One offline qube for writing. It runs only LibreOffice Writer. This is
where Bob does all of his writing. This window is usually open side-by-side
with another window containing research or material from a source.
Multiple email qubes. One is for receiving emails from the general
public. Another is for emailing his editor and colleagues. Both are based on
a minimal template (https://www.qubes-os.org/doc/templates/minimal/) with Thunderbird installed.
He’s configured both to open all attachments in
disposables (www.qubes-os.org/doc/how…posables) that are offline in case an
attachment contains a beacon that tries to phone home.
Whonix qubes. He has the standard sys-whonix service qube for providing
Torified network access, and he uses disposable anon-workstation app qubes
for using Tor Browser to do research on stories he’s writing. Since the topic
is often of a sensitive nature and might implicate powerful individuals, it’s
important that he be able to conduct this research with a degree of
anonymity. He doesn’t want the subjects of his investigation to know that
he’s looking into them. He also doesn’t want his network requests being
traced back to his work or home IP addresses. Whonix helps with both of these
concerns. He also has another Whonix-based disposable template for receiving
tips anonymously via Tor, since some high-risk whistleblowers he’s interacted
with have said that they can’t take a chance with any other form of
communication.
Two qubes for
Signal (github.com/Qubes-C…ignal.md).
Bob has two Signal app qubes (both on the same template in which the Signal
desktop app is installed). One is linked to his own mobile number for
communicating with co-workers and other known, trusted contacts. The other is
a public number that serves as an additional way for sources to reach him
confidentially. This is especially useful for individuals who don’t use Tor
but for whom unencrypted communication could be dangerous.
Several data vaults. When someone sends Bob material that turns out to be
useful, or when he comes across useful material while doing his own research,
he stores a copy in a completely offline, network-isolated vault qube. Most
of these files are PDFs and images, though some are audio files, videos, and
text files. Since most of them are from unknown or untrusted sources, Bob
isn’t sure if it would be safe to put them all in the same vault, so he makes
different vaults (usually one for each story or topic) just in case. This has
the side benefit of helping to keep things organized.
A VPN
qube (github.com/Qubes-C…n/vpn.md)
and associated qubes for accessing work resources. The servers at work can
only be accessed from the organization’s network, so Bob has certain qubes
that are connected to a VPN qube so that he can upload his work and access
anything he needs on the local network when he’s not physically there.
A password manager vault. Bob stores all of his login credentials in the
default password manager that came with his offline vault qube. He securely
copies and pastes (www.qubes-os.org/doc/how…ste-text) them into other qubes as
needed.
A colleague helped Bob set up his Qubes system initially and showed him how to
use it. Since Bob’s workflow is pretty consistent and straightforward, the way
his qubes are organized doesn’t change much, and this is just fine by him. His
colleague told him to remember a few simple rules: Don’t copy or move
text (www.qubes-os.org/doc/how…ste-text) or
files (www.qubes-os.org/doc/how…ve-files) from less trusted to more trusted
qubes; update (https://www.qubes-os.org/doc/how-to-update/) your system when prompted; and make
regular backups (www.qubes-os.org/doc/how…-migrate). Bob doesn’t have