Software:Tails (operating system)

From HandWiki
Short description: Linux distribution for anonymity and privacy
Tails
Tails logo
TAILS 5.21 desktop with Tor Browser.png
Tails 5.21 Desktop, with Tor Browser open.
DeveloperThe Tails project
OS familyLinux (Unix-like)
Working stateActive
Source modelOpen source
Initial releaseJune 23, 2009; 14 years ago (2009-06-23)
Marketing targetPersonal computers
Update methodTails Upgrader[1]
Package managerAPT (front-end), dpkg
Platformsx86-64[2]
Kernel typeMonolithic
UserlandGNU
Default user interfaceGNOME 3
LicenseGNU GPLv3[3]
Preceded byIncognito
Official websitetails.net

Tails, or "The Amnesic Incognito Live System", is a security-focused Debian-based Linux distribution aimed at preserving Internet privacy and anonymity.[4] It connects to the Internet exclusively through the anonymity network Tor.[5] The system is designed to be booted as a live DVD or live USB and never writes to the hard drive or SSD, leaving no digital footprint on the machine unless explicitly told to do so. It can also be run as a virtual machine, with some additional security risks.[6]

The Tor Project provided financial support for Tails' development in the beginnings of the project,[7] and continues to do so alongside numerous corporate and anonymous sponsors.

History

Tails was first released on June 23, 2009. It is the next iteration of development on Incognito, a discontinued Gentoo-based Linux distribution.[8] The original project was called Amnesia. The operational system was born when Amnesia was merged with Incognito.[9] The Tor Project provided financial support for its development in the beginnings of the project.[7] Tails also received funding from the Open Technology Fund, Mozilla, and the Freedom of the Press Foundation.[10]

Laura Poitras, Glenn Greenwald, Bruce Schneier and Barton Gellman have each said that Tails was an important tool they used in their work with National Security Agency whistleblower Edward Snowden.[9][11][12][13]

From release 3.0, in 2017, Tails requires a 64-bit processor to run.[14]

Features

Tails's pre-installed desktop environment is GNOME 3. The system includes essential software for functions such as reading and editing documents, image editing, video watching and printing. Other software from Debian can be installed at the user's behest.[15][16] Despite being open-source, Tails contains non-free firmware blobs.[17]

Tails includes a unique variety of software that handles the encryption of files and internet transmissions, cryptographic signing and hashing, and other functions important to security. It is pre-configured to use Tor with multiple connection options. It tries to force all connections to use Tor and blocks connection attempts outside Tor. For networking, it features a modified version of Tor Browser with the inclusion of uBlock Origin,[18] instant messaging, email, file transmission and monitoring local network connections for security.[16]

By design, Tails is "amnesic". It runs in the computer's random access memory (RAM) and does not write to a hard drive or other storage medium. The user may choose to keep files, applications or some settings on their Tails drive in "Persistent Storage". Though the Persistent Storage is encrypted by default, it is not hidden and detectable by forensic analysis.[19] While shutting down, Tails overwrites most of the used RAM to avoid a cold boot attack.[20]

Security incidents

In 2014 Das Erste reported that the NSA's XKeyscore surveillance system sets threat definitions for people who search for Tails using a search engine or visit the Tails website. A comment in XKeyscore's source code calls Tails "a comsec mechanism advocated by extremists on extremist forums".[21][22]

In the same year, Der Spiegel published slides from an internal National Security Agency presentation dating to June 2012, in which the NSA deemed Tails on its own as a "major threat" to its mission and in conjunction with other privacy tools as "catastrophic".[23][24]

In 2017, the FBI used malicious code developed by Facebook, identifying sexual extortionist and Tails user Buster Hernandez through a zero-day vulnerability in the default video player. The exploit was never explained to or discovered by the Tails developers, but it is believed that the vulnerability was patched in a later release of Tails. Hernandez had eluded authorities for a long time; the FBI and Facebook had searched for him with no success, and resorted to developing the custom hacking tool.[25]

