1 # SOME DESCRIPTIVE TITLE
2 # Copyright (C) YEAR Free Software Foundation, Inc.
3 # This file is distributed under the same license as the PACKAGE package.
4 # FIRST AUTHOR <EMAIL@ADDRESS>, YEAR.
9 "Project-Id-Version: PACKAGE VERSION\n"
10 "POT-Creation-Date: 2013-10-27 00:01+0200\n"
11 "PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n"
12 "Last-Translator: FULL NAME <EMAIL@ADDRESS>\n"
13 "Language-Team: LANGUAGE <LL@li.org>\n"
16 "Content-Type: text/plain; charset=UTF-8\n"
17 "Content-Transfer-Encoding: 8bit\n"
21 msgid "[[!meta title=\"Upgrade to more secure persistence settings\"]]\n"
26 "Tails 0.21 introduces a more secure access control over the persistent "
27 "volume settings. This also means that before Tails 0.21, an attacker who "
28 "could run an exploit from inside your Tails session could corrupt the "
29 "persistent volume settings. By doing this, an attacker could possibly gain "
30 "persistent administrator rights or install malicious software."
35 "For more technical details about the security of the persistent volume, read "
36 "our [[design document|contribute/design/persistence#security]]."
41 msgid "<div id=\"automatic_upgrade\">\n"
46 msgid "Automatic upgrade\n"
51 "We designed a migration mechanism that allows, in most cases, to upgrade "
52 "automatically to those more secure persistent volume settings. To do this "
53 "upgrade, start Tails 0.21 or later, and enable persistence without the "
54 "read-only option. If the upgrade is successful, Tails starts as usual and no "
55 "notification appears. This upgrade is done once and for all. Activating the "
56 "read-only option prevents Tails from starting correctly until the upgrade is "
61 msgid "But this automatic upgrade might not be sufficient in some cases."
64 #. type: Bullet: '1. '
66 "**If you have custom persistence settings or use [[additional software "
67 "packages|configure#additional_software]]**, the corresponding settings are "
68 "not upgraded automatically."
74 " A notification should appear when starting Tails that indicates which\n"
75 " persistence settings are temporarily disabled. In that case, follow\n"
76 " the instructions to [[enable again your custom persistence\n"
77 " settings|upgrade#custom_settings]].\n"
82 msgid " <div class=\"caution\">\n"
88 " If you have custom persistence settings or use additional software\n"
89 " but no notification appear on the desktop, then your Tails system\n"
90 " might be corrupted. In that case, follow the instructions to [[manually "
92 " your persistent data to a new device|upgrade#new_device]].\n"
100 #. type: Bullet: '1. '
102 "**If you have good reasons to think that your persistence settings are "
103 "corrupted** or if you want to be extra careful, then follow the instructions "
104 "to [[manually copy your persistent data to a new "
105 "device|upgrade#new_device]]."
110 msgid "<div id=\"custom_settings\">\n"
115 msgid "Enabling again your custom persistence settings\n"
120 "Custom persistence settings and additional software are disabled during the "
121 "automatic upgrade because, there is technically a possibility for these "
122 "files to be corrupted."
127 "These instructions explain how to verify the content of these files and "
128 "enable again your custom persistence settings."
131 #. type: Bullet: '1. '
133 "Start Tails and set an [[administration "
134 "password|startup_options/administration_password]]."
141 " <span class=\"menuchoice\">\n"
142 " <span class=\"guimenu\">Applications</span> ▸\n"
143 " <span class=\"guisubmenu\">Accessories</span> ▸\n"
144 " <span class=\"guimenuitem\">Root Terminal</span>\n"
146 " to open a terminal with administration rights.\n"
149 #. type: Bullet: '1. '
151 "Execute the <span class=\"code\">nautilus</span> command to open the file "
155 #. type: Bullet: '1. '
157 "In the file browser navigate to <span "
158 "class=\"filename\">/live/persistence/TailsData_unlocked</span>."
163 msgid "<span class=\"filename\">live-persistence.conf.old</span>\n"
169 "If there is a file named\n"
170 "<span class=\"filename\">live-persistence.conf.old</span> in the\n"
171 "<span class=\"filename\">TailsData_unlocked</span> folder, then some of "
173 "persistence settings need to be enabled manually.\n"
176 #. type: Bullet: '1. '
178 "In the file browser, right-click on the <span "
179 "class=\"filename\">live-persistence.conf.old</span> file and open it by "
180 "choosing <span class=\"guilabel\">Open with Other Application...</span> and "
181 "then <span class=\"guilabel\">gedit</span>."
184 #. type: Bullet: '1. '
186 "Switch back to the file browser, right-click on the <span "
187 "class=\"filename\">persistence.conf</span> file and choose <span "
188 "class=\"guilabel\">Open with Other Application...</span> and then <span "
189 "class=\"guilabel\">gedit</span> to open it in a new tab in <span "
190 "class=\"application\">gedit</span>."
