Reproducible Builds and Security Gaps in Debian-Based Tails
-
Reproducible Builds: Reproducible Builds in January 2025
Our monthly reports outline what we’ve been up to over the past month and highlight items of news from elsewhere in the world of software supply-chain security when relevant. As usual, though, if you are interested in contributing to the Reproducible Builds project, please visit our Contribute page on our website.
-
[Repeat] Linuxiac ☛ Tails 6.12 Rolls Out, Sealing Critical Security Gaps
According to the development team, several vulnerabilities were discovered during an external security audit by Radically Open Security. In light of this, perhaps the most noteworthy highlights in Tails 6.12 are the fixes preventing attackers from monitoring Tor circuits and altering Persistent Storage settings. Here are some more details about it.
-
Tor ☛ New Release: Tails 6.12 | The Tor Project
The vulnerabilities described below were identified during an external security audit by Radically Open Security and disclosed responsibly to our team. We are not aware of these attacks being used against Tails users until now.
These vulnerabilities can only be exploited by a powerful attacker who has already exploited another vulnerability to take control of an application in Tails.
Sponsor revealed:
-
Debian ☛ Bits from Debian: Proxmox Platinum Sponsor of DebConf25
We are pleased to announce that Proxmox has committed to sponsor DebConf25 as a
Proxmox develops powerful, yet easy-to-use Open Source server software. The product portfolio from Proxmox, including server virtualization, backup, and email security, helps companies of any size, sector, or industry to simplify their IT infrastructures. The Proxmox solutions are based on the great Debian platform, and we are happy that we can give back to the community by sponsoring DebConf25.