providing an application programming interface (API) that allows the programmer to output colored text in terminal user interfaces (CLI). . Applications can send messages to msgcollector which it collects and dispatches once instructed to do so by the application. . For clarity and avoidance of confusion, msgcollector does not collect any data. Applications that do not use msgcollector do not interact with msgcollector. It is roughly in the same category as ncurses but has of course much less and very different features. . For graphical user interface (GUI) support also install package msgcollector-gui. Package: msgcollector-gui Source: msgcollector Version: 3:14.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 75 Depends: msgcollector, python3-pyqt5, qtwayland5, yad, libnotify-bin | kde-baseapps-bin, lxqt-notificationd, x11-utils, gnome-colors-common Homepage: https://github.com/Kicksecure/msgcollector Priority: optional Section: misc Filename: pool/main/m/msgcollector/msgcollector-gui_14.8-1_all.deb Size: 47252 SHA256: bef4b62982e709e89498c062c8850684f23c2b2b126bcad422088df5ca2a5f97 SHA1: cfb29c942b4a5c98b2d869fb0e9488411bcc4838 MD5sum: 2f17ca182ad85c38a7ed319e742ae2ac Description: Graphical User Interface Toolkit Library A programming library providing an application programming interface (API) that allows the programmer to output colored text in graphical user interfaces (GUI). . Applications can send messages to msgcollector which it collects and dispatches once instructed to do so by the application. . For clarity and avoidance of confusion, msgcollector does not collect any data. Applications that do not use msgcollector do not interact with msgcollector. It is roughly in the same category as Qt or GDK but has of course much less and very different features. . A metapackage that installs required dependencies for graphical user interface support. Package: open-link-confirmation Version: 3:7.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 102 Depends: sensible-utils, icon-pack-dist, msgcollector, xdg-utils Recommends: tb-starter, tb-updater Breaks: tb-default-browser (<< 3:7.5-1) Replaces: tb-default-browser (<< 3:7.5-1) Homepage: https://github.com/Kicksecure/open-link-confirmation Priority: optional Section: misc Filename: pool/main/o/open-link-confirmation/open-link-confirmation_7.6-1_all.deb Size: 33492 SHA256: 53c2a61dd1ffb4400cca89827f015ff04607d2f568f562b2fb8eb999195c6574 SHA1: 34388062b6344e75b5e651fa67b2d8198dd924da MD5sum: 7173895dcbc0b56cf39cadc72450807f Description: Asks for confirmation before opening links Asks before a link is (accidentally) opened in a browser. Links are opened in x-www-browser. . Currently only the Tor Browser starter from the tb-starter package (by Whonix developers) supports using open-link-confirmation. Shell wrappers could be written to support other browsers as well. . On an Anonymity Gateway (when the anon-gw-base-files package is installed), it honors the $EDITOR environment variable (falls back to mousepad if unset), asks if a file should be opened in an editor before opening it and informs, that opening links on a Gateway is unsupported for security reasons. . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: privleap Version: 3:4.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 212 Depends: python3, python3-pam, python3-sdnotify Homepage: https://www.kicksecure.com/wiki/Privleap Priority: optional Section: admin Filename: pool/main/p/privleap/privleap_4.1-1_all.deb Size: 52780 SHA256: ec9d57a04615dd902aa27ad6217ddb7b7f42e7e83c57a26ae901e93186b71382 SHA1: 13704a844fbf33b0b241565e79d4cfb2076b3924 MD5sum: 77d6fcbb6ed8367435e3cb50d51feed4 Description: Limited privilege escalation framework Provides a privilege escalation framework for running pre-defined command sequences ("actions") as root. . Does not require a SUID executable. Package: rads Version: 3:7.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 114 Depends: systemd Homepage: https://www.kicksecure.com/wiki/RAM_Adjusted_Desktop_Starter Priority: optional Section: misc Filename: pool/main/r/rads/rads_7.8-1_all.deb Size: 35784 SHA256: d7b9bf8ae12080bee4911103693cf1a5c6aaa17c8eb37f36d1a125e251431291 SHA1: dd79c64ff9de904109e7951eca1ef531bbc6a35e MD5sum: 7e26754dc2a534e16c7520378618ce9d Description: RAM Adjusted Desktop Starter If there is more than X MB RAM in total, the desktop environment will be started. . If less than X MB RAM in total (for example, only 196 MB RAM in total), no desktop environment will be started. . This should be quite convenient, because users with low RAM could reduce Y MB and even if they sometimes wanted to configure/check something, they could assign 512 RAM and automagically boot into the graphical desktop. There are also many settings in /etc/rads.d/ (stackable) to configure this feature, so if you want, you can also add a lot RAM, but not boot into a desktop environment, or use different display managers and so on. . Most useful in virtual machines. Package: ram-wipe Version: 3:3.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 97 Depends: helper-scripts, dracut, secure-delete, kexec-tools, systemd-cryptsetup Homepage: https://github.com/Kicksecure/ram-wipe Priority: optional Section: misc Filename: pool/main/r/ram-wipe/ram-wipe_3.9-1_all.deb Size: 25780 SHA256: 1385396b56ab65bc76486dcee268b31d724eb755a7ac44088d5467068f3f4837 SHA1: 47f11dd19e93c007963b9193f3b1c903840d0a22 MD5sum: 433ab86f53f91807a1613d7c2c109cf4 Description: Wipe RAM on shutdown and reboot A dracut module that wipes RAM on shutdown and reboot. . Not implemented for initramfs-tools. Package: repository-dist Version: 3:12.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 218 Depends: helper-scripts, lsb-release, moreutils, python3:any Homepage: https://www.kicksecure.com/wiki/Project-APT-Repository Priority: optional Section: misc Filename: pool/main/r/repository-dist/repository-dist_12.8-1_all.deb Size: 112448 SHA256: 642cbc5e5540aa9442886a0734be99ece7b12ce00237ee228e837dead6aafa13 SHA1: 3059d02ae00e51c0f62b433b152abe4d62793f96 MD5sum: 3de576a3c130ee24dd284a5892b58bd8 Description: Derivative APT Repository Command Line Interface (CLI) This tool can always be used to enable either Derivative's stable, testers or developers repository or to disable Derivative's repository. . Derivative's APT Repository is not enabled by default. Some users prefer this for trust/security reasons. . On first boot of Derivative, the Derivative Repository Tool gets automatically started by setup-dist. The user is free to either leave Derivative's repository disabled or to configure it as desired. . Technically speaking, this tool creates or deletes file `/etc/sources.list.d/derivative.sources`. . Using APT `signed-by`. Package: repository-dist-wizard Source: repository-dist Version: 3:12.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 74 Depends: pkexec, python3-pyqt5, python3:any, qtwayland5 Homepage: https://www.kicksecure.com/wiki/Project-APT-Repository Priority: optional Section: misc Filename: pool/main/r/repository-dist/repository-dist-wizard_12.8-1_all.deb Size: 40728 SHA256: 6eb59998244e926873fbde90c0aa50386c5c9e872179dd84b644e1f62ed4aa88 SHA1: c97ce15e658ac5a3ee525169cab44f0f7c224790 MD5sum: b13a9f78220d65f008dd98281a671473 Description: Derivative APT Repository Graphical User Interface (GUI) This tool can always be used to enable either Derivative's stable, testers or developers repository or to disable Derivative's repository. . This is a metapackage depending on the required packages for the GUI (Graphical User Interface). Package: ro-mode-init Version: 3:3.3-1 Architecture: all Maintainer: Algernon <33966997+Algernon-01@users.noreply.github.com> Installed-Size: 60 Depends: live-boot, live-boot-initramfs-tools, live-tools Conflicts: grub-default-live, grub-live Replaces: grub-default-live, grub-live Provides: boot-live Homepage: https://github.com/Kicksecure/ro-mode-init Priority: optional Section: misc Filename: pool/main/r/ro-mode-init/ro-mode-init_3.3-1_all.deb Size: 19556 SHA256: 5880392cec7c0c25d70ac8c799835a04fc5eb7c118b56541a3d424b2ef750fae SHA1: f5e96a4e5d2773ee9a3b4388ae4a60ec5ab07017 MD5sum: 9073b1ec309be7199744853611daf628 Description: Detects read-only disks and automatically enables live-boot Allows booting the system in live mode. Meaning, no persistent modifications will be written to the disk. All changes stay in RAM. . No claims are made with regard to anti forensics. Package: sandbox-app-launcher Version: 0:7.