Hi ! > 1. How can we be sure tails.boum.org is really tails.boum.org, and not its > evil twin.
that's (one of) the purpose of the SSL certificate, check the fingerprint (see 3.) > 2. How could I configure the OpenDNS to protect me against a malicious DNS > server that points me through a fake tails.boum,org? there is a support forum on their website https://support.opendns.com/forums > 3. Where I see, in the Icewesel browser, the tails.boum.org fingerprint? > (78:F1:3B:80:FA:77:35:74:18:87:59:D3:64:86:03:13:0B:91:CD:4D) connect to https://tails.boum.org, and click on the little padlock near the URL bar, then "more info", "security", "view the certificate" > > 4. "We need trusted organizations to validate that the copy of > tails.boum.org we see in our browsers is the real deal. Specifically, we > need to know: > > The IP address of tails.boum.org there are mirrors servers running the website, it may not be always the same IP address, you should not rely on it > The Certificate Authority that vouches for the site would you be more confortable if it was verified by a US company subjected to the Patriot Act ? > Whether the certificate is a regular one or extended > validation (seems to be regular) > The issue date and expiration date of the certificate > Some way to insure that the certificate we see in our browser > is the > right one. Perhaps the serial number of the certificate or its MD5 > fingerprint or its SHA1 fingerprint.**" look at the certificate. > The complete article, we read here: > http://www.computerworld.com/article/2476515/network-security/the-security-flaws-in-tails-linux-are-not-its-only-problem.html that article was written this summer, as part of the buzz around exodus's tweets (a good advertisment campain for their company), and that site is rejecting connections from the Tor Network. cheers.
signature.asc
Description: PGP signature
_______________________________________________ tails-support mailing list [email protected] https://mailman.boum.org/listinfo/tails-support To unsubscribe from this list, send an empty email to [email protected].
