Hello everyone!
After 3 years working on DTails a tool used to remaster a Tails/Debian based OS to add curated privacy and Bitcoin tools without the need to enable persistence partition, got reproducible builds recently.
ℹ️ Same base image + same package selection = identical file, on any machine, verifiable by anyone rebuilding from the published manifest.
As well I release Dtails-7.10.1.img ready to use. I recommend to check the signature before flashing. This is the manifest:
DTails-amd64-7.10.1 build manifest
base image : tails-amd64-7.10.1.img
base sha256: b0a5f45e79221abe2c34f6e03f0cbf6b15af5e1df7c2e60cbf5c9af7586beb6f
output : DTails-amd64-7.10.1.img (2258.0 MiB)
sha256 : f37c4ae7765844031d1f28475a4391975e145b9ac25a540bbef56a2a6efaf375
flashed to : /dev/sda
build epoch: 1231006505 (SOURCE_DATE_EPOCH — reproducible)
Installed (13):
+ BIP39 (iancoleman) offline v0.5.4
+ Bitcoin Core v31.1
+ Border Wallets (offline) v1.0.5
+ Hodl Hodl (web launcher) v1.0
+ Iris.to (web launcher) v1.0
+ Liana Wallet v14.0
+ Mempool.space (web launcher) v1.0
+ Rana (Nostr pubkeys mining) v0.5.5
+ RoboSats (web launcher) v1.0
+ Seedtool (offline) v2.2.0
+ Snort (web launcher) v1.0
+ Sparrow Wallet v2.5.2
+ Specter Desktop v2.1.10
Removed (2):
- GIMP
- Thunderbird
Reproducible: the same base image + same selection rebuilds to the
same SHA256. Share this manifest so others can verify the hash.I recommend visiting the project's website.
I'd be happy to answer any questions or address any concerns or suggestions you may have!
DT - 4559 764E 1410 9E7F
Well done! I look forward to exploring more closely and verifying what you have made here.
With the whole Coldcard fiasco, I am reevaluating cold storage options and have been exploring TailsOS as a potential solution among many.
Tails gives a few benefits: Being able to enter a passphrase and manage wallets and files in a full desktop environment is much easier with a full keyboard etc.
For Tails I really wanted to be able to use Sparrow. Electrum is iconic, but it is just not the right tool for me in this case for a few reasons (Not really designed for BIP39 seedphrases etc).
I worked out how to get Sparrow working in Tails persistently by setting up a sparrow.desktop launcher file in the dotfiles directory and pointing it to the extracted tarball, but the issue was how to get the config and wallets to persist between reboots.
I ended up using the -d flag in the launcher to point to its own folder in amnesia/Persistent that makes it clean and simple.
@DesobedienteTec If this project is not using persistent storage, how does it handle storing the config and wallets for Sparrow? Where do they live? Or do you need to keep them on a seperate storage device etc?
Thank you!
After that fiasco as you said, I think old school still solid as rock for many things.
By default persistent partition is not enabled/configured. To store config and wallets you have to configure the partition manually and enable dotfiles.
You can also have another storage device which you can mount as /home/amensia and have all your configuration even in a LUKS or Veracrypt/Truecrypt partition or file.
Do you think persistence for e.g. wallets would be a good default to have?
Is there any security or operational issue with having the seed / wallets stored in persistent that you can think of? What about even having passphrase etc on there too (textfile?)?
My understanding is passphrase is designed for a cold card or evil maid scenario where the seed is compromised, but if the tailsOS is behind a long encrypted partition password already, can it be stored in plaintext or a password manager on the device do you think? Or is my security thinking wrong here?
How did I not know about this, great work!
Thanks! I hope more people hear about the project.
I always forget how it's called when I need it. Why is this always so hard to find? I know that I want "the application to create your own version of Tails OS" and it never shows up in any searches. I somehow usually try BTails, because I think it's related to bitcoin, but that's a different thing.
Can be hard to find probably because of the name sure. Dtails is similar to the word Details or even D'tails, and web searches do not match it well just yet. Let's give more time to people use the tool/OS and hopefully they write about it in blogs, podcast... etc.
Bests!
This looks awesome! A comprehensive amnesic Bitcoin OS.
I was also looking into Tails and had seen DTails crop up in search results but had yet to investigate it. Looks like it's time for me to fully dive into deterministic/reproducible builds and how to verify them. The project certainly looks useful and something like a bitcoin's dream temporary system! Is the persistent partition still available for wallet data and for saving the welcome screen settings and such?
I'm happy you like the project!
Persistent partition is not enabled by default, you have to create it, and then enable dotfiles in order to get your data wallet, etc.
If you have any questions, I'll be here or on social media to help you out.
I use it with success and also taught others how to use it.
Cool! Good to know you use it.
Reproducible builds are the feature that matters most here, 'trust me bro' is not a security model and the manifest kills that whole class of doubt. Same image, same selection, same hash, on any machine, that's verifiable sovereignty. 13 curated tools and they still cut GIMP and Thunderbird, that's someone who understands attack surface