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 131 Depends: sudo, bubblewrap, apparmor, libseccomp-dev, helper-scripts, dbus-x11 Homepage: https://www.kicksecure.com/wiki/Sandbox-app-launcher Priority: optional Section: misc Filename: pool/main/s/sandbox-app-launcher/sandbox-app-launcher_7.1-1_all.deb Size: 48884 SHA256: 5c2f88799a0577c9ea1d2426351e9cd3787cd118ff4ed6f4d3eebb3ba09400e1 SHA1: 9b70b350ff57a1168bfb00bac5c3d72b163b21f7 MD5sum: 6049e9389d0c19109fd0148e7f81d318 Description: application launcher to start apps in a restrictive sandbox sandbox-app-launcher runs each app as its own user, in a bubblewrap sandbox and confined by apparmor. . The directory, `/shared`, is shared across all app sandboxes to transfer files across. . This implements a permissions system to configure what apps can access. There are currently 5 available permissions: . * Network access . * Webcam access . * Microphone access . * Shared storage access (read-only or read-write) . * Dynamic native code execution . All apps the user installs will be automatically configured to run in the sandbox and a prompt will ask the user which permissions they wish to grant the application (not implemented yet). . Currently a WIP and not for actual use. Package: sdwdate Version: 3:26.2-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 344 Depends: sudo, bc, helper-scripts, adduser, gcc, libc6-dev, privleap, python3-stem, python3-dateutil, python3-socks, python3-sdnotify, python3-requests, python3, tor Recommends: timesanitycheck, bootclockrandomization Conflicts: time-daemon Provides: time-daemon Homepage: https://www.kicksecure.com/wiki/Sdwdate Priority: optional Section: misc Filename: pool/main/s/sdwdate/sdwdate_26.2-1_all.deb Size: 151012 SHA256: 2128c70a188a6785fd1b2118ca2df1dbd6b7ffc6c805d834924975314ffb772f SHA1: 786e34cdf81faf07946b35bb73f98204fb66e010 MD5sum: 9acbc6fcb4f7d721ef6774b0bcf2877f Description: Secure Distributed Network Time Synchronization Time keeping is crucial for security, privacy, and anonymity. Sdwdate is a Tor friendly replacement for rdate and ntpdate that sets the system's clock by communicating via onion encrypted TCP with Tor onion webservers. . At randomized intervals, sdwdate connects to a variety of webservers and extracts the time stamps from http headers (RFC 2616). Using sclockadj option, time is gradually adjusted preventing bigger clock jumps that could confuse logs, servers, Tor, i2p, etc. . This package contains the sdwdate time fetcher and daemon. No installation on remote servers required. To avoid conflicts, this daemon should not be enabled together with ntp or tlsdated. Package: sdwdate-gui Version: 1:11.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 267 Depends: sudo, privleap, python3, python3-pyqt5, qtwayland5, helper-scripts, sdwdate, adduser Homepage: https://www.kicksecure.com/wiki/sdwdate-gui Priority: optional Section: misc Filename: pool/main/s/sdwdate-gui/sdwdate-gui_11.8-1_all.deb Size: 98776 SHA256: 4f5ed94efc8f07e7d55d0ac19ced6c7c8b5dcd4ab39e87ce60d02d53e2d0a9dc SHA1: 91c74a9fdf21d61641d2a3c7683a2f83a637cb12 MD5sum: d50a25cc5bc3395a11ff64d6017c5a86 Description: Sdwdate Monitor sdwdate-gui is a systray icon monitor for sdwdate: checks sdwdate's status and modify the tray icon accordingly. In addition, it allows the user to restart sdwdate and view the log. Package: security-misc Version: 3:47.4-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 695 Depends: adduser, apparmor-profile-dist, build-essential, dmsetup, helper-scripts, libcap2-bin, libglib2.0-bin, libpam-modules-bin, libpam-runtime, libpam-umask, memlockd, python3, secure-delete, sudo, dconf-gsettings-backend | gsettings-backend, debconf (>= 0.5) | debconf-2.0 Replaces: anon-gpg-tweaks, swappiness-lowest, tcp-timestamps-disable Homepage: https://www.kicksecure.com/wiki/Security-misc Priority: optional Section: misc Filename: pool/main/s/security-misc/security-misc_47.4-1_all.deb Size: 240424 SHA256: ba8f4cbc17f5c85beb50e10d05016e5a348ed75808384ba4c235f1cfe63b26e5 SHA1: e000b7ed1a7bf290941570fc0e1337466ff68ef9 MD5sum: 9f4c213e069abad3cee3020b2cc288e2 Description: Enhances Miscellaneous Security Settings https://github.com/Kicksecure/security-misc/blob/master/README.md . https://www.kicksecure.com/wiki/Security-misc . Discussion: . Happening primarily in Whonix forums. https://forums.whonix.org/t/kernel-hardening/7296 Package: serial-console-enable Version: 3:4.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 62 Homepage: https://github.com/Kicksecure/serial-console-enable Priority: optional Section: misc Filename: pool/main/s/serial-console-enable/serial-console-enable_4.5-1_all.deb Size: 18112 SHA256: 317a76bef2339842afb50259f39b6a17368be2ada4fc7a1228d041bcb2b8cc30 SHA1: aa7e516038259ff46d12850a3b1bfa440a577986 MD5sum: 1151eeb8fc1337853a74503bb00a4898 Description: Enables serial console Ships a /etc/default/grub.d/30_serial_console.cfg configuration file, that enables serial console. . Enables /lib/systemd/system/getty.target.wants/serial-getty@ttyS0.service by creating a symlink from: /lib/systemd/system/serial-getty@.service to: /lib/systemd/system/getty.target.wants/serial-getty@ttyS0.service . Useful for serial console login such as into Whonix KVM VMs from the host operating system. . Forum discussion: https://forums.whonix.org/t/how-do-i-enter-the-whonix-shell-from-cli/7271 . Safe to remove if you do not require serial console login such as: virsh console vm-name Package: setup-dist Version: 3:11.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 137 Depends: helper-scripts, dialog, privleap, menu, python3 Conflicts: whonixsetup Replaces: whonixsetup Provides: whonixsetup Homepage: https://github.com/Kicksecure/setup-dist Priority: optional Section: misc Filename: pool/main/s/setup-dist/setup-dist_11.8-1_all.deb Size: 47364 SHA256: 44b5139d2fcb57c73a6588069837157f8f6b6daa657b6e2d5dc688318ac55932 SHA1: 699101e95c99dc2954444da5c088ffc229d5cd60 MD5sum: 4109da0d87bd00662cf5a855ba981de5 Description: First Time Connection Setup Disclaimer. . When the derivative starts for the first time, it won't automatically connect to the public Tor network. This is useful for users who want to hide Tor from their ISP. setup-dist is automatically started, which educates about different methods to connect (public Tor network, bridges, etc.). Package: setup-wizard-dist Version: 3:12.9-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 139 Depends: setup-dist, python3-yaml, helper-scripts, python3, x11-xserver-utils Recommends: icon-pack-dist Conflicts: whonix-setup-wizard Replaces: whonix-setup-wizard Provides: whonix-setup-wizard Homepage: https://github.com/Kicksecure/setup-wizard-dist Priority: optional Section: misc Filename: pool/main/s/setup-wizard-dist/setup-wizard-dist_12.9-1_all.deb Size: 60064 SHA256: ee679cbb2448fdcbe2aaeb030e237e08415f2f9f73c93171d3036e96b4e9c4ce SHA1: 5936738b468d4bdd48a5dc29fdd020d6d0f494d7 MD5sum: 447f4f95e17ed90422341f9b9872adf2 Description: First Boot Setup Disclaimer. . When distribution starts for the first time, it won't automatically connect to the public Tor network. This is useful for users who want to hide Tor from their ISP. Anon Connection Wizard is automatically started, which educates about different methods to connect (public Tor network, bridges, etc.). Package: swap-file-creator Version: 3:8.