8 ms·
Tails 3.0 Released
- d33 9y agoThose two changes seem particularly important: * Tails 3.0 works on 64-bit computers only and not on 32-bit computers anymore. Dropping hardware support, even for a small portion of our user base, is always a hard decision to make but being 64-bit only has important security and reliability benefits. For example, to protect against some types of security exploits, support for the NX bit is compulsory and most binaries are hardened with PIE which allows ASLR. * Update Tor Browser to 7.0 (based on Firefox 52 ESR) which is multiprocess and paves the way to content sandboxing. This should make it harder to exploit security vulnerabilities in the browser. What do you guys think about dropping 32-bit?
- codewiz 9y agoWhat do you guys think about dropping 32-bit? About time.
- sft 9y ago>What do you guys think about dropping 32-bit? Nothing of value lost.
- kakarot 9y ago32-bit is insecure. There's no good reason to support it. Get a cheap old laptop if you have 32-bit machine for some reason, it's good to have separate hardware for this type of thing anyway.
- venomsnake 9y agoHas there been any pure x86 processor in the last 10 year at all?
- jwilk 9y agoEarly Intel Atom CPUs in 2008 were 32-bit only.
- skraelingjar 9y agoI wonder if this will effect journalists and activists in parts of the world where old machines are still used (Africa, Middle East, parts of Asia). Not being able to make use of newer browser versions (without updating every time or taking the risk of using a persistent volume) could put them at greater risk.
- jwilk 9y agoPrevious versions of Tails already had exuberant hardware requirements. I guess privacy is only for the rich.
- weberc2 9y agoYeah, this is a consequence of limited resources. In an ideal world, the good guys would have resources for all the things, I guess.
- nextlevelwizard 9y agoLiterally nothing is preventing you from creating your own secure Linux installation on any hardware you've got.
- ViViDboarder 9y agoBesides ones technical skills. Not all activists are knowledgeable enough to just roll their own distro.
- Sir_Substance 9y agoBeyond that, I thought it was now well understood that rolling ones own security software is a terrible idea. Many eyeballs etc. Activists with the technical skills /should not/ roll their own, they should definitely contribute to existing projects.
- Laforet 9y agoI don't think it is unreasonable to assume everyone already has a 64-bit capable PC considering the most recent mainstream 32-bit only CPU is 2004's first gen Prescott Pentium 4.
- openmosix 9y agoYou can run Tails on a supercheap chromebook. It seems a right product compromise.
- barbs 9y agoI understand thst 32-bit is inherently less secure than 64-bit but if you had no choice but to use a 32-bit computer, what would be the best way to provide yourself with similar security features? I guess you could use an older version of Tails but I imagine this would become less and less secure as more and more vulnerabilities are found.
- nickpsecurity 9y agoThe 32-bit computers are the only thing available to lots of poor people or those just relying on other people's computers. People's teenagers, people using libraries, workers with legacy systems, and Internet cafes come to mind. Dropping it is a mistake if both could be supported. If it was lack of contributions or funding, I can understand the perspective of focusing on most secure one. EDIT to add: Always remember with solutions like this that the adversary isn't always the NSA and so on. The Tor users' page lists all kinds of people who need help against foes with limited budgets or knowledge who might not be able to break Linux or Tor. https://www.torproject.org/about/torusers.html.en https://www.torproject.org/about/torusers.html.en
- mrmondo 9y agoI can't honestly say I've seen a 32bit computer in what must be nearly a decade now?
- stevekemp 9y agoA lot of hosting companies run KVM/qemu/Xen or even UML with 32-bit guests by default. But yeah in terms of physical computers 64-bit has long been the default. I remember upgrading from 32-bit to 64-bit in-place a few times, which is a bit fiddly but not impossible with Debian. I wrote up a couple of guides once upon a time, but right now I can just find this old wiki-page discussing the process: https://wiki.debian.org/Migrate32To64Bit https://wiki.debian.org/Migrate32To64Bit
- Tepix 9y agoSure but cheap Intel Atom N270 netbooks are probably still being used in poor countries even though they were released around 2008/2009.
- vbezhenar 9y ago> What do you guys think about dropping 32-bit? If they don't have any usage data, I think, they should provide old version and support it with critical security updates. If they have usage data, it depends, I guess.
- teekert 9y agoI still occasionally use My Asus 1000HE (early 2009) and my Sony Vaio FE11S (2006), both still run fine with Arch/Ubuntu and Mate. Getting more and more difficult to find distro's though.
