[HN Gopher] Tails 5.0~beta1: Call for testing
       ___________________________________________________________________
        
       Tails 5.0~beta1: Call for testing
        
       Author : agumonkey
       Score  : 62 points
       Date   : 2022-04-15 19:47 UTC (3 hours ago)
        
 (HTM) web link (tails.boum.org)
 (TXT) w3m dump (tails.boum.org)
        
       | sgarman wrote:
       | It would be cool for ARM support. I'm not sure how hard that is
       | but seems like it's hit or miss for various linux distros if you
       | can get them to run on apple silicon.
        
       | vosper wrote:
       | > Tails is a portable operating system that protects against
       | surveillance and censorship.
        
       | cosmiccatnap wrote:
       | This stuff is really cool but in a world with IME it's sadly,
       | moot. What good does a secure OS do you if the hardware has a
       | fully embedded OS tied to both your keyboard and Ethernet adapter
       | such that it can transparently send and receive anything you are
       | doing?
        
         | Datagenerator wrote:
         | Are these AMT of AMD and Intel Pro, features that create mesh
         | networks on the fly?
        
         | Forbo wrote:
         | How many adversaries have the ability to act on that risk? I
         | hate the security defeatism that is rampant across the space.
         | The perfect is the enemy of the good and all that. Unless your
         | threat model includes nation state adversaries (or
         | individuals/orgs with similar levels of skill and funding)
         | explicitly targeting you, worrying about IME/PSP is probably
         | completely unwarranted. Unless I'm unaware of active
         | exploitation campaigns against these systems, in which case I
         | would love to learn more.
         | 
         | Edit: Don't get me wrong, I would love to see a world where the
         | entire system is open from hardware on up. Unfortunately I
         | don't know that we'll get there without some substantial shifts
         | in humanity as a whole.
        
         | BobbyJo wrote:
         | If you don't want anyone knowing who you are you're stuck using
         | only public wifi anyway. Who cares if they build a profile
         | around a piece of hardware? As long as they can't link it to a
         | real human it's not really an issue.
        
         | JackGreyhat wrote:
         | Can IME decrypt network traffic if tails runs inside a VM?
        
       | cf100clunk wrote:
       | heads (lower case h) does much the same thing as Tails but
       | without systemd or non-free software:
       | 
       | ''heads is a GNU/Linux liveCD distribution aimed at people who
       | like the aspect of controlling their privacy and anonymity on the
       | Internet. You might have heard of Tails as a similar GNU/Linux
       | distribution. heads was born as an answer to Tails, since Tails
       | is using systemd as an init system and also contains non-free
       | software.
       | 
       | In heads, the init of choice is not systemd. systemd is a huge
       | piece of software that, while being free software, has not been
       | audited for security since its creation. Being big as it is, it
       | is hard to do so, and as time goes, it's becoming even tougher to
       | audit systemd. We do not aim to disrespect or get into the
       | controversy on why systemd is a bad choice. We just do not wish
       | to use it.
       | 
       | Another important thing is that heads uses only free software,
       | while Tails continues using non-free software. Non-free software
       | can not be audited and as such cannot guarantee you security or
       | anonymity.''
       | 
       | https://heads.dyne.org/about.html
        
         | Forbo wrote:
         | A rather unfortunate name collision, at first I thought this
         | project (targeting tamper evident attestation pre-boot) had
         | vastly expanded its scope: https://osresearch.net/
        
           | cf100clunk wrote:
           | heads vs Heads, it would seem. The names are too close for
           | comfort, given their purposes.
        
         | hjek wrote:
         | > Another important thing is that heads uses only free
         | software, while Tails continues using non-free software. Non-
         | free software can not be audited and as such cannot guarantee
         | you security or anonymity.
         | 
         | Latest version of heads is 4 years old so not sure how much
         | security those developers can guarantee.
        
           | cf100clunk wrote:
           | It says on their page that they use latest forward patches
           | from grsecurity.
        
       | i_like_waiting wrote:
       | Seems like reasonably good solution for vacations when I need to
       | take with me my work laptop, but I want to also work on my
       | personal projects, without dragging second laptop?
       | 
       | Or does company laptop prohibit this somehow?
        
         | zdragnar wrote:
         | Depends on where you live and your company. In the US, the
         | laptop is company property, and so is anything you produce on
         | it barring some other agreement.
         | 
         | I think this is less true to an extent in Europe, where at
         | least some countries establish privacy rights to employees when
         | using company equipment- at least when it comes to Internet
         | browsing history and private emails. I'm not sure if creative
         | works like personal side projects would also be protected.
         | 
         | Really though, when it comes to using company time or property
         | for personal gain, the only real answer is "talk to your
         | lawyer".
        
           | i_like_waiting wrote:
           | from legal perspective definitely, usually its phrase "as
           | long as its created during work time or with work equipment
           | or its work related" its property of the company.
           | 
           | I am asking more from technical point of view, e.g. I guess
           | the tech companies at least will have booting from usb
           | blocked completely, or it triggers some bitlocker type lock
        
       | einpoklum wrote:
       | Have they weaned themselves off of systemd yet?
       | 
       | (checks)
       | 
       | ok, no. Too bad, they really should :-(
        
       ___________________________________________________________________
       (page generated 2022-04-15 23:01 UTC)