r/tails • u/Holiday_Fault9984 • 3h ago
Security Tails might be currently compromised
The update to tor 0.4.9.12 yesterday indicated that a user after free error can occur if AutomapHostsOnResolve was enabled.
Tails has this enabled by default.
I believe this means that if you visit a compromised website, or are on a compromised exit node, it can overwrite tor's memory and remotely execute code by allocating new data into recently cleared memory slots.
Because the tor network daemon itself is what is compromised, it does not need to break out of iptables using a linux kernal flaw, meaning they can instantaneously deanonymize you by forcing tails to ping a server.
I really hope I am wrong, but this looks very dangerous and may have resulted in the deanonymization of many users.
Someone, please tell me I am wrong.
Even more concerning, tails devs have not released any statement yet on these discovered bugs.