1 tails (0.6.1) unstable; urgency=low
3 * Tor: upgrade to 0.1.28 (fixes CVE-2010-1676)
4 * Software: upgrade NSS, Xulrunner, glibc (fixes various security issues)
5 * FireGPG: use the same keyserver as the one configured in gpg.conf.
6 * Seahorse: use same keyserver as in gpg.conf.
7 * HTP: display the logs when the clock synchronization fails.
8 * Update HTP configuration: www.google.com now redirects to
10 * Use the light version of the "Are you using Tor?" webpage.
11 * Update AdBlock patterns.
13 -- T(A)ILS developers <amnesia@boum.org> Fri, 24 Dec 2010 13:28:29 +0100
15 tails (0.6) unstable; urgency=low
19 * New OpenPGP signing-only key. Details are on the website:
20 https://amnesia.boum.org/GnuPG_key/
23 - Fixed torbutton has migrated to testing, remove custom package.
26 - Query ssl.scroogle.org instead of lists.debian.org.
27 - Don't run when the interface that has gone up is the loopback one.
30 - Add shortcut to securely erase free space in a partition.
31 - The nautilus-wipe shortcut user interface is now translatable.
34 - Really fix virtualization warning display.
35 - More accurate APT pinning.
36 - Disable Debian sid APT source again since a fixed live-config has
37 migrated to Squeeze since then.
39 * live-boot: upgrade to 2.0.8-1+tails1.13926a
40 - Sometimes fixes the smem at shutdown bug.
41 - Now possible to create a second partition on the USB stick T(A)ILS is
45 - Support RT2860 wireless chipsets by installing firmware-ralink from
47 - Install firmware-linux-nonfree from backports.
48 - Fix b43 wireless chipsets by having b43-fwcutter extract firmwares at
52 - Install live-build and live-helper from Squeeze.
53 - Update SquashFS sort file.
55 -- T(A)ILS developers <amnesia@boum.org> Wed, 20 Oct 2010 19:53:17 +0200
57 tails (0.6~rc3) UNRELEASED; urgency=low
59 ** SNAPSHOT build @a3ebb6c775d83d1a1448bc917a9f0995df93e44d **
62 - Autostart Iceweasel with the GNOME session. This workarounds the
63 "Iceweasel first page is not loaded" bug.
66 - Upgrade htpdate script (taken from Git 7797fe9).
69 - Disable ssh-agent auto-starting with X session: gnome-keyring is
71 - Fix virtualization warning display.
72 - Boot profile hook: write desktop file to /etc/skel.
75 - Convert build system to live-build 2.0.1.
76 - APT: fetch live-build and live-helper from Debian Live snapshots.
77 - Remove dependency on live-build functions in chroot_local-hooks.
78 This makes the build environment more robust and less dependent on
80 - Remove hand-made rcS.d/S41tails-wifi: a hook now does this.
81 - Measure time used by the lh build command.
82 - Fix boot profile hook.
83 - Boot profiling: wait a bit more: the current list does not include
86 -- T(A)ILS developers <amnesia@boum.org> Sat, 02 Oct 2010 23:06:46 +0200
88 tails (0.6~rc2) UNRELEASED; urgency=low
90 ** SNAPSHOT build @c0ca0760ff577a1e797cdddf0e95c5d62a986ec8 **
93 - Refreshed AdBlock patterns (20100926).
94 - Set network.dns.disableIPv6 to true (untested yet)
95 - Torbutton: install patched 1.2.5-1+tails1 to fix the User-Agent bug,
96 disable extensions.torbutton.spoof_english again.
99 - WhisperBack: upgrade to 1.3~beta3 (main change: let the user provide
100 optional email address and OpenPGP key).
102 - Update haveged backport to 0.9-3~amnesia+lenny1.
103 - Update live-boot custom packages (2.0.6-1+tails1.6797e8): fixes bugs
104 in persistency and smem-on-shutdown.
105 - Update custom htpdate script. Taken from commit d778a6094cb3 in our
106 custom Git repository: fixes setting of date/time.
109 - Bugfix: failed builds are now (hopefully) detected.
110 - Fix permissions on files in /etc/apt/ that are preserved in the image.
111 - Install version 2.0~a21-1 of live-build and live-helper in the image.
112 We are too late in the release process to upgrade to current Squeeze
116 - Pidgin/OTR: disable the automatic OTR initiation and OTR requirement.
118 -- T(A)ILS developers <amnesia@boum.org> Wed, 29 Sep 2010 19:23:17 +0200
120 tails (0.6~1.gbpef2878) UNRELEASED; urgency=low
122 ** SNAPSHOT build @ef28782a0bf58004397b5fd303f938cc7d11ddaa **
125 - Use a 2.6.32 kernel: linux-image-2.6.32-bpo.5-686 (2.6.32-23~bpo50+1)
126 from backports.org. This should support far more hardware and
127 especially a lot of wireless adapters.
128 - Add firmware for RTL8192 wireless adapters.
