bk99.de entertain the web since 1997

Oniux: Tor isolation with Linux namespaces

Summary

The Tor Project presents oniux, which starts any Linux program in isolated Tor network namespaces. oniux is Linux-specific and written in Rust. The tool combines Linux namespaces, Arti and onionmasq.

Ideas

  • A separate network namespace removes direct non-Tor network interfaces.
  • onionmasq routes traffic within the namespace to Arti.
  • The isolation also covers programs without SOCKS support.
  • Raw system calls no longer bypass a mere LD_PRELOAD redirection.
  • Kernel boundaries reduce configuration mistakes as a source of data leaks.

Insights

  • An enforced network architecture protects more reliably than voluntary proxy configuration.
  • Privacy tools need an explicitly formulated threat model.
  • Stronger isolation cannot eliminate functional side channels outside the network path.

Facts

  • The Tor post described oniux as new and experimental.

Recommendations

  • Test DNS, IPv6, local sockets and abort behaviour before sensitive use.
  • Use the current oniux documentation rather than outdated examples from the announcement.

References

Read the original article

Search the Web Archive