Boot Clock Randomization

Randomizes clock when systems boots.
Randomizes clock at boot time. Moves clock a few seconds and nanoseconds to past or future to prevent time based fingerprinting / linkablity.
Introduction[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Introduction
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Boot_Clock_Randomization#Introduction|Introduction]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Introduction](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Introduction)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Introduction](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Introduction)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Introduction]Introduction[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
The TimeSync page notes:
Using Boot Clock Randomization, i.e. after boot, the clock is set randomly between 0 and 180 seconds into the past or future. This is useful to enforce the design goal, that the host clock and VM clock should always slightly differ. It is also useful to obfuscate the clock when sdwdate itself is running, because naturally at this time, sdwdate hasn't finished. sdwdate runs after booting.
By randomly moving the system clock a few seconds (and nanseconds) in the past or future during boot, this enforces the design goal of a slightly different host clock and any VMs clock, even before secure timesync has succeeded. This prevents time-based fingerprinting and linkability issues, thereby improving security and privacy. [1]
For technical discussion on the Boot Clock Randomization design, see here. [2]
Log Inspection[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Log_Inspection
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Boot_Clock_Randomization#Log_Inspection|Log Inspection]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Log Inspection](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Log_Inspection)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Log Inspection](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Log_Inspection)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Log_Inspection]Log Inspection[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Click = Copy Copied to clipboard! sudo journalctl -b --no-pager -u bootclockrandomization
Disable[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Disable
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Boot_Clock_Randomization#Disable|Disable]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Disable](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Disable)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Disable](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Disable)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Disable]Disable[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Disabling of Boot Clock Randomization is discouraged because it is not usually required. However, it may be useful for offline (vault) VMs.
Run the following command. Note:
- Qubes: Use a StandaloneVM or a separate Template.
- Non-Qubes: No extra steps are required.
Click = Copy Copied to clipboard! sudo systemctl mask bootclockrandomization
Boot Clock Randomization will no longer occur after reboot.
See Also[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Boot_Clock_Randomization#See_Also
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Boot_Clock_Randomization#See_Also|See Also]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[See Also](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#See_Also)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[See Also](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#See_Also)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Boot_Clock_Randomization#See_Also]See Also[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
Footnotes[edit]
Copy or share this direct link!
Click = Copy
Copied to clipboard!
https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Footnotes
Click below ↴ = Copy to Clipboard
Click = Copy
Copied to clipboard!
[[Boot_Clock_Randomization#Footnotes|Footnotes]]
Copy as Wikitext
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Footnotes)
for Discourse, reddit, GitHub
Click = Copy
Copied to clipboard!
[Footnotes](https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Footnotes)
Copy as Markdown
Click = Copy
Copied to clipboard!
[url=https://www.kicksecure.com/wiki/Boot_Clock_Randomization#Footnotes]Footnotes[/url]
Copy as phpBB
Click below ↴ = Open social URL with share data
We don't use embedded scripts
This share button is completely self-hosted by this webserver. No scripts from any of the social networks are embedded on this webserver. See also
Social Share Button.
- ↑
https://github.com/Kicksecure/bootclockrandomization
- ↑ Notably, one recent change is the 0-5 second time window is no longer excluded in the process, as it was found to aid fingerprinting.


Copy as Wikitext

for Discourse, reddit, GitHub

Copy as Markdown

Copy as phpBB Click below ↴ = Open social URL with share data











We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!