129 - Enable power management on all wireless interfaces on boot.
134 - Install gfshare and ssss: two complementary implementations
135 of Shamir's Secret Sharing.
136 - Install tor-geoipdb.
137 - Remove dialog, mc and xterm.
140 - Set extensions.torbutton.spoof_english to its default true value
141 in order to workaround a security issue:
142 https://amnesia.boum.org/security/Iceweasel_exposes_a_rare_User-Agent/
145 - Install the Iceweasel extension.
146 - Use a hkps:// keyserver.
149 - Install gnupg from backports.org so that hkps:// is supported.
150 - Use a hkps:// keyserver.
151 - Proxy traffic via polipo.
152 - Prefer up-to-date digests and ciphers.
154 * Vidalia: rebased our custom package against 0.2.10.
157 - Built images are now named like this:
158 tails-i386-lenny-0.5-20100925.iso
159 - Use live-helper support for isohybrid options instead of doing the
160 conversion ourselves. The default binary image type we build is now
162 - Remove .deb built by m-a after they have been installed.
163 - Setup custom GConf settings at build time rather than at boot time.
164 - Move $HOME files to /etc/skel and let adduser deal with permissions.
165 - Convert to live-boot / live-config / live-build 2.x branches.
166 - Replaced our custom live-initramfs with a custom live-boot package;
167 included version is 2.0.5-1+tails2.6797e8 from our Git repository:
168 git clone git://git.immerda.ch/tails_live-boot.git
169 - Install live-config* from the live-snapshots Lenny repository.
170 Rationale: live-config binary packages differ depending on the target
171 distribution, so that using Squeeze's live-config does not produce
172 fully-working Lenny images.
173 - Rename custom scripts, packages lists and syslinux menu entries from
174 the amnesia-* namespace to the tails-* one.
177 - Use (authenticated) HTP instead of NTP.
178 - The htpdate script that is used comes from commit 43f5f83c0 in our
179 custom repository: git://git.immerda.ch/tails_htp.git
180 - Start Tor and Vidalia only once HTP is done.
183 - Fix IPv6 firewall restore file. It was previously not used at all.
184 - Use ftp.us.debian.org instead of the buggy GeoIP-powered
186 - Gedit: don't autocreate backup copies.
187 - Build images with syslinux>=4.01 that has better isohybrid support.
188 - amnesia-security-check: got rid of the dependency on File::Slurp.
189 - Take into account the migration of backports.org to backports.debian.org.
190 - Make GnuPG key import errors fatal on boot.
191 - Warn the user when T(A)ILS is running inside a virtual machine.
192 - DNS cache: forget automapped .onion:s on Tor restart.
194 * Documentation: imported Incognito's walkthrough, converted to
195 Markdown, started the needed adaptation work.
197 -- T(A)ILS developers <amnesia@boum.org> Sun, 26 Sep 2010 11:06:50 +0200
199 tails (0.5) unstable; urgency=low
201 * The project has merged efforts with Incognito.
202 It is now to be called "The (Amnesic) Incognito Live System".
206 - Created the amnesia-news mailing-list.
207 - Added a forum to the website.
208 - Created a chatroom on IRC: #tails on irc.oftc.net
211 - Workaround nasty NetworkManager vs. Tor bug that often
212 prevented the system to connect to the Tor network: restart Tor and Vidalia
213 when a network interface goes up.
214 - onBoard now autodetects the keyboard layout... at least once some
215 keys have been pressed.
216 - New windows don't open in background anymore, thanks to
218 - Memory wiping at shutdown is now lightning fast, and does not prevent
219 the computer to halt anymore.
220 - GNOME panel icons are right-aligned again.
221 - Fixed permissions on APT config files.
222 - Repaired mouse integration when running inside VirtualBox.
225 - Torbutton: redirect to Scroogle when presented a Google captcha.
227 . moved T(A)ILS own website to the personal toolbar
228 . moved webmail links (that are expected to be more than 3 soon)
229 to a dedicated folder.
230 - Don't show AdBlock Plus icon in the toolbar.
231 - Adblock Plus: updated patterns, configured to only update subscriptions
232 once a year. Which means never, hopefully, as users do update their
233 Live system on a regular basis, don't they?
235 * Vidalia: rebased our custom package against 0.2.8.
238 - Install Claws Mail from backports.org to use the X.509 CA
239 certificates provided by Debian.
240 - Enable PGP modules with basic configuration:
241 . Automatically check signatures.
242 . Use gpg-agent to manage passwords.
243 . Display warning on start-up if GnuPG doesn't work.
244 - Set the IO timeout to 120s (i.e. the double of the default 60s).
247 - Automatically connect to irc.oftc.net with a randomized nickname,
248 so as not to advertize the use of T(A)ILS; this nickname is made of:
249 . a random firstname picked from the 2000 most registered by the U.S.
250 social security administration in the 70s;
252 Good old irc.indymedia.org is still configured - with same nickname -
253 but is not enabled by default anymore.