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 84 Depends: helper-scripts, cryptsetup-bin, bc, systemd-cryptsetup Recommends: haveged, jitterentropy-rngd Homepage: https://www.kicksecure.com/wiki/Swap-file-creator Priority: optional Section: misc Filename: pool/main/s/swap-file-creator/swap-file-creator_8.5-1_all.deb Size: 33000 SHA256: 3025f8c42d892d96f40052f92b349f7c1ab1bc470f64d2ae543886b4f7c40eaa SHA1: b12dfb648800b54374cf3e8d13361131a228c766 MD5sum: ff08bf054a595e66f4069738ba27eb9b Description: Adds encrypted swap file to the system On every boot, creates a new encrypted swapfile with a random key. . Useful for systems with low RAM such as inside virtual machines. . Has an option to shred the swapfile on shutdown. Package: sysmaint-panel Version: 3:3.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 124 Depends: helper-scripts, pkexec, python3, python3-pyqt5, safe-rm Homepage: https://www.kicksecure.com/wiki/System_Maintenance_Panel Priority: optional Section: admin Filename: pool/main/s/sysmaint-panel/sysmaint-panel_3.3-1_all.deb Size: 28620 SHA256: 85f965ad0109cbb57c10a31f043a3f53f950aefd9a501bc7d3b26ab002791f94 SHA1: 2ff97dca48b3ee1e1adfa67e1c4c91a3b081ed2e MD5sum: a45dafe672bff9576b4c4cb1c10421f1 Description: System Maintenance Panel The System Maintenance Panel (sysmaint-panel) allows the user to perform several common system maintenance and administration tasks. It can be used to install, remove, and update software, create and remove user accounts, and enable or disable password protection and autologin for user accounts. . Provides a minimal session that can be booted into for system maintenance tasks on Linux distributions. Package: systemcheck Version: 3:41.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 553 Depends: dist-base-files, python3, signify-openbsd, curl, ca-certificates, msgcollector, psmisc, sudo, vrms, libarchive-tools, helper-scripts, net-tools, privleap, systemd, adduser, security-misc, spectre-meltdown-checker, apparmor-profile-dist Recommends: icon-pack-dist, msgcollector-gui Conflicts: apparmor-profile-whonixcheck, whonixcheck Replaces: apparmor-profile-whonixcheck, whonixcheck Homepage: https://www.kicksecure.com/wiki/systemcheck Priority: optional Section: misc Filename: pool/main/s/systemcheck/systemcheck_41.6-1_all.deb Size: 176676 SHA256: 2d14e5f120fc482718b1cbbd3f361d419e3b114365b4f0036b0d341aa29d5c6b SHA1: f2da17e138ba12bfc014631690388f572c113965 MD5sum: 4c0b3cac1948149ae1484c8b4b391178 Description: Anonymity and security check Checks many important aspects for better security. . Only checks things. Does not change things. . Safe to remove. Package: tb-default-browser Source: open-link-confirmation Version: 3:7.6-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 60 Depends: open-link-confirmation Homepage: https://github.com/Kicksecure/open-link-confirmation Priority: optional Section: oldlibs Filename: pool/main/o/open-link-confirmation/tb-default-browser_7.6-1_all.deb Size: 28092 SHA256: 6155fa9972a5e456bc89c4538e4e50c0955b0c58f1aa48252c51671fda70b0b6 SHA1: 9cb1a931e775e0632298431bdc1fc028efa77283 MD5sum: 87aa305f647e45618205a79c6d61b8b7 Description: transitional package This is a transitional package. It can safely be removed. Package: tb-starter Version: 3:18.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 171 Depends: msgcollector, privleap Recommends: tb-updater, open-link-confirmation, icon-pack-dist Provides: torbrowser-launcher Homepage: https://github.com/Kicksecure/tb-starter Priority: optional Section: misc Filename: pool/main/t/tb-starter/tb-starter_18.0-1_all.deb Size: 67604 SHA256: 300a314e2a4ebc228857218f8ec19060e77513ac5a479b359f5f94add13aeef6 SHA1: 6b2fe1a4412250164aee30a3d151884f809f5355 MD5sum: 677b64fceb99cc414074cdec31867b16 Description: Tor Browser Starter (by Whonix developers) Both, a starter for Tor Browser. Provides security hardening, integration with Debian, Whonix and Qubes. . Starter. . - Tor Browser Starter start menu entry and `/usr/bin/torbrowser` starter. Starts `/home/user/.tb/tor-browser/start-tor-browser`. . When config option tb_hardening=true is set or when using command line option --hardening, firejail will