This looks valuable.
Login to reply
Replies (67)
Do not trust Tails OS.
Tails is no longer open source. You need to email them to request permission to even look at the source code. They've closed registration to their GitLab instance, they don't explain why.
Half of the opening paragraph about Getting Started as a contributor is about pronouns.
Everyone working on the project seems to be salaried and keeps strict office hours. Even if you get access to their instance, as an outsider you can't report issues to it.
Oh, and if you want to access their mailing list archive, you can't because it was hosted on Autistici/Inventati, the Italian hard-left entity that was just designated as a Specially Designated Global Terrorist by the US and taken offline. I would not trust the project anymore.
DYOR.
DTails seems to be fine tho
What version was the first closed source?
Dtails? Firt time I hear about it π
HeadsOS still exists. I couldn't find out when it was last updated, though.
heads downloads | heads
heads, the libre privacy linux distro
The designation of Autistici/Inventati as a "Specially Designated Global Terrorist" by the US is total bullshit, and a direct attack against civil liberties.
Is it affiliated with the Tor Project?
I thought so. I was on Tors website recently & that's what it seemed like.
I Think Tor is compromised


Tail OS is that what ?
The Tor Project seems to be full of far-left woke people too.
Which means they are corrupted
Wow, what's their argument for that?
There's no way that makes any logical sense. They just want to see your real IP I think
Likely. I still think TOR is safe tho, i only have a problem with the team behind it (Tor Project)
No it isn't safe. But if you use it with a VPN it isn't bad
future rug.
Their wiki does't even explain why they recommend not using a VPN. So strange...
Using a VPN 24/7 should be the default for everyone. I see TOR an extra layer on top for added protection.
Perhaps because your ISP can't see Tor usage (though bridges do that better), but now the VPN provider knows your real identity and that you're on Tor, a correlation choke point with payment records attached. Plain Tor never asks who you are. This is negated with some VPN provider though as not all require KYC. If you're using a private VPN and then from their connecting to Tor, you're most likely fine.
If you're connecting to Tor and then a VPN, that's bad. You're essentially negating Tor's random exit node. Tor exits rotate per circuit, a VPN exit doesn't, so the VPN becomes one persistent observer of all your traffic, defeating Tor Browser's per site circuit isolation.
It's also technically fragile: Tor only carries TCP, so UDP based WireGuard/OpenVPN won't tunnel over it without special config.
And this special configuration is very complicated for the average person that just what's some privacy.
My two sats.
That said, three letter agencies absolutely run Tor exit nodes. Why wouldn't they? They'd be terrible at their jobs if they didn't.
Derek had a decent response but yeah I think its sketchy
I do use a VPN at all times
Lots of good points although raw dogging Tor is far worse imo
This would be no different to an ISP? ISP can absolutely see tor traffic so this only stands if for some reason your ISP is retarded? Which in the US is likely to be one of 4-5 major companies, all of which have state-of-the-art traffic detection for their ad's business. And we cannot simply forget about Room 641A.
A primary (and my opinion only) purpose of a VPN is to shield traffic from your ISP, which has the added benefit of hiding your physical location from servers. Because ISPs publish your IPaddress location information for legal reasons, and because they get advert money from it.
Then, you must vet your VPN the same way we don't trust our ISPs because we simply shifted the watching to the VPN opposed to our ISP. However the VPN provider has been proven to be much less likely NOT to share your traffic information NOR your personally identifiable information on the public internet to find in milliseconds like ISPs do.
> Tor only carries TCP, so UDP based WireGuard/OpenVPN won't tunnel over it without special config.
Don't think this is true at all. Tor works just fine being tunneled over wireguard out of the box ime. So not sure which setting people are leaving off that breaks this.
If were worried about the alphabet bois none of these are a solution, and I would consider them equally a problem. Tor traffic is identifiable, and can be time-correlated well enough by the alphabet bois that you're pretty boned using tor at all if they care enough about you.
I didnβt see actually any bug different between if you use VPS , the functions still the same to hide your identity . If you donβt want to get tracked then you just use , incognito mode while using reguler VPS.
Donβt need TOR for that . In my opinion .
What about vibe-coding an os?
@MissingNo Can you say which version number it changed?
Correct.
Your ISP can see:
That you use Tor. Your first hop connects to a guard relay, and all relay IPs are on a public list. The traffic is fully encrypted, but "connected to known Tor relay" = "this customer uses Tor."
Volume and timing, how much, when.
Your ISP cannot see:
Content. Thanks to three layers of encryption, peeled one hop at a time. No single party holds both ends, by design.
Destination. The guard knows you but not where you're going. DNS also resolves inside the circuit, so no DNS leaks (unlike a sloppy VPN setup).
Just about 8y ago
If you are asking because you wan't to download & use old versions, please don't. They most likely contain security vulnerabilities. As of right now, Tails seems to be fully compromised, i would never be trusted again. The Tor Project has also been very shady for quite some time now.
what did they do to earn a terrorist label tho?
Datura is here to fix, what Tor is refusing to fix.
Better use i2p for now.
Just have a VPN on the router/secondary device and then connect over tor on the main machine.
What's Datura?
