Skip to content

Stop leaking dom0 timezone to Qubes-Whonix #8381

@adrelanos

Description

@adrelanos

Qubes OS release

R4.2

Brief summary

Qubes VMs leak timezone.

Reported by @chessjazz.

Steps to reproduce

qubesdb-read /qubes-timezone

Expected behavior

No command available to leak dom0 timezone.

Actual behavior

Dom0 timezone can be leaked in VM if malware is running inside the VM.

Additional information

For issue tracking.

  • issue caused by Qubes-Whonix: no
  • affects Qubes-Whonix: yes, because Whonix sets timezone to UTC as it should be hidden. (It doesn't leak to remote websites but malware with local code execution could read dom0 timezone.)
  • only relevant for Whonix: Dunno if there are also other users who would prefer not to leak this information to VMs.

Suggested solution

If qvm-features or similar mechanism has whonix-ws 1, whonix-gw 1, notimezone 1, then don't write /qubes-timezone to qubesdb.

Metadata

Metadata

Assignees

No one assigned

    Labels

    C: WhonixThis issue pertains to Whonix templates or standalones.P: defaultPriority: default. Default priority for new issues, to be replaced given sufficient information.S: partialStatus: partial. Work on this issue is partially complete, but it is not actively being worked on.community templateThis issue pertains to a community-maintained template.privacyThis issue pertains to privacy in Qubes OS or something controlled by the Qubes OS Project.

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions