Because sd-proxy does not use a browser, there are only limited security benefits in the split VM architecture we currently use to access Tor. The complexity cost is significant. Post-beta, we should consider the advantages and disadvantages of different approaches:
- No change
- Using a single Whonix-based VM to run the proxy
- Using a single Debian-based VM to run the proxy and managing Tor access / Firewall rules ourselves
- Other options
Because
sd-proxydoes not use a browser, there are only limited security benefits in the split VM architecture we currently use to access Tor. The complexity cost is significant. Post-beta, we should consider the advantages and disadvantages of different approaches: