<!DOCTYPE html>
<html>
  <head>
  <meta charset="utf-8">
  <meta http-equiv="X-UA-Compatible" content="IE=edge">
  <meta name="viewport" content="width=device-width, initial-scale=1">

  <title>
    
      TorVM | Qubes OS
    
  </title>
  
  <meta name="description"
        content="Known issues: Service doesn’t start without (even empty) user torrc Qubes TorVM (qubes-tor) Qubes TorVM is a deprecated ProxyVM service that provides torified networking to all its clients. If you are interested in TorVM, you will find the Whonix implementation in Qubes a more usable an...">
  
  <!-- LD+JSON schema --> 
  <script type='application/ld+json'> 
  {
    "@context": "http://www.schema.org",
    "@type": "WebSite",
    "name": "Qubes OS",
    "url": "https://www.qubes-os.org/"
  }
  </script>

  <!-- Open Graph -->
  <meta property="og:type" content="article">
  <meta property="og:url" content="https://www.qubes-os.org/doc/torvm/">
  <meta property="og:title" content="TorVM">
  
  
  <meta property="og:description"
        content="Known issues: Service doesn’t start without (even empty) user torrc Qubes TorVM (qubes-tor) Qubes TorVM is a deprecated ProxyVM service that provides torified networking to all its clients. If you are interested in TorVM, you will find the Whonix implementation in Qubes a more usable an...">
  
  
  <meta property="og:image" content="https://www.qubes-os.org/attachment/icons/qubes-logo-icon-name-slogan-fb.png">
  
  
  <meta property="article:published_time" content="2019-04-06T18:40:08+00:00">
  
  
  
  
  <meta property="article:section" content="">
  <meta property="og:site_name" content="Qubes OS">
  <meta property="fb:admins" content="andrewdavidwong.adw">

  <!-- Twitter Cards -->
  <meta name="twitter:card" content="summary_large_image">
  <meta name="twitter:site" content="@QubesOS">
  <meta name="twitter:title" content="TorVM">
  
  
  <meta property="twitter:description"
        content="Known issues: Service doesn’t start without (even empty) user torrc Qubes TorVM (qubes-tor) Qubes TorVM is a deprecated ProxyVM service that provides torified networking to all its clients. If you are interested in TorVM, you will find the Whonix implementation in Qubes a more usable an...">
  
  
  <meta name="twitter:image" content="https://www.qubes-os.org/attachment/icons/qubes-logo-icon-name-slogan-twitter.png">
  

  <!-- Qubes - Bootstrap Theme -->
  <link rel="stylesheet" href="../css/main.css">

  <!-- HTML5 shim and Respond.js for IE8 support of HTML5 elements and media queries -->
  <!-- WARNING: Respond.js doesn't work if you view the page via file:// -->
  <!--[if lt IE 9]>
    <script src="https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js"></script>
    <script src="https://oss.maxcdn.com/respond/1.4.2/respond.min.js"></script>
  <![endif]-->

  <link href="../css/font-awesome.min.css" rel="stylesheet">
  <link rel="canonical" href="torvm">
  <link rel="icon" type="image/x-icon" href="../attachment/icons/512x512/apps/qubes-logo-icon.png">
  <link rel="alternate" type="application/rss+xml" title="Qubes OS - Feed" href="../feed.xml" />

  <!-- Favicons -->
  <link rel="apple-touch-icon" sizes="180x180" href="../apple-touch-icon.png?v=bOv986l09r">
  <link rel="icon" type="image/png" href="../favicon-32x32.png?v=bOv986l09r" sizes="32x32">
  <link rel="icon" type="image/png" href="../favicon-16x16.png?v=bOv986l09r" sizes="16x16">
  <link rel="manifest" href="../manifest.json?v=bOv986l09r">
  <link rel="mask-icon" href="../safari-pinned-tab.svg?v=bOv986l09r" color="#5bbad5">
  <link rel="shortcut icon" href="../favicon.ico?v=bOv986l09r">
  <meta name="apple-mobile-web-app-title" content="Qubes OS">
  <meta name="application-name" content="Qubes OS">
  <meta name="theme-color" content="#ffffff">
</head>