193 #. type: Bullet: '1. '
195 "Switch between the two tabs corresponding to those files in <span "
196 "class=\"application\">gedit</span> and compare their content. Copy from "
197 "<span class=\"filename\">live-persistence.conf.old</span> to <span "
198 "class=\"filename\">persistence.conf</span> the lines corresponding to your "
199 "custom settings that have not been upgraded automatically."
204 "Those missing lines should correspond to your custom directories or other "
205 "custom persistence settings."
211 "**If you detect unexpected lines in\n"
212 "<span class=\"filename\">live-persistence.conf.old</span>** that do not\n"
213 "correspond to any change that you have made, they might have been\n"
214 "introduced by an attacker. In this case, do the following:\n"
217 #. type: Bullet: '1. '
219 "[[Report a bug using <span "
220 "class=\"application\">WhisperBack</span>|bug_reporting]] and explain which "
221 "are the lines that look suspicious to you."
224 #. type: Bullet: '1. '
226 "Keep that Tails device without modifying it in order to analyse it later if "
230 #. type: Bullet: '1. '
232 "Follow the instructions to [[manually copy your persistent data to a new "
233 "device|upgrade#new_device]]."
239 "**If you do not detect any suspicious line**, close\n"
240 "<span class=\"application\">gedit</span> and delete the\n"
241 "<span class=\"filename\">live-persistence.conf.old</span> file using the\n"
247 msgid "<span class=\"filename\">live-additional-software.conf.disabled</span>\n"
253 "If there is a file named\n"
254 "<span class=\"filename\">live-additional-software.conf.disabled</span> in\n"
255 "the <span class=\"filename\">TailsData_unlocked</span> folder, then your\n"
256 "[[additional software|configure#additional_software]] need to be enabled\n"
260 #. type: Bullet: '1. '
262 "In the file browser, right-click on the <span "
263 "class=\"filename\">live-additional-software.conf.disabled</span> file and "
264 "open it by choosing <span class=\"guilabel\">Open with Other "
265 "Application...</span> and then <span class=\"guilabel\">gedit</span>."
268 #. type: Bullet: '1. '
270 "Right-click on the <span "
271 "class=\"filename\">live-additional-software.conf</span> file and choose "
272 "<span class=\"guilabel\">Open with Other Application...</span> and then "
273 "<span class=\"guilabel\">gedit</span> to open it in a new tab in <span "
274 "class=\"application\">gedit</span>."
277 #. type: Bullet: '1. '
280 "class=\"filename\">live-additional-software.conf.disabled</span> to <span "
281 "class=\"filename\">live-additional-software.conf</span> the lines "
282 "corresponding to your additional software."
288 "**If you detect unexpected lines in\n"
289 "<span class=\"filename\">live-additional-software.conf.disabled</span>**\n"
290 "that do not correspond to any additional software added by you, they\n"
291 "might have been introduced by an attacker. In this case, do the\n"
298 "**If you do not detect any suspicious line**, close\n"
299 "<span class=\"application\">gedit</span> and delete the\n"
300 "<span class=\"filename\">live-additional-software.conf.disabled</span>\n"
301 "file using the file browser.\n"
306 msgid "<div id=\"new_device\">\n"
311 msgid "Manually copying your persistent data to a new device\n"
316 "These instructions explain how to manually copy your persistent data to a "
317 "new device. Follow them if you have good reasons to think that your "
318 "persistence settings are corrupted or if want to be extra careful."
323 msgid "Create a new device\n"
326 #. type: Bullet: '1. '
328 "Install Tails 0.21 or later onto a new device using the usual [[installing "
329 "instructions|installation]]. Do not use the Tails device that might be "
330 "corrupted in the process of installing the new one."
333 #. type: Bullet: '1. '
335 "[[Create a persistent volume|configure]] on this new device. We advice you "
336 "to use a different passphrase to protect this new persistent volume."
339 #. type: Bullet: '1. '
340 msgid "Enable again on this new device the persistence features of your choice."
343 #. type: Bullet: '1. '
344 msgid "Restart Tails and enable persistence."
349 msgid "Rescue your files from the old Tails device\n"
352 #. type: Bullet: '1. '
353 msgid "Plug in the old Tails device from which you want to rescue your data."
360 " <span class=\"menuchoice\">\n"
361 " <span class=\"guimenu\">Applications</span> ▸\n"
362 " <span class=\"guisubmenu\">System Tools</span> ▸\n"
363 " <span class=\"guimenuitem\">Disk Utility</span>\n"
365 " to open the <span class=\"application\">GNOME Disk Utility</span>.\n"
368 #. type: Bullet: '1. '
370 "In the left panel, click on the device corresponding to the old Tails "
374 #. type: Bullet: '1. '
376 "In the right panel, click on the partition labeled as <span "
377 "class=\"guilabel\">Encrypted</span>. The <span class=\"guilabel\">Partition "
378 "Label</span> must be <span class=\"label\">TailsData</span>."
381 #. type: Bullet: '1. '
383 "Click on <span class=\"guilabel\">Unlock Volume</span> to unlock the old "
384 "persistent volume. Enter the passphrase of the old persistent volume and "
385 "click <span class=\"guilabel\">Unlock</span>."
388 #. type: Bullet: '1. '
390 "Click on the <span class=\"guilabel\">TailsData</span> partition that "
391 "appears below the <span class=\"guilabel\">Encrypted Volume</span> "
395 #. type: Bullet: '1. '
397 "Click on <span class=\"guilabel\">Mount Volume</span>. The old persistent "
398 "volume is now mounted as <span class=\"filename\">/media/TailsData</span>."
405 " <span class=\"menuchoice\">\n"
406 " <span class=\"guimenu\">Places</span> ▸\n"
407 " <span class=\"guimenuitem\">TailsData</span>\n"
409 " from the top navigation bar to open the old persistent volume.\n"
415 "1. In the file browser, choose\n"
416 " <span class=\"menuchoice\">\n"
417 " <span class=\"guimenu\">File</span> ▸\n"
418 " <span class=\"guimenuitem\">New Tab</span>\n"
421 " <span class=\"filename\">/live/persistence/TailsData_unlocked</span> in\n"
425 #. type: Bullet: '1. '
426 msgid "Click on the <span class=\"guilabel\">TailsData</span> tab."
429 #. type: Bullet: '1. '
431 "To import a folder containing persistent data from the old persistent volume "
432 "to the new one, drag and drop that folder from the <span "
433 "class=\"guilabel\">TailsData</span>onto the <span "
434 "class=\"guilabel\">TailsData_unlocked</span> tab. When importing a folder, "
435 "choose to <span class=\"guilabel\">Merge All</span> the folder, and <span "
436 "class=\"guilabel\">Replace All</span> files. Do not import a folder if you "
437 "do not know what it is used for."
440 #. type: Bullet: ' - '
442 "The <span class=\"filename\">apt</span> folder corresponds to the <span "
443 "class=\"guilabel\">[[APT Packages|configure#apt_packages]]</span> and <span "
444 "class=\"guilabel\">[[APT Lists|configure#apt_lists]]</span> persistence "
445 "features. But it requires administration rights to be imported and this goes "
446 "beyond the scope of these instructions. Note that this folder does not "
447 "contain personal data."
450 #. type: Bullet: ' - '
452 "The <span class=\"filename\">bookmarks</span> folder corresponds to the "
453 "<span class=\"guilabel\">[[Browser "
454 "bookmarks|configure#browser_bookmarks]]</span> persistence feature."
457 #. type: Bullet: ' - '
459 "The <span class=\"filename\">claws-mail</span> folder corresponds to the "
460 "<span class=\"guilabel\">[[Claws Mail|configure#claws_mail]]</span> "
461 "persistence feature."
464 #. type: Bullet: ' - '
466 "The <span class=\"filename\">dotfiles</span> folder corresponds to the <span "
467 "class=\"guilabel\">[[Dotfiles|configure#dotfiles]]</span> persistence "
471 #. type: Bullet: ' - '
473 "The <span class=\"filename\">gnome-keyring</span> folder corresponds to the "
474 "<span class=\"guilabel\">[[GNOME Keyring|configure#gnome_keyring]]</span> "
475 "persistence feature."
478 #. type: Bullet: ' - '
480 "The <span class=\"filename\">gnupg</span> folder corresponds to the <span "
481 "class=\"guilabel\">[[GnuPG|configure#gnupg]]</span> persistence feature."
484 #. type: Bullet: ' - '
486 "The <span class=\"filename\">nm-connections</span> folder corresponds to the "
487 "<span class=\"guilabel\">[[Network "
488 "Connections|configure#network_connections]]</span> persistence feature."
491 #. type: Bullet: ' - '
493 "The <span class=\"filename\">openssh-client</span> folder corresponds to the "
494 "<span class=\"guilabel\">[[SSH Client|configure#ssh_client]]</span> "
495 "persistence feature."
498 #. type: Bullet: ' - '
500 "The <span class=\"filename\">Persistent</span> folder corresponds to the "
501 "<span class=\"guilabel\">[[Personal Data|configure#personal_data]]</span> "
502 "persistence feature."
505 #. type: Bullet: ' - '
507 "The <span class=\"filename\">pidgin</span> folder corresponds to the <span "
508 "class=\"guilabel\">[[Pidgin|configure#pidgin]]</span> persistence feature."