Live data from Hacker News

Tails 3.0 Released

tails.boum.org

21–30 of 79 posts

Re: Tails 3.0 Released

#22

Tails should use Devuan. It does not have systemd. What do you think? Translated automatically.

Assuming Debian Stretch still uses non-systemd networking configuration (which was the default case in 8 at least), or Tails switches back to it, systemd shouldn't impact what Tails tries to do in any way.

Re: Tails 3.0 Released

#23
post #12

For the love of Christ don't use Tor Browser. Every other modern browser, including mainline Firefox, is safer.

Is there an article or post I can read with more information? I was about to downvote before I noticed your username!

Re: Tails 3.0 Released

#24
post #10

https://tails.boum.org/news/version_3.0/index.en.html#news-v... says you should run "uname -m" under Tails to see if "your computer is 64-bit". How does that work? Does Tails automatically choose kernel version appropriate for your hardware, or what?

> How does that work? Does Tails automatically choose kernel version appropriate for your hardware, or what?

No, you run `uname -m` and then download the appropriate version of Tails (although it appears Tails 3.0 is only available on 64-bit now).

Re: Tails 3.0 Released

#25
post #18

Earlier quoted context omitted.

do you suggest I should be running Firefox in Tails?

The safer solution is to run the modern browser of your choice (probably chrome) in an isolated VM routed through a torified gateway. Hardware isolation would of course be preferable. If you're using Tails you'd probably be much better off using Whonix instead. With Tails, an attacker capable of breaking your browser will m̶o̶s̶t̶ ̶l̶i̶k̶e̶l̶y̶ definitely also be capable of easily grabbing your IP address.

I love Chrome but I'm sure in some way it reports what I'm doing to Google.

Why not just use Firefox?

Re: Tails 3.0 Released

#26
post #2

Those two changes seem particularly important: * Tails 3.0 works on 64-bit computers only and not on 32-bit computers anymore. Dropping hardware support, even for a small portion of our user base, is always a hard decision to make but being 64-bit only has important security and reliability benefits. For example, to protect against some types of security exploits, support for the NX bit is compulsory and most binarie…

Has there been any pure x86 processor in the last 10 year at all?

Early Intel Atom CPUs in 2008 were 32-bit only.

Re: Tails 3.0 Released

#27
post #18

Earlier quoted context omitted.

The safer solution is to run the modern browser of your choice (probably chrome) in an isolated VM routed through a torified gateway. Hardware isolation would of course be preferable. If you're using Tails you'd probably be much better off using Whonix instead. With Tails, an attacker capable of breaking your browser will m̶o̶s̶t̶ ̶l̶i̶k̶e̶l̶y̶ definitely also be capable of easily grabbing your IP address.

I love Chrome but I'm sure in some way it reports what I'm doing to Google. Why not just use Firefox?

That's indeed far better; specifically, Firefox ESR with all the calling-home features disabled in about:config and noscript with no whitelist on top of it.

Ideally you'd make sure the one responsible for going through tor isn't Firefox, too; IE at the very least a wrapper such as tsocks when running it or even better, a VM containing the browser and the entire VM connecting only through tor.

Re: Tails 3.0 Released

#28
post #18

Earlier quoted context omitted.

The safer solution is to run the modern browser of your choice (probably chrome) in an isolated VM routed through a torified gateway. Hardware isolation would of course be preferable. If you're using Tails you'd probably be much better off using Whonix instead. With Tails, an attacker capable of breaking your browser will m̶o̶s̶t̶ ̶l̶i̶k̶e̶l̶y̶ definitely also be capable of easily grabbing your IP address.

I love Chrome but I'm sure in some way it reports what I'm doing to Google. Why not just use Firefox?

Whonix is an OS, a modern browser of your choice could be firefox.

Whonix runs TOR in a separate VM from your browser/user space. The idea is that even if you get hacked they don't get your IP address since they can only access the internet through the gateway VM that pushes all traffic through TOR.

Re: Tails 3.0 Released

#29
post #2

Those two changes seem particularly important: * Tails 3.0 works on 64-bit computers only and not on 32-bit computers anymore. Dropping hardware support, even for a small portion of our user base, is always a hard decision to make but being 64-bit only has important security and reliability benefits. For example, to protect against some types of security exploits, support for the NX bit is compulsory and most binarie…

I understand thst 32-bit is inherently less secure than 64-bit but if you had no choice but to use a 32-bit computer, what would be the best way to provide yourself with similar security features?

I guess you could use an older version of Tails but I imagine this would become less and less secure as more and more vulnerabilities are found.

Re: Tails 3.0 Released

#30
post #12

For the love of Christ don't use Tor Browser. Every other modern browser, including mainline Firefox, is safer.

Is there an article or post I can read with more information? I was about to downvote before I noticed your username!

I think it's reasonable to downvote if his comment is just an assertion with no evidence. It shouldn't matter who he is or how high his karma is.
Post reply on HN