    <body>
      <!-- Fixed navbar -->
<nav class="navbar navbar-custom navbar-static-top">
  <div class="container">
    <div class="navbar-header">
      <button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#navbar" aria-expanded="false" aria-controls="navbar">
        <span class="sr-only">Toggle navigation</span>
        <span class="icon-bar"></span>
        <span class="icon-bar"></span>
        <span class="icon-bar"></span>
      </button>
      <a class="page-link" href="../index.html">
        <img src="../attachment/icons/128x128/apps/qubes-logo-icon.png" width="44" height="44" alt="Qubes OS Project">
        <span><strong>Qubes</strong> OS</span>
      </a>
    </div>
    <div id="navbar" class="navbar-collapse collapse">
      <ul class="nav nav-justified">
        
        <li><a href="../intro/index.html">Intro</a></li>
        
        <li><a href="../downloads/index.html">Downloads</a></li>
        
        <li><a href="index.html">Docs</a></li>
        
        <li><a href="../news/index.html">News</a></li>
        
        <li><a href="../team/index.html">Team</a></li>
        
        <li><a href="../donate/index.html">Donate</a></li>
        
      </ul>
    </div><!--/.nav-collapse -->
  </div>
</nav>

      <div class="container">
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        <h1 class="more-top add-left outer-heading">
          <a href="index.html#user-documentation" class="heading-link">
            <i class="fa fa-book"></i>
              User Documentation
          </a>
        </h1>
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        
        <div class="more-bottom white-box page-content">
  <div class="row">
    <div class="col-lg-3 col-md-3 text-center">
      <div class="page-source-side remove-bottom">
        <h3 class="remove-bottom">Contents</h3>
      </div>
      <a id="toc-button" data-toggle="collapse" href="torvm#page-toc" class="btn btn-primary btn-block" role="button">Contents</a>
      <div id="page-toc" class="collapse in"></div>
      <div class="page-source-side">
        <a href="index.html"
           class="btn btn-primary btn-block"
           title="Go to Documentation">
          <span class="fa fa-fw fa-book"></span> Documentation
        </a><br>
        <a href="doc-guidelines/index.html"
           class="page-source-link btn btn-default btn-block"
           title="Improve the Docs"
           target="_blank">
          <span class="fa fa-fw fa-pencil"></span> Improve the Docs
        </a><br>
        <a href="https://github.com/QubesOS/qubes-doc/blob/master/privacy/torvm.md"
           class="page-source-link btn btn-default btn-block"
           title="View page source"
           target="_blank">
          <span class="fa fa-fw fa-code"></span> View Page Source
        </a><br>
        <a href="https://github.com/QubesOS/qubes-doc/edit/master/privacy/torvm.md"
           class="page-source-link btn btn-default btn-block"
           title="Edit this page"
           target="_blank">
          <span class="fa fa-fw fa-code-fork"></span> Edit This Page
        </a><br>
        <a href="reporting-bugs/index.html"
           class="page-source-link btn btn-default btn-block"
           title="Report a Bug"
           target="_blank">
          <span class="fa fa-fw fa-bug"></span> Report a Bug
        </a><br>
        <a href="../support/index.html"
           class="page-source-link btn btn-default btn-block"
           title="Help & Support"
           target="_blank">
          <span class="fa fa-fw fa-life-ring"></span> Help & Support
        </a><br>
        <a href="../donate/index.html"
           class="page-source-link btn btn-default btn-block"
           title="Make a Donation"
           target="_blank">
          <span class="fa fa-fw fa-heart"></span> Make a Donation
        </a>
      </div>
    </div>
    <div class="toc-button-spacer more-bottom"></div>
    <div class="col-lg-9 col-md-9 col-sm-12 page-content-right">
      <article id="doc-content" class="post-content">
        <h2 id="known-issues">Known issues:</h2>

