Gentoo Archives: gentoo-user

From: James <wireless@×××××××××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: Tails security implemetation
Date: Wed, 17 Feb 2016 17:51:47
Message-Id: loom.20160217T180932-137@post.gmane.org
In Reply to: Re: [gentoo-user] Re: Tails security implemetation by Nils Gillmann
1 Nils Gillmann <niasterisk <at> grrlz.net> writes:
2
3
4 > >> > So I just read about how Tails is now available on Debian [1].
5 > >> > [1] https://bits.debian.org/2016/02/tails-installer-in-debian.html
6 > >> > [2] https://tails.boum.org/blueprint/bootstrapping/installer/
7 > > Trimmed down per gmane posting rules.
8 > Could you provide a link, so I could look into the rules, as the
9 > gentoo.org pages dealing with the lists show no difference to
10 > what I am used to on other lists.
11
12 http://news.gmane.org/gmane.linux.gentoo.user
13
14 gmane.org is a front end to this and other lists that I use. I complains
15 loudly if you post is shorter than what you respond to as included text.
16 Just use it a bit and you'll see.
17
18
19 > >> There are gentoo based systems with security in mind, but I am not
20 > >> very positive about re-creating Tails on current state of Gentoo.
21
22 > I have to rephrase this. It is possible, but I personaly don't
23 > see a benefit in reinventing the 10th generation of wheels (a
24 > widespread issue). For research, well, why not.
25
26 No harm in using debian, to me. I just like to keep the things I do
27 in the gentoo family, as opposed to running all sorts of other linux
28 distros. For a person working alone, there are only so many hours
29 in the day.
30
31
32 > > Hmmmm. LikeWhoa, one of the gentoo devs, put together a gentoo install
33 > > system from usb, that includes persistence, quite some time ago. [B]
34 > >> Tails and/or Whonix have tried and shifted focus away from Gentoo
35 > >> for reasons which can be read on their github repo wiki and with
36 > >> good websearches.
37 > See next reply.
38 > > Tails is the tor-node on a usb, with persistence, or did I miss some of
39 > > the deeper capabilities? Having a debian and gentoo similar (anonymous)
40 > > device does seem a bit enticing to me. For sure it'd be a great
41 > > additional protection for credit card usage over the net, in addition
42 > > to the existing pathetic protections folks currently have.
43 > > I certainly appreciate your candor. However, I cannot find the listing of
44 > > issues with these aforementioned codes(packages) on gentoo. All I think I
45 > > really need it the software (packages) listings and some guidelines and
46 > > gotchas. Also you should look at Anthony's excellent works [C]. I'd
47 > > ceratainly appreciate a bit more detail (private email is ok too), or a
48 > > 'data dump' on exactly what problems exist. My interest is to master a
49 > > similar device for stealth usage, that is gentoo centric. Most of the pieces
50 > > seem to be present, so it's mostly an integration and testing effort?
51
52 > Okay, I think I was wrong. I got mixed up with Whonix and Tails
53 > coming together, what whonix did run into is listed here:
54 > https://github.com/Whonix/Gentoo-Port/issues
55
56 Excellent!
57
58 > Back then I did not look very closely. It might be that some of
59 > the 1 - 1.5 year old issues are closed now.
60
61 LikeWhoa's work did not get disseminated widely for quit a while, so
62 you are not alone in missing persistence with usb and live installs.
63 I'm not sure he is the first, but, his work here at gentoo is always
64 appreciated and top-notch.
65
66
67 tinhat and Blueness's other works beccame very close to what I was looking
68 for. It did not have a ebtables/iptables/nftables frontend so I have
69 struggled to put that together on one tinhat system. I think the whonix
70 gateway mostly solves that issue, or at least provides a similarly
71 functioning codebase to start with, for what I'm looking for.
72
73
74 > I only did stop because I became sceptical on some parts of the
75 > Gentoo project and looked for better solutions to topic unrelated
76 > issues. Currently I am interested in doing the same thing with
77 > GuixSD or with Gentoo running Guix, although that's a rather long
78 > term project and not my primary focus of interest.
79
80 I'm challenged enough trying to build something like Tails+Whonix
81 on a usb-stick for now, gentoo centric. Sure after that I'd also be
82 interested in it's VM modifications, so it can be easily installed in a
83 variety of server (cluster) situations.
84
85 Thanks for all of your help and insight.
86
87 James