Tinfoil hat 2.0 pre-release
I finally had a few days free to work on tinfoil hat. All of the code is
more than a year old, so it was time to update to new versions of gpg and wipe. While I was at it, I rebuilt almost every other program on the disk.
Where is it
You can get version 2.0pre1 here. The signature file is here
So what's new?
- GPG version 1.2, Wipe version 2.1, loopaes 1.7d, util-linux 2.11z, busybox 1.0-pre1. Needless to say, 18 months of updates added about 1/3 more bytes to cram on the floppy disk.
- New random number gathering using clrngd. This gathers real randomness from fluctuations of high-frequency clocks on a PC's mainboard.
- MD5 checks of the system board ROMs thanks to ree.
- All editors were replaced with e3. It's not great, it is really small.
- Support for safe viewing of MS Word documents, thanks to strings|more
- New kernel build with support for all USB chips, ext2, vfat, iso9660 and loop-aes. The kernel is compressed with the bzip2 patch
- Minimal support for finding & mounting knoppix encrypted home partitions. Warning:: tinfoilhat doesn't have fsck, so this could make a corrupt ext2 filesystem much worse.
- First steps for booting from USB keys.
THL will accept a FLOPPY=dev argument from syslinux. If you know your USB key is /dev/sda1, typing "linux FLOPPY=sda1" at the syslinux prompt will make THL look for GPG key info on the USB key instead of the floppy. In theory this & syslinux is all you need to boot from a USB device. In practice most BIOSes are still to fussy to make this worth while.
- New bugs, mostly because of the changes to msh
FAQ
The old faq is a good place to start. These are FAQs for the testing release:
- Q: Why don't you include the build environment & source?
A: No matter what some people might think, there's no security benefit from using my code tree. If you're going to actually review all of the code used to build this, you may as well get it from kernel.org. I will try to provide all patches & configuration options so it's easy to rebuild on other architectures.
- Q: When will 2.0 final come out?
A: Probably in less than 18 months, but maybe not.
- Q: Why don't you make a CD version?
A: Time. I may get to it some day. The trick would be finding the CD & the storage device. And avoiding the temptation to bloat into knoppix.
- Q: How do I report bugs?
A: anonymous A T nameless. cultists. org .