<ul>
  <li><a href="https://groups.google.com/d/msg/qubes-users/fyBVmxIpbSs/R5mxUcIEZAQJ">Service doesn’t start without (even empty) user torrc</a></li>
</ul>

<h1 id="qubes-torvm-qubes-tor">Qubes TorVM (qubes-tor)</h1>

<p>Qubes TorVM is a deprecated ProxyVM service that provides torified networking to
all its clients. <strong>If you are interested in TorVM, you will find the
<a href="privacy/whonix/index.html">Whonix implementation in Qubes</a> a
more usable and robust solution for creating a torifying traffic proxy.</strong></p>

<p>By default, any AppVM using the TorVM as its NetVM will be fully torified, so
even applications that are not Tor aware will be unable to access the outside
network directly.</p>

<p>Moreover, AppVMs running behind a TorVM are not able to access globally
identifying information (IP address and MAC address).</p>

<p>Due to the nature of the Tor network, only IPv4 TCP and DNS traffic is allowed.
All non-DNS UDP and IPv6 traffic is silently dropped.</p>

<p>See <a href="https://blog.invisiblethings.org/2011/09/28/playing-with-qubes-networking-for-fun.html">this article</a> for a description of the concept, architecture, and the original implementation.</p>

<h2 id="warning--disclaimer">Warning + Disclaimer</h2>

<ol>
  <li>
    <p>Qubes TorVM is produced independently from the Tor(R) anonymity software and
carries no guarantee from The Tor Project about quality, suitability or
anything else.</p>
  </li>
  <li>
    <p>Qubes TorVM is not a magic anonymizing solution. Protecting your identity
requires a change in behavior. Read the “Protecting Anonymity” section
below.</p>
  </li>
  <li>
    <p>Traffic originating from the TorVM itself <strong>IS NOT</strong> routed through Tor.
This includes system updates to the TorVM. Only traffic from VMs using TorVM
as their NetVM is torified.</p>
  </li>
</ol>

<h1 id="installation">Installation</h1>

<ol>
  <li>
    <p><em>(Optional)</em> If you want to use a separate vm template for your TorVM</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> qvm-clone fedora-23 fedora-23-tor
</code></pre></div>    </div>
  </li>
  <li>
    <p>In dom0, create a proxy vm and disable unnecessary services and enable qubes-tor</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> qvm-create -p torvm
 qvm-service torvm -d qubes-netwatcher
 qvm-service torvm -d qubes-firewall
 qvm-service torvm -e qubes-tor

 # if you  created a new template in the previous step
 qvm-prefs torvm -s template fedora-23-tor
</code></pre></div>    </div>
  </li>
  <li>
    <p>From your TemplateVM, install the torproject Fedora repo</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> sudo yum install qubes-tor-repo
</code></pre></div>    </div>
  </li>
  <li>
    <p>Then, in the template, install the TorVM init scripts</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> sudo yum install qubes-tor
</code></pre></div>    </div>
  </li>
  <li>
    <p>Configure an AppVM to use TorVM as its NetVM (for example a vm named anon-web)</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> qvm-prefs -s anon-web netvm torvm
 ... repeat for any other AppVMs you want torified...
</code></pre></div>    </div>
  </li>
  <li>Shutdown the TemplateVM.</li>
  <li>
    <p>Set the prefs of your TorVM to use the default sys-net or sys-firewall as its NetVM</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> qvm-prefs -s torvm netvm sys-net
</code></pre></div>    </div>
  </li>
  <li>Start the TorVM and any AppVM you have configured to be route through the TorVM</li>
  <li>From the AppVMs, verify torified connectivity, e.g. by visiting
<code class="highlighter-rouge">https://check.torproject.org</code>.</li>
</ol>

