Running Tails inside a VM risk?

Trying to understand the risk of running Tails inside of a VM. While trying to learn this approach a warning message pops up stating that there is an additional risk of the host O/S being able to “see” the activity .

If a person is running Linux and a host VPN, what is the actual risk of running Tails inside a Linux VM? (I hope the question makes sense)

It just means your safety will heavily depend on which host OS you use and how it’s configured. Tails is primarily made to be ran as a live OS, Whonix is probably a better option for you if you must use VMs. They have much more extensive documentation on how to choose and configure your host OS and hypervisor, not to mention it’s actually made to work well in VMs.

Thank you for the response. Whonix seemed like it was complex and beyond my abilities.

More specific on the question: Just at a basic level, is this a relatively unsafe from spying configuration?

SecureBlue using Trivalent and a VPN like Proton or Mullvad on the base OS, then using a VM for Tails.

There is no sense in that setup.
Your hosts provides every service for hardware so it sees every data. If your host is compromised then tails inside vm will be compromised too.

Thank you. That is what I needed to know.

What are you even trying to achieving with that setup?

I am simply trying to learn. I saw recommendations for Tails and Tor. While reading about Tails, it shows instructions for using within a VM. My thought was that a VM was an isolated “O/S” so that anyone “snooping” on my system from the internet would only see that isolated VM and nothing more. Tails had a warning though and I wasn’t sure what kind of risk there would be from “external snooping” if my setup was SecureBlue, VPN and a VM running Tails.

That’s normally correct, but if your system host was already compromised as @john.982387487 said you can’t trust your VM isolation.
That’s why Tails best use is running live from a usbkey, bypassing the host OS.

If you trust your system and you’re just trying to isolate some online activity from your base OS and like mitigate the risk of opening dubious files any VM will be useful to sandbox some malware, even if it’s not bulletproof.
In this case Tails doesn’t add anything to your security.

It is more work than Tails but it’s not much more complex in my opinion, I’d encourage you to read through their guide on how to setup and use Whonix. Tails is easier to use but it’s generally best used as a live OS. It can be used as a VM, just be sure to read: Running Tails in a virtual machine

This could be a decent setup but keep 2 things in mind:

  • Using Tails as a live OS allows stronger separation between your ‘Tails activities’ and ‘non-Tails’ activities. Running it in a VM on your main PC opens you up to some risk. If your host is compromised or spying on you in any way, your ‘Tails activity’ is equally vulnerable and tied to your ‘normal activity’. I’d question why you’d use a Tails VM at all, running Tails as a live OS is usually better.
  • Your VM may not be tunneled through your VPN by default. Assuming you want to connect to a VPN before Tor (which usually isn’t strictly necessary but could be beneficial), you’ll want to research how to do so with your hypervisor. If you use Tails in a VM, you can check whether you’re connected to a VPN via the Unsafe Browser.

Virtual machines are useful for containing things like malware infections, but they do not help with anyone snooping on your internet traffic. That’s where VPNs, Tor, etc come in.

If you’re just using these tools to learn how they work, I’d either use Tails as a live OS or Whonix in a VM. Tails is easier but Whonix offers better security. I can’t really think of a scenario where I’d recommend using Tails in a VM. Even if you just wanted to play with it, the live OS doesn’t affect your host installation. Once you reboot your computer you’ll be right back in Secureblue.

Thank you for this info.

Thank you for taking so much time to provide this information. It helps me to understand.