AWAMARKET

Home//Client//C6 Whonix

C6Awazon Market // record C6

C6 // One machine to a gateway and a workstation

The strongest technical arrangement documented here, and the one most often installed by people whose actual problem was in the address group.

Awazon Market // onion addresses

The three strings below open the same market. The same account, the same balance, the same open orders sit behind each one. Copy a string, paste it into Tor Browser, and read the last six characters in the address bar before you type a password.

  • awazonozc4jwyrveu4473igv5ldt2hnccl2s7lerm2z27cvrc22e4uyd.onion
  • awazonth6ocz5cyos63czmhtsglqr7ydkdcc4lopux7nxbauoo2qmvyd.onion
  • awazonvaqbgkhirejon6qnlxcjibrhkqhzh2xb2lclc6t67vxhlvjkyd.onion

NOTHING HERE IS RANKED. THE ORDER IS THE ORDER THEY WERE WRITTEN IN.

Baseline
One system running both your applications and your Tor client.
Substitution
Two virtual machines. A gateway that runs Tor and touches the network, and a workstation that has no other route out.
What moves
The workstation cannot discover your real address even if something on it is compromised, because it has never been able to see one. Leaks that go around Tor stop being possible rather than being unlikely.
Does not move
The circuit itself, the market, the addresses, and the correctness of the string you paste into the workstation browser.
Cost
Real setup effort, a machine with enough memory to run two systems, ongoing updates for both, and a permanently more complicated session.
Verdict
Only if your threat model includes the workstation being compromised. For most readers that is a larger claim than the situation supports.

IWhat the split prevents

On a single machine, everything shares one network stack. A tool that ignores the proxy, an application that resolves a name directly, or a piece of malware that opens its own connection all reach the internet as you. This is not exotic; the ordinary version is a misconfigured client leaking a name lookup, which is enough on its own.

The gateway model removes the possibility rather than reducing it. The workstation has one route out and that route is Tor. Software running there cannot see your address, so it cannot report it, regardless of intent or of a bug in the browser.

IIWhonix against Tails

PropertyTailsWhonix
Leaves traces on the machineNoYes, it is installed
Leak proof by architectureYesYes
Survives a compromise of the browserPartlyYes, the address is not present to leak
Effort to start a sessionRebootStart two machines
Keeps your setup between sessionsOnly with persistenceYes, naturally

IIIWho this is actually for

The honest answer is: people whose plausible worst case is a compromised workstation, and who can say why that is plausible for them. Somebody who opens files sent by strangers, or runs unusual software alongside the session, has a case. Somebody who reads a catalogue and places an order does not have the same one, and the effort spent here would be better spent on the two manual checks in the address group.

IVThe failure mode of installing it anyway

A setup this involved produces a strong sense of having solved the problem. That sense is spent later on the decisions the architecture cannot reach: a link from a chat, a password reused from another site, a transfer sent while annoyed. The pattern is described in the method and it is the reason several verdicts on this site are stricter than the technology alone would suggest.

IN ONE LINE

It makes a leak architecturally impossible. It has no opinion about the fifty six characters you typed into it.