<h3 id="troubleshooting">Troubleshooting</h3>

<ol>
  <li>
    <p>Check if the qubes-tor service is running (on the torvm)</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> [user@torvm] $ sudo service qubes-tor status
</code></pre></div>    </div>
  </li>
  <li>
    <p>Tor logs to syslog, so to view messages use</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> [user@torvm] $ sudo grep Tor /var/log/messages
</code></pre></div>    </div>
  </li>
  <li>
    <p>Restart the qubes-tor service (and repeat 1-2)</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> [user@torvm] $ sudo service qubes-tor restart
</code></pre></div>    </div>
  </li>
  <li>
    <p>You may need to manually create the private data directory and set its permissions:</p>

    <div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code> [user@torvm] $ sudo mkdir /rw/usrlocal/lib/qubes-tor
 [user@torvm] $ sudo chown user:user /rw/usrlocal/lib/qubes-tor
</code></pre></div>    </div>
  </li>
</ol>

<h1 id="usage">Usage</h1>

<p>Applications should “just work” behind a TorVM, however there are some steps
you can take to protect anonymity and increase performance.</p>

<h2 id="protecting-anonymity">Protecting Anonymity</h2>

<p>The TorVM only purports to prevent the leaking of two identifiers:</p>

<ol>
  <li>WAN IP Address</li>
  <li>NIC MAC Address</li>
</ol>

<p>This is accomplished through transparent TCP and transparent DNS proxying by
the TorVM.</p>

<p>The TorVM cannot anonymize information stored or transmitted from your AppVMs
behind the TorVM.</p>

<p><em>Non-comprehensive</em> list of identifiers TorVM does not protect:</p>

<ul>
  <li>Time zone</li>
  <li>User names and real name</li>
  <li>Name+version of any client (e.g. IRC leaks name+version through CTCP)</li>
  <li>Metadata in files (e.g., exif data in images, author name in PDFs)</li>
  <li>License keys of non-free software</li>
</ul>

<h3 id="further-reading">Further Reading</h3>

<ul>
  <li><a href="https://trac.torproject.org/projects/tor/wiki/doc/TorifyHOWTO#Protocolleaks">Information on protocol leaks</a></li>
  <li><a href="https://www.torproject.org/download/download-easy.html.en#warning">Official Tor Usage Warning</a></li>
  <li><a href="https://www.torproject.org/projects/torbrowser/design/">Tor Browser Design</a></li>
</ul>

<h2 id="how-to-use-tor-browser-behind-torvm">How to use Tor Browser behind TorVM</h2>

<ol>
  <li>In a clean VM, <a href="https://www.torproject.org/download/download-easy.html">download Tor Browser from the Tor Project</a>.</li>
  <li><a href="https://www.torproject.org/docs/verifying-signatures.html">Verify the PGP signature</a>.</li>
  <li>Copy/move the Tor Browser archive into your AnonVM (i.e., the AppVM which has your TorVM as its netvm).</li>
  <li>Unpack the Tor Browser archive into your home directory.</li>
  <li>In dom0, right click the KDE Application Launcher Menu (AKA “Start Menu”) and left click “Edit Applications…”</li>
  <li>In the KDE Menu Editor, find your AnonVM’s group and create a new item (or make a copy of an existing item).</li>
  <li>Edit the following fields on the “General” tab:
    <ul>
      <li>Name: <code class="highlighter-rouge">my-new-anonvm: Tor Browser</code></li>
      <li>Command: <code class="highlighter-rouge">qvm-run -q --tray -a my-new-anonvm 'TOR_SKIP_LAUNCH=1 TOR_SKIP_CONTROLPORTTEST=1 TOR_SOCKS_PORT=9050 TOR_SOCKS_HOST=1.2.3.4 ./tor-browser_en-US/Browser/start-tor-browser'</code>
        <ul>
          <li>Replace <code class="highlighter-rouge">my-new-anonvm</code> with the name of your AnonVM.</li>
          <li>Replace <code class="highlighter-rouge">1.2.3.4</code> with your TorVM’s internal Qubes IP address, which can be viewed in Qubes VM Manager by clicking “View” –&gt; “IP” or by running <code class="highlighter-rouge">qvm-ls -n</code> in dom0.</li>
          <li>Replace <code class="highlighter-rouge">en-US</code> with your locale ID, if different.</li>
        </ul>
      </li>
    </ul>
  </li>
  <li>Click “Save” in the KDE Menu Editor.</li>
</ol>