be used. . Uses open-link-confirmation if available. . Prompts to install the browser if not yet installed. . Changes directory into browser directly before startup. . Custom homepage support. . Qubes integration. . Sanity tests: - Aborts if detected being run as root. - Aborts in Qubes TemplateVM. - Aborts in Qubes DVM Template. - Waits for Qubes mount dirs and gui agent being ready. . In Qubes AppVM copies browser from root image to private image at first start. . Tor Browser documentation by Whonix. . - https://www.whonix.org/wiki/Tor_Browser - https://www.whonix.org/wiki/Tor_Browser/Advanced_Users . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: tb-updater Version: 3:39.8-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 523 Depends: msgcollector-gui, curl, psmisc, gpg-bash-lib, pv, libarchive-tools, sudo, jq, libdbus-glib-1-2, privleap, python3 Recommends: tb-starter, icon-pack-dist, helper-scripts Suggests: open-link-confirmation Homepage: https://github.com/Kicksecure/tb-updater Priority: optional Section: misc Filename: pool/main/t/tb-updater/tb-updater_39.8-1_all.deb Size: 243228 SHA256: c2abd193fc6f5fda78d9243604b2b01e9dde5cafbe2a404dc42492f8c6ae738d SHA1: 71da65b6139872da0b072333ad85a5a603022193 MD5sum: f41c4c5098640131717f3e15b738dd1a Description: Tor Browser Downloader by Whonix developers Automates download and verification of Tor Browser from The Tor Project's website. Useful for initial installation of Tor Browser, clean re-installations of Tor Browser and keeping newly created Qubes AppVMs inherited from updated Qubes TemplateVMs can ship up to date versions of Tor Browsers. . Incapable of preserving of updating and preserving user data. Use Tor Browser's internal updater for that purpose. Notifies about already exiting installations of Tor Browser. Renamed rather than deletes old versions of Tor Browsers to avoid user data loss. . Has a cli and a gui mode. Can auto detect latest version numbers or use user configured version numbers. Comes with a download confirmation screen that lets users choose which version to download. [1] Has a installation confirmation screen [2] that enables users to detect indefinite freeze and rollback attacks. . Integrates well with tb-starter and open-link-confirmation package as well as with Qubes. . Without the helper-scripts package installed, the GUI will not move the progress bar. . If you have the helper-scripts package installed, it will show a nicer progress bar when run in terminal and more meaningful curl exit code messages, when curl failed. . When having the helper-scripts package installed (recommended for Anonymity Distributions), Tor Browser Downloader will check, that Tor is enabled, that no package manager is currently running and that Tor finished bootstrapping before download attempts. . Supports being run inside chroot and from Debian maintainer postinst script. . Qubes integration: . - Up-to-date browser versions made available to freshly created AppVMs and DispVMs. - In DispVM mounts browser folder which resides in root image to user home folder rather than copying for faster browser startup. . This package is produced independently of, and carries no guarantee from, The Tor Project. . [1] https://www.whonix.org/wiki/Tor_Browser#Download_Confirmation_Screen [2] https://www.whonix.org/wiki/Tor_Browser#Installation_Confirmation_Screen Package: timesanitycheck Version: 3:7.3-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 78 Homepage: https://www.whonix.org/wiki/Dev/TimeSync Priority: optional Section: misc Filename: pool/main/t/timesanitycheck/timesanitycheck_7.3-1_all.deb Size: 27204 SHA256: 9ab98ce940685425a1133b46f5396a02e5d2e5e0a0128ace35c40df221ebb3b2 SHA1: 434c71660ba2a2423a4c73ede2debcb6311d47a7 MD5sum: 60d5e51285f15010983d2b1d3d83759b Description: Checks if the system clock is sane between build timestamp and expiration date Reports, if clock is sane and not slower than build timestamp or faster than expiration date (configurable, default currently set