Inside the Operating System Edward Snowden Used to Evade the NSA
wired.com
wired.com
Your encrypted data and sensitive files are often accessible via memory forensics even if you shut your computer down. Including the websites you visited. Your encryption keys can be in your computers memory for weeks and is easily accessible via a memory dump.
This is why people say that with physical access your computer can always be owned. Even if it's encrypted. Tails is the only one I know that handles this attack vector by default.
http://en.wikipedia.org/wiki/Cold_boot_attack
"in the seconds to minutes after power has been removed."
The reason is explained here:
http://en.wikipedia.org/wiki/Memory_refresh
And even the electrons from SRAM, which doesn't need refreshes and which was for decades not used as "RAM" in the computers will leak away without the power:
http://en.wikipedia.org/wiki/Static_random-access_memory
"SRAM exhibits data remanence but it is still volatile in the conventional sense that data is eventually lost when the memory is not powered."
Of course, if you never power off your computer but just reset it (the power is never cut off) or if you shut it down and immediately power it up the content of the RAM can really survive for much longer.
"This study is based on 5 different computer systems. While we demonstrate that simple warm reset attacks (not cutting power) are effective even against DDR3 systems, we were not able to detect any data remanence for DDR3 after cold boots. Even cooling the RAM chips did not reveal data remanence beyond cold boots. This leads us to the claim that cold boot attacks relying on RAM remanence beyond cold boots are not possible against modern DDR3 RAM chips."
[1] https://www.usenix.org/legacy/event/sec08/tech/full_papers/h...
[2] http://www1.cs.fau.de/filepool/projects/coldboot/fares_coldb... (search for DDR3 to find the relevant sections)
This is why it's good to power down or sdmem when you're finished working with sensitive data.
On a full shutdown persistence is not as big of a risk, as the other commenter pointed out, cold boots are mitigated by DDR3 similar to how modern SSDs with TRIM make deleted data-recovery nearly impossible (such as Swap data which may also contain encryption keys).
No. After some high-enough RAM area contained the keys and you keep it powered and your OS uses much less physical RAM than physically available there's no hard limit. Just forget the "week."
I don't really trust their tests, but DDR3 memory kind of makes this attack useless. The $FEDAGENCY also plans arrests so you're cuffed with everything turned on and no way to push buttons or yank out cables like Ross Ulbricht or Max Vision
"For various reasons Tails tries to diverge by the smallest possible amount from its upstream projects, and especially from Debian"
"We try to push our changes upstream when we need to modify software we ship. This often requires us to write code in a generic way, rather than implementing ad-hoc hacks to fit our specific needs: e.g. we often need to make the stuff we need opt-in and add configuration options."
The official term for this is "Debian derivative" rather than "fork."
Or is this proof of tor being better than nothing?
Edit: apparently I was mistaken. GNOME 2 is the default desktop, but there is an XP skin. See comments below.
http://www.bitblokes.de/wp-content/uploads/2013/02/tails-0-1...
No Win7 skin?
http://www.bunniestudios.com/blog/?p=3554
my 2c
same stuff, too many cpu everywhere, making protocols meaningless.
Here's an example: Let's say (for the sake of example please) that the NSA can passively monitor Google searches in realtime. Let's say you search for a phrase that sets off their monitor: something like "a Tor user has Googled for Snowden." They'd like to know who you are. How would they do that?
One way is to record the fact that from your home computer originated some Tor traffic at almost the same time the Google search took place.
It's unclear exactly how they deanonymize Tor users, but one piece of info that may corroborate my hypothesis is that in a Snowden screenshot, you can see the NSA has a tab called "Tor Events" in one of their tools.
The need for websites to load quickly is Tor's Achilles heel, because it enables timing correlation. The fact that few people use Tor exacerbates the problem.
http://www.theguardian.com/world/2013/oct/04/nsa-gchq-attack...
"Tor doesn't protect you from a global adversary
A global passive adversary would be a person or an entity able to monitor at the same time the traffic between all the computers in a network. By studying, for example, the timing and volume patterns of the different communications across the network, it would be statistically possible to identify Tor circuits and thus matching Tor users and destination servers.
It is part of Tor's initial trade-off not to address such a threat in order to create a low-latency communication service usable for web browsing, Internet chat or SSH connections.
For more expert information see Tor Project: The Second-Generation Onion Router, part 3. Design goals and assumptions. [https://svn.torproject.org/svn/projects/design-paper/tor-des...
This either implies someone already suspects you and are monitoring you or that you are the only person searching on Google using Tor at that particular moment. I find the latter hard to believe. Even if it is true, it can be mitigated by more people using tor at the same time.
(And of course they wouldn't know that it was your traffic to whatever site they're surveilling, they'd just have evidence that was not inconsistent with you actively using Tor to do Something Or Other at that time.)
Would not take long to grep ISP logs and find the known Tor bridges, Obfsproxy bridges, relays and who might have used them.
If you tunneled Tor traffic through a VPN exiting Russia then your local ISP has no Tor timing metadata to give, unless you're Snowden and your adversary is global. Running an internal relay would help obfuscate your own traffic too if you can connect to it on a local network it would be a lot harder to prove you logged into IRC channel #blowuptheembassy on the Al Qaeda IRC freenode server.
For all X, X does not make you impervious. All it can do is increase the cost to an attacker.
A nice comparison: https://www.whonix.org/wiki/Comparison_with_Others
You can't even call yourself a Troll in the UK now without people thinking you go on Facebook and mock the dead to their nearest and dearest.
I did once mail a correction to a story about a new EU regulation which had been a high profile item across BBC News. It was quite a fundamental thing, and I got a short mail from a senior editor, thanking me and angrily lamenting that it wasn't a difficult thing for his reporter to check, state of journalists these days, etc etc. The story was changed.
--edit: make a bad pun worse.
I guess the main thing would be the OS is everything which isn't an application, and Tails is definitely not a single application, though it is specialised.
It does not follow that either, or both, of these points (Open source, an NSA complaint slide) make this "snare proof". I'm not saying that it isn't, but there is no logic in the Wired article's assertions.
Shouldn't it be the opposite so we all know who we're relying on? It's the same question I'd throw at Bitcoin.
Plus, as TFA states, the code is all out there in the open and able to be reviewed. Does it matter who wrote it at that point?
Yeah, that worked out well for openssl.
Doesn't mean "Open Source sux", just some nuanced criticism, ok?