<p>Tor Browser should now work correctly in your AnonVM when launched via the shortcut you just created.</p>

<p><strong>Note:</strong> If you want to use Tor Browser in a <a href="DisposableVms/index.html">DispVM</a>, the steps are the same as above, except you should copy the Tor Browser directory into your DVM template, <a href="UserDoc/DispVMCustomization/index.html">regenerate the DVM template</a>, then use the following command in your KDE menu entry:</p>

<p><code class="highlighter-rouge">sh -c 'echo TOR_SKIP_LAUNCH=1 TOR_SKIP_CONTROLPORTTEST=1 TOR_SOCKS_PORT=9050 TOR_SOCKS_HOST=1.2.3.4 ./tor-browser_en-US/Browser/start-tor-browser | /usr/lib/qubes/qfile-daemon-dvm qubes.VMShell dom0 DEFAULT red'</code></p>

<p>(Replace <code class="highlighter-rouge">1.2.3.4</code> and <code class="highlighter-rouge">en-US</code> as indicated above.)</p>

<h2 id="performance">Performance</h2>

<p>In order to mitigate identity correlation TorVM makes use of Tor’s new <a href="https://gitweb.torproject.org/torspec.git/blob/HEAD:/proposals/171-separate-streams.txt">stream
isolation feature</a>. Read “Threat Model” below for more
information.</p>

<p>However, this isn’t desirable in all situations, particularly web browsing.
These days loading a single web page requires fetching resources (images,
javascript, css) from a dozen or more remote sources. Moreover, the use of
IsolateDestAddr in a modern web browser may create very uncommon HTTP behavior
patterns, that could ease fingerprinting.</p>

<p>Additionally, you might have some apps that you want to ensure always share a
Tor circuit or always get their own.</p>

<p>For these reasons TorVM ships with two open SOCKS5 ports that provide Tor
access with different stream isolation settings:</p>

<ul>
  <li>Port 9050 - Isolates by SOCKS Auth and client address only<br />
            Each AppVM gets its own circuit, and each app using a unique SOCKS
            user/pass gets its own circuit</li>
  <li>Port 9049 - Isolates client + destination port, address, and by SOCKS Auth
            Same as default settings listed above, but additionally traffic
            is isolated based on destination port and destination address.</li>
</ul>

<h2 id="custom-tor-configuration">Custom Tor Configuration</h2>

<p>Default tor settings are found in the following file and are the same across
all TorVMs.</p>

<div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code>  /usr/lib/qubes-tor/torrc
</code></pre></div></div>

<p>You can override these settings in your TorVM, or provide your own custom
settings by appending them to:</p>

<div class="highlighter-rouge"><div class="highlight"><pre class="highlight"><code>  /rw/config/qubes-tor/torrc
</code></pre></div></div>

<p>For information on tor configuration settings <code class="highlighter-rouge">man tor</code></p>

<h1 id="threat-model">Threat Model</h1>

<p>TorVM assumes the same Adversary Model as <a href="https://www.torproject.org/projects/torbrowser/design/#adversary">TorBrowser</a>, but does
not, by itself, have the same security and privacy requirements.</p>

<h2 id="proxy-obedience">Proxy Obedience</h2>

<p>The primary security requirement of TorVM is <em>Proxy Obedience</em>.</p>

<p>Client AppVMs MUST NOT bypass the Tor network and access the local physical
network, internal Qubes network, or the external physical network.</p>

<p>Proxy Obedience is assured through the following:</p>

<ol>
  <li>All TCP traffic from client VMs is routed through Tor</li>
  <li>All DNS traffic from client VMs is routed through Tor</li>
  <li>All non-DNS UDP traffic from client VMs is dropped</li>
  <li>Reliance on the <a href="QubesNet/index.html">Qubes OS network model</a> to enforce isolation</li>
</ol>

<h2 id="mitigate-identity-correlation">Mitigate Identity Correlation</h2>

<p>TorVM SHOULD prevent identity correlation among network services.</p>

<p>Without stream isolation, all traffic from different activities or “identities”
in different applications (e.g., web browser, IRC, email) end up being routed
through the same tor circuit. An adversary could correlate this activity to a
single pseudonym.</p>

<p>TorVM uses the default stream isolation settings for transparently torified
traffic. While more paranoid options are available, they are not enabled by
default because they decrease performance and in most cases don’t help
anonymity (see <a href="https://lists.torproject.org/pipermail/tor-talk/2012-May/024403.html">this tor-talk thread</a>)</p>

<p>By default TorVM does not use the most paranoid stream isolation settings for
transparently torified traffic due to performance concerns. By default TorVM
ensures that each AppVM will use a separate tor circuit (<code class="highlighter-rouge">IsolateClientAddr</code>).</p>

<p>For more paranoid use cases the SOCKS proxy port 9049 is provided that has all
stream isolation options enabled. User applications will require manual
configuration to use this socks port.</p>

<h1 id="future-work">Future Work</h1>
<ul>
  <li>Integrate Vidalia</li>
  <li>Create Tor Browser packages w/out bundled tor</li>
  <li>Use local DNS cache to speedup queries (pdnsd)</li>
  <li>Support arbitrary <a href="https://tails.boum.org/todo/support_arbitrary_dns_queries/">DNS queries</a></li>
  <li>Fix Tor’s openssl complaint</li>
  <li>Support custom firewall rules (to support running a relay)</li>
</ul>

<h1 id="acknowledgements">Acknowledgements</h1>

<p>Qubes TorVM is inspired by much of the previous work done in this area of
transparent torified solutions. Notably the following:</p>

<ul>
  <li><a href="mailto:adrelanos@riseup.net">Patrick Schleizer</a> for his work on <a href="https://www.whonix.org">Whonix</a></li>
  <li>The <a href="https://trac.torproject.org/projects/tor/wiki/doc/TorifyHOWTO">Tor Project wiki</a></li>
  <li>And the many people who contributed to discussions on <a href="https://lists.torproject.org/pipermail/tor-talk/">tor-talk</a></li>
</ul>


      </article>
    <br>
    </div>
  </div>
  <div class="page-source-bottom">
        <a href="index.html"
           class="btn btn-primary btn-block"
           title="Go to Documentation">
          <span class="fa fa-fw fa-book"></span> Documentation
        </a><br>
        <a href="doc-guidelines/index.html"
           class="page-source-link btn btn-default btn-block"
           title="Improve the Docs"
           target="_blank">
          <span class="fa fa-fw fa-pencil"></span> Improve the Docs
        </a><br>
        <a href="https://github.com/QubesOS/qubes-doc/blob/master/privacy/torvm.md"
           class="page-source-link btn btn-default btn-block"
           title="View page source"
           target="_blank">
          <span class="fa fa-fw fa-code"></span> View Page Source
        </a><br>
        <a href="https://github.com/QubesOS/qubes-doc/edit/master/privacy/torvm.md"
           class="page-source-link btn btn-default btn-block"
           title="Edit this page"
           target="_blank">
          <span class="fa fa-fw fa-code-fork"></span> Edit This Page
        </a><br>
        <a href="reporting-bugs/index.html"
           class="page-source-link btn btn-default btn-block"
           title="Report a Bug"
           target="_blank">
          <span class="fa fa-fw fa-bug"></span> Report a Bug
        </a><br>
        <a href="../support/index.html"
           class="page-source-link btn btn-default btn-block"
           title="Help & Support"
           target="_blank">
          <span class="fa fa-fw fa-life-ring"></span> Help & Support
        </a><br>
        <a href="../donate/index.html"
           class="page-source-link btn btn-default btn-block"
           title="Make a Donation"
           target="_blank">
          <span class="fa fa-fw fa-heart"></span> Make a Donation
        </a>
  </div>
</div>
<footer>
  <div class="white-box more-bottom">
  <div class="row footer-search">
    <div class="col-lg-3 col-md-3 text-center">
      <h4 class="remove-bottom"><i class="fa fa-search"></i> Search Qubes-OS.org</h4>
    </div>
    <div class="col-lg-9 col-md-9 text-left">
      <form action="https://duckduckgo.com/" method="get">
        <div class="input-group">
          <input type="hidden" name="sites" value="https://www.qubes-os.org">
          <input type="text" class="form-control" name="q" placeholder="Using DuckDuckGo&hellip;">
          <span class="input-group-btn">
            <button class="btn btn-primary" type="submit">Go!</button>
          </span>
        </div><!-- /input-group -->
      </form>
    </div>
  </div>
  </div>
  <div class="row footer-nav">
    
