3 ms·
Tails answers this question on their site [0] Their general opinion is that this makes Tails less secure as now you have to trust both the host and the visuali
by Homunculiheaded 12y ago
Tails answers this question on their site [0]
Their general opinion is that this makes Tails less secure as now you have to trust both the host and the visualization software.
Provided that you trust Tails itself. The expected way to run it is off of a live cd. This way the trusted OS is only ever in ram, and if you use a non-rewritable disk you can also be assured that the Tails disk itself cannot be modified after its creation.
Tails handles the 'only talking to Tor' via iptables. Unless I am mistaken Tails' firewall will not allow clearnet connections.
[0] https://tails.boum.org/doc/advanced_topics/virtualization/index.en.html https://tails.boum.org/doc/advanced_topics/virtualization/in...
- willvarfar 12y agoThis is not the same question. The question is, inside the tails itself, should apps like the browser and your mail and chat programs be isolated from each other i.e. placed in "jails", "containers", "zones" or whatever? Security in depth.
- dobbsbob 12y agoTails has an 'unsafe browser' so you can log into wifi gateways then start the regular browser. If I'm a federal agent in need to decloak Tails users I would probably target that script that disables the firewall that any unprivileged user can run. If you don't need the script probably a good idea to build Tails without it