Live data from Hacker News

Tails 3.0 Released

tails.boum.org

51–60 of 79 posts

Re: Tails 3.0 Released

#51

Tails should use Devuan. It does not have systemd. What do you think? Translated automatically.

Why is that important? Especially considering Tails has worked fine using systemd in their previous version based on Jessie. Additionally, Tails has used systemd's service namespacing functionality as part of a defense-in-depth strategy. Switching to Devuan makes little to no sense based on this track record.

Re: Tails 3.0 Released

#52
post #17

Earlier quoted context omitted.

I wonder if this will effect journalists and activists in parts of the world where old machines are still used (Africa, Middle East, parts of Asia). Not being able to make use of newer browser versions (without updating every time or taking the risk of using a persistent volume) could put them at greater risk.

Previous versions of Tails already had exuberant hardware requirements. I guess privacy is only for the rich.

Literally nothing is preventing you from creating your own secure Linux installation on any hardware you've got.

Re: Tails 3.0 Released

#53
post #17

Earlier quoted context omitted.

Previous versions of Tails already had exuberant hardware requirements. I guess privacy is only for the rich.

Literally nothing is preventing you from creating your own secure Linux installation on any hardware you've got.

Besides ones technical skills. Not all activists are knowledgeable enough to just roll their own distro.

Re: Tails 3.0 Released

#54
post #12

For the love of Christ don't use Tor Browser. Every other modern browser, including mainline Firefox, is safer.

since there's no reply, I'm guessing it's because Tor Browser is using Firefox ESR, even though Fx ESR are guaranteed for a security update... any other reason?

IIRC, the highlights of the anti-Tor-Browser argument are something like:

- Various people who are very interesting to intelligence agencies, police, organized crime syndicates, and private security for major corporations use Tor Browser, increasing the demand for and thus price of black market exploits specifically targeted at it.

- Tor Browser incorporates patches and default settings that receive less testing and review than the code and defaults of vanilla Firefox, making it more likely that vulnerabilities exist.

- Architecturally, Firefox lacks robust exploit mitigations, making it more likely that such vulnerabilities are actually exploitable.

- There's a delay between security fixes in vanilla Firefox and their release in a Tor Browser update.

- Exit nodes and root CA certificates may both be controlled by attackers, potentially giving them the ability to deploy exploits even to targets that only use HTTPS to trusted sites.

Adding all of the above together, it is not only plausible but likely that effective exploits specifically for Tor Browser currently exist in some attackers' toolkits.

Re: Tails 3.0 Released

#55
post #47

Earlier quoted context omitted.

Making a claim while not explaining your reasoning is a sign of a low quality post that provides no actual contribution to the thread (and more often than not, of trolling) which justifies downvoting the post, no matter who the creator. Reputation matters if you want to buy something or if you want an expert opinion on a topic that you have no idea about. However I don't believe that reputation matters in a forum ful…

A warning from a knowledgeable person without explanation is still better than no warning at all. I hope tptacek just didn't have time to post an explanation; maybe he'll find the time later.

I'm on vacation in the middle of Austria with spotty Internet access, so you'll all have to take what you can get. :)

Re: Tails 3.0 Released

#56
post #12

For the love of Christ don't use Tor Browser. Every other modern browser, including mainline Firefox, is safer.

From another comment elsewhere in this thread: > Update Tor Browser to 7.0 (based on Firefox 52 ESR) which is multiprocess and paves the way to content sandboxing. This should make it harder to exploit security vulnerabilities in the browser. Firefox 52 ESR sounds like mainline Firefox to me.

Literally the same version of Firefox as underpins Tor Browser will tend, pretty much at all times, to be safer than Tor Browser. You can use the search bar at the bottom of the page to find out why, or search the Internet for "grugq tor browser" if you want more people explaining the issue.

Re: Tails 3.0 Released

#57
post #12

For the love of Christ don't use Tor Browser. Every other modern browser, including mainline Firefox, is safer.

I'm not necessarily doubting you, but I wonder if you can say why you think the Tor project is distributing such an unsafe browser? If that's a very poor decision, does it call into question other decisions the project has made?

The problem is intrinsic to what Tor is trying to do; it's not simply a bad engineering decision on the project's part.

Re: Tails 3.0 Released

#59

Earlier quoted context omitted.

since there's no reply, I'm guessing it's because Tor Browser is using Firefox ESR, even though Fx ESR are guaranteed for a security update... any other reason?

IIRC, the highlights of the anti-Tor-Browser argument are something like: - Various people who are very interesting to intelligence agencies, police, organized crime syndicates, and private security for major corporations use Tor Browser, increasing the demand for and thus price of black market exploits specifically targeted at it. - Tor Browser incorporates patches and default settings that receive less testing and…

Thanks, this is a good summary.

Re: Tails 3.0 Released

#60

Earlier quoted context omitted.

Intel early centrinos are not 64bit (Dothan / Banias) so are the initial Core / Core Duo CPUs (Yona). Intel didn't release a mobile 64bit CPU until 2006/7 with Core 2 Duo. Also the initial implementations of Intel64/EMT64 lack certain functions so even tho they technically support 64bit they might lack certain other features that are required by modern operating systems. So overall if you have a 10 year old laptop yo…

not even. If you have a netbook from 2009 the ubiquitous Intel Atom N270 that powered all of those was a single-core 32-bit CPU.

My thought as well. Those things are everywhere like rats.
Post reply on HN