    <div class="col-lg-2 col-md-2">
      <a href="../intro/index.html"><h5 class="text-left add-bottom">Intro </h5></a>
      <ul class="list-unstyled">
        
        <li><a href="../intro/index.html">What is Qubes OS?</a></li>
        
        <li><a href="../faq/index.html">FAQ</a></li>
        
        <li><a href="../video-tours/index.html">Video Tours</a></li>
        
        <li><a href="../experts/index.html">From the Experts</a></li>
        
        <li><a href="../screenshots/index.html">Screenshots</a></li>
        
        <li><a href="../getting-started/index.html">Getting Started</a></li>
        
        <li><a href="../support/index.html">Help and Support</a></li>
        
        <li><a href="../code-of-conduct/index.html">Code of Conduct</a></li>
        
        <li><a href="../security/index.html">Security Center</a></li>
        
        <li><a href="architecture/index.html">OS Architecture</a></li>
        
      </ul>
    </div>
    
    <div class="col-lg-2 col-md-2">
      <a href="../downloads/index.html"><h5 class="text-left add-bottom">Downloads </h5></a>
      <ul class="list-unstyled">
        
        <li><a href="system-requirements/index.html">System Requirements</a></li>
        
        <li><a href="certified-hardware/index.html">Certified Hardware</a></li>
        
        <li><a href="../hcl/index.html">Compatibility List</a></li>
        
        <li><a href="installation-guide/index.html">Installation Guide</a></li>
        
        <li><a href="../security/verifying-signatures/index.html">Verifying Signatures</a></li>
        
        <li><a href="supported-versions/index.html">Supported Versions</a></li>
        
        <li><a href="version-scheme/index.html">Version Scheme</a></li>
        
        <li><a href="source-code/index.html">Source Code</a></li>
        
        <li><a href="license/index.html">Software License</a></li>
        
        <li><a href="../downloads/index.html#mirrors">Download Mirrors</a></li>
        
      </ul>
    </div>
    
    <div class="col-lg-2 col-md-2">
      <a href="index.html"><h5 class="text-left add-bottom">Docs </h5></a>
      <ul class="list-unstyled">
        
        <li><a href="index.html#the-basics">The Basics</a></li>
        
        <li><a href="index.html#security-information">Security Information</a></li>
        
        <li><a href="index.html#choosing-your-hardware">Choosing Hardware</a></li>
        
        <li><a href="index.html#installing--upgrading-qubes">Installing Qubes</a></li>
        
        <li><a href="index.html#common-tasks">Common Tasks</a></li>
        
        <li><a href="index.html#managing-operating-systems-within-qubes">Managing OSes</a></li>
        
        <li><a href="index.html#security-guides">Security Guides</a></li>
        
        <li><a href="index.html#privacy-guides">Privacy Guides</a></li>
        
        <li><a href="index.html#troubleshooting">Troubleshooting</a></li>
        
        <li><a href="index.html#developer-documentation">Developer Docs</a></li>
        
      </ul>
    </div>
    
    <div class="col-lg-2 col-md-2">
      <a href="../news/index.html"><h5 class="text-left add-bottom">News </h5></a>
      <ul class="list-unstyled">
        
        <li><a href="../news/categories/index.html#announcements">Announcements</a></li>
        
        <li><a href="../news/categories/index.html#articles">Articles</a></li>
        
        <li><a href="../news/categories/index.html#press">Press</a></li>
        
        <li><a href="../news/categories/index.html#talks">Talks</a></li>
        
        <li><a href="../research/index.html">Research</a></li>
        
        <li><a href="../statistics/index.html">Statistics</a></li>
        
        <li><a href="https://github.com/QubesOS">GitHub</a></li>
        
        <li><a href="https://twitter.com/QubesOS">Twitter</a></li>
        
        <li><a href="https://www.reddit.com/r/Qubes/">Reddit</a></li>
        
        <li><a href="https://www.facebook.com/QubesOS">Facebook</a></li>
        
      </ul>
    </div>
    
    <div class="col-lg-2 col-md-2">
      <a href="../team/index.html"><h5 class="text-left add-bottom">Team </h5></a>
      <ul class="list-unstyled">
        
        <li><a href="../security/index.html">Report a Security Issue</a></li>
        
        <li><a href="reporting-bugs/index.html">Report a Bug</a></li>
        
        <li><a href="mailto:press@qubes-os.org">Press Inquiries</a></li>
        
        <li><a href="mailto:business@qubes-os.org">Business Inquiries</a></li>
        
      </ul>
    </div>
    
    <div class="col-lg-2 col-md-2">
      <a href="../donate/index.html"><h5 class="text-left add-bottom">Donate <i class="fa fa-heart"></i></h5></a>
      <ul class="list-unstyled">
        
        <li><a href="../donate/index.html">How to donate</a></li>
        
        <li><a href="../partners/index.html">Partners</a></li>
        
        <li><a href="contributing/index.html">Contributing</a></li>
        
      </ul>
    </div>
    
  </div>
  <div class="row footer-nav text-center more-top add-bottom">
    <div class="footer-logo more-bottom">
      <a href="../index.html"><img src="../attachment/icons/logo-outline-small.svg" alt="Qubes"><strong>Qubes</strong> OS</a>
    </div>
    <p>
      &#169; <script type="text/javascript">
               document.write(new Date().getFullYear());
             </script><noscript>2019</noscript> The Qubes OS Project and others<br>
      <a href="https://github.com/QubesOS/qubesos.github.io">Website Source Code</a> |
      <a href="reporting-bugs/index.html">Report a Problem</a> |
      <a href="../privacy/index.html">Privacy Policy</a> |
      <a href="../terms/index.html">Terms of Use</a> |
      <a href="../sitemap.xml">Sitemap</a>
    </p>
  </div>
</footer>

<script src="../js/jquery-2.2.2.min.js"></script>
<script src="../js/bootstrap.min.js"></script>



<script src="../js/jquery.toc.js"></script>
<script>
$(document).ready(function() {
  $('#doc-content').toc({
    renderIn: '#page-toc',
    anchorPrefix: 'tocAnchor-', // the default prefix used for generated TOC elements IDs
    showAlways: true, //Show TOC also if only one H1 is present on page, the TOC is never show if no H1s are found on page
    saveShowStatus: false, // Save the collapse status using a cookie (see dependecies for further details)
    contentsText: 'Contents', // The label text shown for Content, you can localize passing another string
    hideText: 'hide', // The label text shown for hide button, you can localize passing another string
    showText: 'show' // The label text shown for show button, you can localize passing another string
  })
})
</script>
<script src="../js/anchor.min.js"></script>
<script>
  anchors.add();
</script>

      </div>
  </body>
</html>