to 17 MAY 2033 10:00:00). . This should catch situations, where the host's clock is too much off (CMOS battery defect, user mistakenly set a very wrong date, etc.), resulting in network time synchronization tools (such as sdwdate) no longer being able to correct the clock; catch eventual bigger bugs in network time synchronization tools; and some types of attacks on network time synchronization. Package: tor-control-panel Version: 1:7.7-1 Architecture: all Maintainer: troubadour Installed-Size: 182 Depends: anon-connection-wizard, helper-scripts, pkexec, policykit-1-gnome | polkit-1-auth-agent, python3, python3-ipy, python3-pyqt5, python3-stem, qtwayland5 Recommends: obfs4proxy, tor Homepage: https://www.whonix.org/wiki/Tor-control-panel Priority: optional Section: misc Filename: pool/main/t/tor-control-panel/tor-control-panel_7.7-1_all.deb Size: 70960 SHA256: e621c8f331670a04000f966abc1e931e9554cbaa5a75238778ff8a61e67c238a SHA1: 714db4412b44788570262aed92af49a6f339f669 MD5sum: 001740ef0f159896ebd51832f9df8e48 Description: Tor Control Graphical User Interface WARNING: Not (yet) a standalone ready to use outside of Whonix: . tor-control-panel is a Tor controller. . tor-control-panel is produced independently from the Tor anonymity software and carries no guarantee from The Tor Project about quality, suitability or anything else. Package: tor-ctrl Version: 3:6.1-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 82 Depends: tor, netcat-openbsd, xxd, safe-rm Homepage: https://gitweb.torproject.org/torspec.git/tree/control-spec.txt Priority: optional Section: misc Filename: pool/main/t/tor-ctrl/tor-ctrl_6.1-1_all.deb Size: 29540 SHA256: 546d5513ac11ed48a0d25e9cce21afcb8f396961cefe78f6e245f25f1ea351fd SHA1: 9be5dfaef7a1e3bf8ec8c3d059cc8101c4007a3f MD5sum: d19b0113fabbb487782cf6ff32307b52 Description: Tor controller command line tool Command line tool for setting up stream for communication from the Tor Controller's (client) to a Tor process (server). The client send commands using TCP sockets or Unix-domain sockets and receive replies from the server. . https://gitweb.torproject.org/torspec.git/tree/control-spec.txt . This package is produced independently of, and carries no guarantee from, The Tor Project. Package: usability-misc Version: 3:29.5-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 719 Depends: sudo, policyrcd-script-zg2, adduser, python3, damngpl, helper-scripts (>= 3:35.3-1), dconf-gsettings-backend | gsettings-backend Replaces: gpl-sources-download, grub-screen-resolution, scurl Homepage: https://github.com/Kicksecure/usability-misc Priority: optional Section: misc Filename: pool/main/u/usability-misc/usability-misc_29.5-1_all.deb Size: 230384 SHA256: 26263db0f6da3a51bc1393a90411c9c9ddd70386e4f63f42b60c94814bff65c3 SHA1: aab57b73313656f3f34a469e3f835bf9f8a13727 MD5sum: 159eb385d4bb292e2c4deb25b85b6be5 Description: Misc usability improvements Enables auto login for user `user` in `lightdm`. `/etc/lightdm/lightdm.conf.d/30_autologin.conf` https://www.kicksecure.com/wiki/Desktop#Disable_Autologin . Creates folders /home/user/Downloads and /home/user/Pictures. . Adds account "user" to group libvirt as well as to group kvm. . Ships a file /etc/sudoers.d/user-passwordless that contains comments and "#user ALL=(ALL:ALL) NOPASSWD:ALL". Lets account "user" easily run all commands without password. Disabled (out commented) by default. . Simplifies running OpenVPN as unprivileged user. . Ships a FoxyProxy add-on configuration file for use with Tor Browser. . Sets mousepad as the default editor for environment variable VISUAL is unset and if mousepad is installed. . Disable sudo default lecture. /etc/sudoers.d/sudo-lecture-disable . Add pwfeedback to sudo Defaults so password asterisks are shown while typing. /etc/sudoers.d/pwfeedback . qterminal: . Ships gsudoedit, a wrapper to run sudoedit with a graphical editor. . Bisq workarond "sudo mkdir -p /usr/share/desktop-directories" as per https://github.com/bisq-network/bisq/issues/848 . gpl_sources_download GPL'ed source code of all installed packages. Used damngpl to get a list of all GPL'ed packages, then downloads them using apt-get source. . SSL curl wrapper: Simple wrapper called scurl, that adds "--tlsv1.3 --proto =https" in front of all invocations of "curl" when running "scurl". . Sets 1024x768 as boot screen resolution Ships a /etc/default/grub.d/30_screen_resolution.cfg configuration file, that injects "vga=0x0317" into the GRUB_CMDLINE_LINUX_DEFAULT variable. Package: user-sysmaint-split Version: 3:8.0-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 178 Pre-Depends: helper-scripts Depends: security-misc, adduser Breaks: qubes-core-agent-passwordless-root (>= 1) Homepage: https://github.com/Kicksecure/user-sysmaint-split Priority: optional Section: misc Filename: pool/main/u/user-sysmaint-split/user-sysmaint-split_8.0-1_all.deb Size: 45092 SHA256: 56e8b8755fada70751c08c42953c45b1abf8020fdf505a260decf5425be25e82 SHA1: 782d35fbc25260bb1bdc438a28bd9a4cdfb1194e MD5sum: 6eb26122d4933b3e5d69b41b0f1c44c7 Description: Role-Based Boot Modes - user versus sysmaint Adds a GRUB boot menu entry: "PERSISTENT Mode | SYSMAINT Session | system maintenance tasks" . Makes Privilege Escalation Tools (such as 'sudo', 'su', 'pkexec') inaccessible to limited user accounts such as account "user". . Adds kernel parameter "boot-role=sysmaint" and "systemd.unit=sysmaint-boot.target". Package: vm-config-dist Version: 3:12.7-1 Architecture: all Maintainer: Patrick Schleizer Installed-Size: 173 Depends: sudo, adduser, 7zip, helper-scripts Replaces: power-savings-disable-in-vms, shared-folder-help Homepage: https://github.com/Kicksecure/vm-config-dist Priority: optional Section: misc Filename: pool/main/v/vm-config-dist/vm-config-dist_12.7-1_all.deb Size: 51144 SHA256: cb936cb06eba528cafe118b4412cfb66ab982efff041ec02c723e28e790d6cbc SHA1: 904304d6aa09f2d218e77c5d86c9f6dfb9656152 MD5sum: 93ce4022b216affb48a97504cc94f902 Description: usability enhancements inside virtual machines Sets environment variable `QMLSCENE_DEVICE=softwarecontext` as workaround for "Automatic fallback to softwarecontext renderer". . It is not useful to open a screensaver or to power down the desktop for operating systems that are run inside VMs. There is no real display that could be saved and no real power that could be saved. From usability perspective it also is counter intuitive when looking at the VM window and only seeing a black screen. Therefore it makes sense to disable power savings in VMs. `/etc/X11/Xsession.d/20_kde_screen_locker_disable_in_vms.sh` `/etc/profile.d/20_power_savings_disable_in_vms.sh` `/etc/X11/Xsession.d/20_software_rendering_in_vms.sh` `/usr/share/kde-power-savings-disable-in-vms/kdedrc` `/usr/share/kde-screen-locker-disable-in-vms/kscreenlockerrc` . Optional: Disables screen locker when running in VMs because that is not useful either. This feature can be enabled in file: `/etc/X11/Xsession.d/20_kde_screen_locker_disable_in_vms.sh` . Makes setting up a shared folder for virtual machines a bit easier. . * Creates a folder `/mnt/shared` with `chmod 777`, adds a group "vboxsf", adds account "user" to group "vboxsf". Facilitates auto-mounting of shared folders. . * Helps using shared folders with VirtualBox and KVM a bit easier (as in requiring fewer manual steps from the user). . * `/lib/systemd/system/mnt-shared-vbox.service` * `/lib/systemd/system/mnt-shared-kvm.service` . Set screen resolution 1920x1080 by default for VM in VirtualBox and KVM. Workaround for low screen resolution 1024x768 at first boot. When using lower screen resolutions, Xfce will automatically scale down. `/etc/skel/.config/xfce4/xfconf/xfce-perchannel-xml/displays.xml` TODO: This may no longer be the case with Wayland. . Installs VirtualBox guest additions if package `virtualbox-guest-additions-iso` is installed if environment variable `dist_build_virtualbox=true` or if running inside VirtualBox. (`systemd-detect-virt` returning `oracle`) `/usr/bin/vbox-guest-installer`