DoD offers up tiny, secure Linux distro
geek.com
geek.com
As a practical matter, it verges on completely useless for any serious business. Note the screenshots don't include evidence of Citrix running, or even a web browser. There's no package management. You couldn't install it if you wanted to. As I recall, I never got networking up. That was a snapshot release from ... March, I believe.
I'm glad to see someone in US government working on desktop Linux. I would love to say goodbye to Windows XP. That said, for the advertized purpose, I've found an Ubuntu thumbdrive much more practical.
If you're expecting Citrix... you're probably not in the target audience.
Anyone can do essentially what they're doing just by using a live CD. They've gone a bit beyond that by not mounting the hard drive as noted, and whatever other changes they've made that the article doesn't specify.
It has consumer-friendly "Windows XP" style UX and the user it logs into isn't root/sudo.
This all leads me to conclude the original purpose of this tool was for "normal people" to use, and so I'm left wondering whether it was for agents or informants to be able to communicate back to the mothership securely.
If this was for security personnel or those performing forensics on evidence, there wouldn't be cutesy UX and it would be logged in to root. If this was for 'rank and file' staff in CIA/FBI offices, they wouldn't need a portable distro.
... except if the underlying hardware is compromised.
http://www.spi.dod.mil/lipose.htm
but the server looks busy.
Can anyone who's downloaded this give us an MD5 hash on the files as I'm going to try to download this from a mirror (why the DoD hasn't published an official MD5 for these I don't know)
MD5 and SHA256 hashes, from the DoD of all people.
Or the DoD could always go back to helping OpenBSD :)
1. Cripple the random number generator similar to the debian bug from 2008, this would be difficult to spot through source inspection, but not hard to spot from active queries.
2. Include valid certificates in the trusted certificate store that allow the distributor to execute a man in the middle attack. This becomes even easier if the dns servers are hardcoded to be those of the attacker.
Basically, if you think the US Air Force has reasons to snoop your communications; don't use their software to communicate. Linux is freely available, build your own high security distro or use OpenBSD or write your own from scratch, don't assume software is secured unless you implicitly trust the person who claims it has been secured for the purpose you are using it; and even then they might be wrong.