See also


References

  1. "Tails - Incremental upgrades". https://tails.boum.org/contribute/design/incremental_upgrades/. 
  2. "Tails - System requirements". https://tails.boum.org/doc/about/requirements/. 
  3. "Tails 0.11 incognito live system released". The H. 30 Apr 2012. http://www.h-online.com/open/news/item/Tails-0-11-incognito-live-system-released-1563498.html. 
  4. Vervloesem, Koen (27 Apr 2011). "The Amnesic Incognito Live System: A live CD for anonymity". LWN.net. https://lwn.net/Articles/440279/. 
  5. "Anonym im Netz" (in de). TecChannel. 6 Feb 2012. http://www.tecchannel.de/sicherheit/news/2038771/tails_0101_the_amnesic_incognito_live_system/. 
  6. "Running Tails in a virtual machine". https://tails.boum.org/doc/advanced_topics/virtualization/index.en.html. 
  7. 7.0 7.1 "Finances". 4 April 2013. https://tails.boum.org/doc/about/finances/index.en.html. 
  8. Gray, James (16 Sep 2011). "The Tails Project's The Amnesic Incognito Live System (Tails)". Linux Journal. http://www.linuxjournal.com/content/tails-projects-amnesic-incognito-live-system-tails. 
  9. 9.0 9.1 Finley, Klint (14 Apr 2014). "Out in the Open: Inside the Operating System Edward Snowden Used to Evade the NSA". WIRED. https://www.wired.com/2014/04/tails/. Retrieved 18 Apr 2014. 
  10. "Tails report for May, 2014". 14 Jun 2014. https://tails.boum.org/news/report_2014_05/index.en.html. 
  11. Timm, Trevor (2 Apr 2014). "Help Support the Little-Known Privacy Tool That Has Been Critical to Journalists Reporting on the NSA". https://pressfreedomfoundation.org/blog/2014/04/help-support-little-known-privacy-tool-has-been-critical-journalists-reporting-nsa. 
  12. Condliffe, Jamie (15 Apr 2014). "Try the Super-Secure USB Drive OS That Edward Snowden Insists on Using". https://gizmodo.com/try-the-super-secure-usb-drive-os-that-edward-snowden-i-1563320487. 
  13. "Air Gaps - Schneier on Security". https://www.schneier.com/blog/archives/2013/10/air_gaps.html. 
  14. "Tails - Tails 3.0 is out". https://tails.boum.org/news/version_3.0/index.en.html. 
  15. "APT repository". 7 October 2019. https://tails.boum.org/contribute/APT_repository/. 
  16. 16.0 16.1 "Features and included software". 7 October 2019. https://tails.boum.org/doc/about/features/index.en.html. 
  17. "Explaining Why We Don't Endorse Other Systems". https://www.gnu.org/distros/common-distros.html. 
  18. "Browsing the web with Tor Browser". https://tails.boum.org/doc/anonymous_internet/Tor_Browser/index.en.html#fingerprint. 
  19. "Tails - Creating and configuring the Persistent Storage". https://tails.boum.org/doc/first_steps/persistence/configure/index.en.html. 
  20. "Tails - Memory erasure". https://tails.boum.org/contribute/design/memory_erasure/. 
  21. Appelbaum, J.; Gibson, A.; Goetz, J.; Kabisch, V.; Kampf, L.; Ryge, L. (3 Jul 2014). "NSA targets the privacy-conscious". http://daserste.ndr.de/panorama/aktuell/NSA-targets-the-privacy-conscious,nsa230.html. 
  22. Bruce Schneier (3 Jul 2014). "NSA Targets Privacy Conscious for Surveillance". Schneier on Security. https://www.schneier.com/blog/archives/2014/07/nsa_targets_pri.html. 
  23. SPIEGEL Staff (28 Dec 2014). "Prying Eyes: Inside the NSA's War on Internet Security". Der Spiegel. http://www.spiegel.de/international/germany/inside-the-nsa-s-war-on-internet-security-a-1010361.html. 
  24. "Presentation from the SIGDEV Conference 2012 explaining which encryption protocols and techniques can be attacked and which not". Der Spiegel. 28 Dec 2014. http://www.spiegel.de/media/media-35535.pdf. Retrieved 23 Jan 2015. 
  25. Franceschi-Bicchierai, Lorenzo (10 Jun 2020). "Facebook Helped the FBI Hack a Child Predator". Vice. https://www.vice.com/en_us/article/v7gd9b/facebook-helped-fbi-hack-child-predator-buster-hernandez. 

External links