- akerro 9y agofreebsd, debian won't drop 32bit any time soon.
- DanBC 9y agoThere are a bunch of new machines that have 64 bit processors but tiny amounts of RAM. The low ram makes 64 bit OSs unfun to use, and most recommendations (Microsoft, Arch, Debian, etc) are to avoid 64 bit OSs on these machines. If you're someone buying burner laptops these machines, which are very cheap, are now probably not a good idea.
- slashink 9y agoThis is great. I very much appreciate the work done by the contributors to the Tails project and I trust & agree with their technical decisions for this release. As Internet keeps getting more monitored, Tails serves as an important tool in maintaining the balance of privacy and allowing for the anonymous sharing of information going forward. Big thanks to the Tails team.
- jwilk 9y agohttps://tails.boum.org/news/version_3.0/index.en.html#news-version-3.0.check https://tails.boum.org/news/version_3.0/index.en.html#news-v... says you should run "uname -m" under Tails to see if "your computer is 64-bit". How does that work? Does Tails automatically choose kernel version appropriate for your hardware, or what?
- deleted 9y ago[deleted]
- jnbiche 9y ago> How does that work? Does Tails automatically choose kernel version appropriate for your hardware, or what? No, you run `uname -m` and then download the appropriate version of Tails (although it appears Tails 3.0 is only available on 64-bit now).
- jwilk 9y agoI mean, "uname -m" gives you information about the kernel, not about the hardware. If "uname -m" says "i686" it means that your kernels is 32-bit (or pretends¹ to be so). It doesn't necessarily mean that your hardware is not capable of running a 64-bit kernel. So unless I'm missing something, the above procedure does not work correctly. Instead, you should run something like this: $ lscpu | grep -w mode CPU op-mode(s): 32-bit, 64-bit ¹ http://man7.org/linux/man-pages/man8/i386.8.html http://man7.org/linux/man-pages/man8/i386.8.html
- jnbiche 9y agoThat's a fair point. I misunderstood your question.
- an27 9y agoNone of the machines available to me worked with the previous release, I guess it's time to try again for the x64 subset...
- tptacek 9y agoFor the love of Christ don't use Tor Browser. Every other modern browser, including mainline Firefox, is safer.
- WillyOnWheels 9y agodo you suggest I should be running Firefox in Tails?
- ryanlol 9y agoThe safer solution is to run the modern browser of your choice (probably chrome) in an isolated VM routed through a torified gateway. Hardware isolation would of course be preferable. If you're using Tails you'd probably be much better off using Whonix instead. With Tails, an attacker capable of breaking your browser will m̶o̶s̶t̶ ̶l̶i̶k̶e̶l̶y̶ definitely also be capable of easily grabbing your IP address.
- WillyOnWheels 9y agoI love Chrome but I'm sure in some way it reports what I'm doing to Google. Why not just use Firefox?
- duozerk 9y agoThat's indeed far better; specifically, Firefox ESR with all the calling-home features disabled in about:config and noscript with no whitelist on top of it. Ideally you'd make sure the one responsible for going through tor isn't Firefox, too; IE at the very least a wrapper such as tsocks when running it or even better, a VM containing the browser and the entire VM connecting only through tor.
- gpm 9y agoWhonix is an OS, a modern browser of your choice could be firefox. Whonix runs TOR in a separate VM from your browser/user space. The idea is that even if you get hacked they don't get your IP address since they can only access the internet through the gateway VM that pushes all traffic through TOR.
- claudiojulio 9y agoTails should use Devuan. It does not have systemd. What do you think? Translated automatically.
- detaro 9y agoAssuming Debian Stretch still uses non-systemd networking configuration (which was the default case in 8 at least), or Tails switches back to it, systemd shouldn't impact what Tails tries to do in any way.
- moosingin3space 9y agoWhy is that important? Especially considering Tails has worked fine using systemd in their previous version based on Jessie. Additionally, Tails has used systemd's service namespacing functionality as part of a defense-in-depth strategy. Switching to Devuan makes little to no sense based on this track record.
- hendry 9y agohttps://webconverger.com/ https://webconverger.com/ is still 32 bit and keeps a clean slate.
- rlka3 9y agono more Tails with my trusty old friend T60 :(
- rallycarre 9y agoI recently started using Tails so for security reasons coughbackdoorwindowsioscough,.. and found that it worked surprisely well. It has a disk utility, liber office, and the drivers even worked for my wireless dongle! Kudos to the Tails team!