A project by Nihilist (creator of the OpSec bible).
He proposed some fixes to tor, that can be used to deanonymise circuits.
After waiting for far too long he started to change his stance on Tor and now thinks it is a compromised project (better than nothing). But far from what it could offer.
So he went on designing a new protocol that takes care of what needs to be fixed.
Read up on it.
Can you provide some links? I can't seem to find anything
I only use a phone
Found them. I have a week worth of reading yay!
yeah. Seems like a counter point to the rest of the accusations
You must understand that the USA government is controlled by pedophiles and this is what they do.
Interesting. Another thing to dive into. Did just use it twice just for fun to try it out.
What about Parrot OS? In general, by any chance, do you know more about other "safe" OS that are possibly compromised?
@MissingNo @npub1ah3aj4mhfew4c7txfdd4paf3wr5syntkeyxenl9fxf9rejte2wpqwcl76e
Can you both share the links please?
Iβm only an occasional Tails user and Iβm not a dev or security expert, so I just did a quick check. Some of your points seem valid, but personally I donβt think they are enough to make me distrust Tails as a whole. Iβll probably keep using it when I need it.
Still, raising doubts and looking critically at tools like Tails is always useful. Open-source privacy tools matter a lot, especially in a world that is becoming increasingly surveilled.
Any OS that has leftism / woke politics attached.
Yeah thats a fact I found out myself already π Thats their thing, being cancer to whatever "them" touch. RIP Blizzard btw.
ATM I am on omarchy exclusively, so should be fine for now. π€
I'm on SecureBlue, it's the GrapheneOS of Linux.
I run secure blue too, although I haven't used my laptop in months.
Same, I only use mine to play games and to run my bitcoin node. Everything else I've transitioned to mobile. Android (and specially GrapheneOS) has superior security and privacy.
Graphene is great. π₯
IΒ΄ll check it out, thx. π€
I summon @brito π
Oh well.. when a product has "secure" on the title then it is likely everything except that.
Worst, they even brag about it right on their frontpage with the adoption of SELinux (Security Enhanced Linux) in contrast to other distros that tend to stay far away from it:
Do you know why they keep distance? Because it was written by the NSA, that's why:
Try to guess what is the business model of that government agency.
Do you know why they keep distance? Because it was written by the NSA, that's why:
Try to guess what is the business model of that government agency.Yeah and DARPA invented the internet. π«£
Muted.
It's the only distro recommended by GrapheneOS. Their browser is a Vanadium fork. You should DYOR before talking nonsense.
Guy won't "look at the code", only tHE cOnnEctIOns.
Typical qanon tard.
Sorry for being too slow to respond. Glad you found it (only on tor).
Best to do both. Look at the code and the connection. And if one is shady put even more eyes on the other.
Only relying on one data point is stupid. Compromise can come in different flavours.
Using Tor without a VPN normalizes Tor usage and is important for its continued existence. Tor requires public volunteer nodes to be able to exist, and if people start being to scared to be seen using Tor even when its legal, it can destroy the entire network.
That's just a VPN-before-Tor setup though. A Tor-before-VPN setup is actually really bad for completely different reasons. The Tor protocol and browser go through a great deal of effort to ensure that even a single browser session is split up across many different Tor circuits. Usually unique circuit across browser tabs, websites, and sessions I believe.
However, when you pay for a VPN subscription, it completely destroys that. Suddenly every tab, website, and browser session is associated with the exact same VPN subscription. Maybe you buy the subscription anonymously, but with a Tor-before-VPN setup, the VPN can still build a profile of your browsing habits to make guesses about who you are. The same cannot be done by the exit nodes in a Tor only setup.
Personally, I think it's silly to warn people about Tor-before-VPN setups. Not only is Tor-before-VPN very difficult to set up even ON PURPOSE, but it actually has some niche applications, such as connecting to some kind of personal server associated with your identity, but without revealing to the VPS provider that you are connecting to it over Tor.
Tbh, I think most people bashing Tor just want to pick on the biggest guy on the block to make themselves feel better, even if in practice their opsec is not nearly good enough to justify dismissing Tor like that.
Another reason to keep distance. That shady android distro with shady funding sources. DYOR before using gov-sponsored software.
As explained earlier, it is darn easy to hide anything inside 25 million lines of code, whereas it is easier to ask who is sponsoring a project.
Past experience like Signal and its gov-sponsoring has demonstrated that it is a good practice to follow the money trail when the topic is privacy.
DARPA isn't the NSA, their goals differ.
This is particularly relevant when the topic is privacy.
When did they close the registrations? There was a remote code exec vulnerability discovered in gitlab few days ago. All you needed to abuse it was a gitlab account.
Use a second phone as a router then.
Do you also avoid Android and every Android derivative because of SELinux?
Yes. I personally build my own operating systems, build the hardware as simple as possible (usually ESP32) and build my own internet (XPRS is an example) running on BLE, reticulum/i2p over internet, radio, LoRa and radio.
This clip is from an operating system that I created from scratch a few years ago in what would later be called CYD (Cheap Yellow Display). In the meanwhile things evolved, now with satellite based text messages at the moment.


