QubesOS fingerprint and YouTube

As a journalist working in a country at war, my privacy and security are essential to my safety. At the same time, my job requires me to upload videos to YouTube. I therefore have two questions about the privacy implications of using Qubes OS.

First question: browser fingerprinting and virtualization in Qubes OS

How identifiable are Qubes OS Whonix qubes and regular qubes from a browser-fingerprinting perspective? For example, wouldn’t the absence of a dedicated GPU potentially be unusual or detectable? Could WebGL and WebGPU expose characteristics of the virtualized GPU, particularly when combined with timing measurements and hardware-performance characteristics that may reveal that a browser is running inside a virtual machine?

How do browsers such as Firefox and Tor Browser mitigate these types of virtualization and hardware-fingerprinting techniques? More broadly, what would you consider the biggest privacy risks when using Qubes OS?

Second question: YouTube and virtualization detection

Can YouTube detect that a user is accessing the service from a virtualized environment and potentially treat the account or traffic differently because its systems suspect the user is a bot or automated account?

As a journalist, this could have a significant impact on my work. If YouTube’s algorithms were to reduce the visibility or distribution of my videos because they were uploaded from a virtualized environment, that would have real professional consequences. Is this a realistic concern, and if so, what aspects of using Qubes OS or virtualization would be most likely to trigger such systems?

I’m not the most knowledgable on this subject and don’t have meaningful experience with QubesOS. So I would suggest waiting for more responses that can hopefully offer more.

My expectation would be that you will be fingerprinted succesfully as using Qubes-Whonix.
But Whonix passes through Tor and I wouldn’t expect that fingerprint to be easily associated with your actual identity or location if you don’t otherwise reveal it.

I don’t expect Google to do anything about it other than forcing you to log in for anything associated with an account, but that might change if they have reason to believe you’re harvesting content.

I don’t know much about detecting the absence of a GPU or fingerprinting a VM. You should ask around on the forums of Qubes OS and Whonix. I expect people there to know more about this specific topic.

Still, I think that using Whonix inside Qubes OS isn’t different from using Whonix on any other host, since Whonix always runs as a VM pair (gateway + workstation). So you should look the same as any other Whonix (or perhaps any other Tor) user.

As always, us Whonix/Tor with caution (don’t change settings besides the security level, use default window size, don’t login to accounts, etc)

I use a Firefox addon called JShelter to detect and block browser fingerprinters. It’s not 100% fool-proof, but at least it alerts me when websites try to do shady stuff. And ever since I started using it, Clownflare and I aren’t friends any more. Disabling Javascript also helps, but breaks many websites, so it’s not a realistic solution, unfortunately. I recall Snowden wrote in his book, that he went wardriving for public WiFi access points when he needed anonymous internet access to avoid leaving tracks. But these events somewhat predate the quantity of fingerprinting found online today. If anything, you could use a disposable device (e.g. a used laptop) exclusively to upload sensitive stuff. Do not use it for anything else (do not cross-contaminate).

I’m not sure about your virtualization detection question though. I think it should be possible to detect it assuming the website has fingerprints of known virtualizers, and they collect individual identifiers to perform the fingerprint. But most fingerprinters that I’ve seen do generate a hash of the collected identifiers and sent that number back to the mothership, not the individual pieces. While I haven’t heard about websites caring about virtualization on the client side, in my personal opinion it’s the CDN’s (CF, PerimeterX, etc.) that would most likely have this technology developed.

If you set Tor/Mullvad Browser to “Safer” or higher, WebGL becomes “click-to-play”, which means it is disabled unless you allow it. WebGPU is disabled too.

By disabling, limiting or randomizing possible values. This is not specific to virtualization, but is relevant for all instances.

I doubt you will get a definitive answer for this, or what would trigger your account as supsicous. Using Tor/Mullvad Browser and a known VPN/TOR exit will most likely trigger something, but how they actually end up using this :person_shrugging: