Live data from Hacker News

Tails 3.0 Released

tails.boum.org

41–50 of 79 posts

Re: Tails 3.0 Released

#41
post #28

Earlier quoted context omitted.

I love Chrome but I'm sure in some way it reports what I'm doing to Google. Why not just use Firefox?

Whonix is an OS, a modern browser of your choice could be firefox. Whonix runs TOR in a separate VM from your browser/user space. The idea is that even if you get hacked they don't get your IP address since they can only access the internet through the gateway VM that pushes all traffic through TOR.

Is there any reason not to use whonix?

Re: Tails 3.0 Released

#42
post #18

Earlier quoted context omitted.

do you suggest I should be running Firefox in Tails?

The safer solution is to run the modern browser of your choice (probably chrome) in an isolated VM routed through a torified gateway. Hardware isolation would of course be preferable. If you're using Tails you'd probably be much better off using Whonix instead. With Tails, an attacker capable of breaking your browser will m̶o̶s̶t̶ ̶l̶i̶k̶e̶l̶y̶ definitely also be capable of easily grabbing your IP address.

many things wrong with tails but it is not the browsers fault anyone breaking firefox will have an extensive hardware profile and easily determine your entry node, bssid, mac and by running traffic correlation (3-letter now knows the entry) determine exactly who you are connecting from and all this without a root exploit just by breaking the TBrowser

nothing new really has been there since the beginning which is why tails doesn't even come close to whonix/qubesos which make this inherent insecurity a lot harder to exploit

Re: Tails 3.0 Released

#43
post #2

Those two changes seem particularly important: * Tails 3.0 works on 64-bit computers only and not on 32-bit computers anymore. Dropping hardware support, even for a small portion of our user base, is always a hard decision to make but being 64-bit only has important security and reliability benefits. For example, to protect against some types of security exploits, support for the NX bit is compulsory and most binarie…

The 32-bit computers are the only thing available to lots of poor people or those just relying on other people's computers. People's teenagers, people using libraries, workers with legacy systems, and Internet cafes come to mind. Dropping it is a mistake if both could be supported. If it was lack of contributions or funding, I can understand the perspective of focusing on most secure one.

EDIT to add: Always remember with solutions like this that the adversary isn't always the NSA and so on. The Tor users' page lists all kinds of people who need help against foes with limited budgets or knowledge who might not be able to break Linux or Tor.

https://www.torproject.org/about/torusers.html.en

Re: Tails 3.0 Released

#44
post #41
post #28

Earlier quoted context omitted.

Whonix is an OS, a modern browser of your choice could be firefox. Whonix runs TOR in a separate VM from your browser/user space. The idea is that even if you get hacked they don't get your IP address since they can only access the internet through the gateway VM that pushes all traffic through TOR.

Is there any reason not to use whonix?

No.

Re: Tails 3.0 Released

#45
post #2

Those two changes seem particularly important: * Tails 3.0 works on 64-bit computers only and not on 32-bit computers anymore. Dropping hardware support, even for a small portion of our user base, is always a hard decision to make but being 64-bit only has important security and reliability benefits. For example, to protect against some types of security exploits, support for the NX bit is compulsory and most binarie…

I can't honestly say I've seen a 32bit computer in what must be nearly a decade now?

Re: Tails 3.0 Released

#46
post #31

Earlier quoted context omitted.

I don't think it is unreasonable to assume everyone already has a 64-bit capable PC considering the most recent mainstream 32-bit only CPU is 2004's first gen Prescott Pentium 4.

Intel early centrinos are not 64bit (Dothan / Banias) so are the initial Core / Core Duo CPUs (Yona). Intel didn't release a mobile 64bit CPU until 2006/7 with Core 2 Duo. Also the initial implementations of Intel64/EMT64 lack certain functions so even tho they technically support 64bit they might lack certain other features that are required by modern operating systems. So overall if you have a 10 year old laptop yo…

not even. If you have a netbook from 2009 the ubiquitous Intel Atom N270 that powered all of those was a single-core 32-bit CPU.

Re: Tails 3.0 Released

#47

Earlier quoted context omitted.

Thats not how it works in the real world. Reputation matters, for good reason. If 'Animats comments on tcp/ip you should trust it more than if I do. If 'tptacek comments on app security it's sort of the same (though I don't know he has anything named after him).

Making a claim while not explaining your reasoning is a sign of a low quality post that provides no actual contribution to the thread (and more often than not, of trolling) which justifies downvoting the post, no matter who the creator. Reputation matters if you want to buy something or if you want an expert opinion on a topic that you have no idea about. However I don't believe that reputation matters in a forum ful…

A warning from a knowledgeable person without explanation is still better than no warning at all. I hope tptacek just didn't have time to post an explanation; maybe he'll find the time later.

Re: Tails 3.0 Released

#48
I recently started using Tails so for security reasons coughbackdoorwindowsioscough,.. and found that it worked surprisely well. It has a disk utility, liber office, and the drivers even worked for my wireless dongle! Kudos to the Tails team!

Re: Tails 3.0 Released

#49
post #45
post #2

Those two changes seem particularly important: * Tails 3.0 works on 64-bit computers only and not on 32-bit computers anymore. Dropping hardware support, even for a small portion of our user base, is always a hard decision to make but being 64-bit only has important security and reliability benefits. For example, to protect against some types of security exploits, support for the NX bit is compulsory and most binarie…

I can't honestly say I've seen a 32bit computer in what must be nearly a decade now?

A lot of hosting companies run KVM/qemu/Xen or even UML with 32-bit guests by default. But yeah in terms of physical computers 64-bit has long been the default.

I remember upgrading from 32-bit to 64-bit in-place a few times, which is a bit fiddly but not impossible with Debian. I wrote up a couple of guides once upon a time, but right now I can just find this old wiki-page discussing the process:

https://wiki.debian.org/Migrate32To64Bit

Re: Tails 3.0 Released

#50
post #41
post #28

Earlier quoted context omitted.

Whonix is an OS, a modern browser of your choice could be firefox. Whonix runs TOR in a separate VM from your browser/user space. The idea is that even if you get hacked they don't get your IP address since they can only access the internet through the gateway VM that pushes all traffic through TOR.

Is there any reason not to use whonix?

What do I do if macOS is my host OS?
Post reply on HN