Live data from Hacker News

Tails is a portable OS that protects against surveillance and censorship

tails.net

61–70 of 192 posts

Re: Tails is a portable OS that protects against surveillance and censorship

#61

Earlier quoted context omitted.

Tails has the entire OS as Tor connections only, an escape from the Tor browser would still be stuck in a Tor only OS. What information do you have to the contrary?

I mean yes and no. Assuming there was an exploit that broke out of the Firefox sand box you are correct that any connection is via tor. Though tails isn't 100% sure, you could chain a Firefox cve + user land to root and then turn off the to routing rules.

administrator/root is turned off by default, and even if the user turned it on during boot, they would still have to be tricked into approving or putting in their password again, am I missing something about the veracity of possible exploits?

Re: Tails is a portable OS that protects against surveillance and censorship

#63
post #52

Love Tails, but I haven't used it in ten years. I have had Tails and Qubes disposable VMs on my mind though. I switched off of Qubes last year to my own Alpine chroot with a hand crafted kernel and initrd that lives only in memory. I find turning off the computer when I'm finished and having it forget everything to be a very peaceful way to compute. I owe the internet a write up. I feel like ramfs for root filesystem…

Same here. Dont understand why not more ppl switched to alpine on the desktop. It is my daily driver. Plus LXD for stuff I must do (typically spawn ubuntu, etc.) my whole PDE (Personal Developer Environment) is within a container. Need python? Shell into (via dmenu) python container. All with complete neovim setup. Need a GUI? No problem. Spawn a container. My lxd profile is set up for this. Use chezmoi for heavy aut…

>why not more ppl switched to alpine

I think one reason might be musl and its compatibility.

Re: Tails is a portable OS that protects against surveillance and censorship

#64

If I were wanting do do secure tor browsing, I would use a liveUSB of ubuntu, running virtualbox, running vmware, running tor. On the host ubuntu, I would run a 2nd instance of virtualbox, running vmware, running Chrome. Networking will be set up so the Chrome inner VM can ssh to the tor VM. The tor VM can access only some whitelisted tor nodes. Now an adversary that uses a Chrome exploit needs to break out of Window…

It's a bit more secure if you use a proper write once DVD as well to read the live cd. It's a bit slower to boot but the best way to prevent persistence is always to make it virtually physically impossible by not having any physical storage mediums connected

Re: Tails is a portable OS that protects against surveillance and censorship

#65

Love Tails, but I haven't used it in ten years. I have had Tails and Qubes disposable VMs on my mind though. I switched off of Qubes last year to my own Alpine chroot with a hand crafted kernel and initrd that lives only in memory. I find turning off the computer when I'm finished and having it forget everything to be a very peaceful way to compute. I owe the internet a write up. I feel like ramfs for root filesystem…

In NixOs it's called Impermanence:

https://nixos.wiki/wiki/Impermanence

Also NixOs has absurd levels of control for upgrades, rollbacks, and control over the build and resulting files.

Re: Tails is a portable OS that protects against surveillance and censorship

#66
post #2

Would be curious to hear criticisms of Tails, if anyone has opinions about it. To be clear, I'm a fan of the product -- just wondering what the other side of the story is.

I'm wary about even Googling it because I swear I heard you are tracked in the US for even Googling it, or downloading it, or even reading on Wikipedia. It sounds laughable when I type it to be honest, but hey. I feel I have better hills to die on.

Re: Tails is a portable OS that protects against surveillance and censorship

#67
post #64

If I were wanting do do secure tor browsing, I would use a liveUSB of ubuntu, running virtualbox, running vmware, running tor. On the host ubuntu, I would run a 2nd instance of virtualbox, running vmware, running Chrome. Networking will be set up so the Chrome inner VM can ssh to the tor VM. The tor VM can access only some whitelisted tor nodes. Now an adversary that uses a Chrome exploit needs to break out of Window…

It's a bit more secure if you use a proper write once DVD as well to read the live cd. It's a bit slower to boot but the best way to prevent persistence is always to make it virtually physically impossible by not having any physical storage mediums connected

I think the main concern of most tor-users is that their real IP address (and hence location) is leaked.

For that, just a run-of-the-mill firefox exploit is all that is needed, and suddenly exploit code can do a wifi scan and get a very precise location.

Re: Tails is a portable OS that protects against surveillance and censorship

#68

Tails is one of those tools I always keep on me physically. Added it to my key ring 6 years ago , and I get use out of it at least twice a month. Also started using it as a recovery ISO. But my main use case is when I have to use a computer but don’t have mine around . Just pop the USB in and voila all the access I need and my data stored in the persistent partition.

[deleted]

Re: Tails is a portable OS that protects against surveillance and censorship

#69

Tails is one of those tools I always keep on me physically. Added it to my key ring 6 years ago , and I get use out of it at least twice a month. Also started using it as a recovery ISO. But my main use case is when I have to use a computer but don’t have mine around . Just pop the USB in and voila all the access I need and my data stored in the persistent partition.

Your use-case sounds like you could be using any other live distribution. Why did you choose Tails over Knoppix, Mint, Ubuntu, Fedora, ... ?

Re: Tails is a portable OS that protects against surveillance and censorship

#70

Earlier quoted context omitted.

All known law enforcement attacks against Tor have involved some kind of exploit (e.g., in Tor Browser) that creates a non-Tor connection to collect the user's IP. Tails does not protect against this. Whonix provides much stronger protection against practical, real-world attacks, since the entire operating system is forced through a Tor connection.

Tails has the entire OS as Tor connections only, an escape from the Tor browser would still be stuck in a Tor only OS. What information do you have to the contrary?

[deleted]
Post reply on HN