254 - Disabled MSN support, that is far too often affected by security flaws.
256 * Build $HOME programmatically
257 - Migrated all GConf settings, including the GNOME panel configuration,
258 to XML files that are loaded at boot time.
259 - Configure iceweasel profile skeleton in /etc/iceweasel.
260 A brand new profile is setup from this skeleton once iceweasel is
262 . build sqlite files at build time from plain SQL.
263 . FireGPG: hard-code current firegpg version at build time to prevent
264 the extension to think it was just updated.
265 . stop shipping binary NSS files. These were here only to
266 install CaCert's certificate, that is actually shipped by Debian's
270 - Updated Debian Live snapshots APT repository URL.
271 - Purge all devel packages at the end of the chroot configuration.
272 - Make sure the hook that fixes permissions runs last.
273 - Remove unwanted Iceweasel search plugins at build time.
276 - Added a progress bar for boot time file readahead.
277 - Readahead more (~37MB) stuff in foreground at boot time.
278 - Make the APT pinning persist in the Live image.
279 - localepurge: keep locales for all supported languages,
280 don't bother when installing new packages.
281 - Removed syslinux help menu: these help pages are either buggy or
282 not understandable by non-geeks.
283 - Fixed Windows autorun.
284 - Disable a few live-initramfs scripts to improve boot time.
285 - Firewall: forbid any IPv6 communication with the outside.
286 - Virtualization support: install open-vm-tools.
287 - WhisperBack: updated to 1.2.1, add a random bug ID to the sent
289 - Prompt for CD removal on shutdown, not for USB device.
291 * live-initramfs: new package built from our Git (e2890a04ff) repository.
292 - Merged upstream changes up to 1.177.2-1.
293 - New noprompt=usb feature.
294 - Fix buggy memory wiping and shutdown.
295 - Really reboot when asked, rather than shutting down the system.
298 - Upgraded to a new custom, patched package (0.93.0-0ubuntu4~amnesia1).
299 - Added an entry in the Applications menu.
302 - Install vim-nox with basic configuration
304 - Install monkeysphere and msva-perl
305 - Replaced randomsound with haveged as an additional source of entropy.
308 - Build ralink rt2570 wifi modules.
309 - Build rt2860 wifi modules from Squeeze. This supports the RT2860
310 wireless adapter, found particularly in the ASUS EeePC model 901
312 - Build broadcom-sta-source wifi modules.
313 - Bugfix: cpufreq modules were not properly added to /etc/modules.
314 - Use 800x600 mode on boot rather than 1024x768 for compatibility
315 with smaller displays.
317 -- amnesia <amnesia@boum.org> Fri, 30 Apr 2010 16:14:13 +0200
319 amnesia (0.4.2) unstable; urgency=low
321 New release, mainly aimed at fixing live-initramfs security issue
322 (Debian bug #568750), with an additional set of small enhancements as
325 * live-initramfs: new custom package built from our own live-initramfs
326 Git repository (commit 8b96e5a6cf8abc)
327 - based on new 1.173.1-1 upstream release
328 - fixed live-media=removable behaviour so that filesystem images found
329 on non-removable storage are really never used (Debian bug #568750)
331 * Vidalia: bring back our UI customizations (0.2.7-1~lenny+amnesia1)
333 * APT: consistently use the GeoIP-powered cdn.debian.net
335 * Software: make room so that {alpha, future} Squeeze images fit on
337 - only install OpenOffice.org's calc, draw, impress, math and writer
339 - removed OpenOffice.org's English hyphenation and thesaurus
340 - removed hunspell, wonder why it was ever added
343 - explicitly disable persistence, better safe than sorry
344 - removed compulsory 15s timeout, live-initramfs knows how to wait for
345 the Live media to be ready
347 * Build system: don't cache rootfs anymore
349 -- amnesia <amnesia@boum.org> Sun, 07 Feb 2010 18:28:16 +0100
351 amnesia (0.4.1) unstable; urgency=low
353 * Brown paper bag bugfix release: have amnesia-security-check use
354 entries publication time, rather than update time... else tagging
355 a security issue as fixed, after releasing a new version, make this
356 issue be announced to every user of this new, fixed version.
358 -- amnesia <amnesia@boum.org> Sat, 06 Feb 2010 03:58:41 +0100
360 amnesia (0.4) unstable; urgency=low
362 * We now only build and ship "Hybrid" ISO images, which can be either
363 burnt on CD-ROM or dd'd to a USB stick or hard disk.
365 * l10n: we now build and ship multilingual images; initially supported
366 (or rather wanna-be-supported) languages are: ar, zh, de, en, fr, it,
368 - install Iceweasel's and OpenOffice.org's l10n packages for every
370 - stop installing localized help for OpenOffice.org, we can't afford it
372 - when possible, Iceweasel's homepage and default search engine are localized
373 - added Iceweasel's "any language" Scroogle SSL search engine
374 - when the documentation icon is clicked, display the local wiki in
375 currently used language, if available
376 - the Nautilus wipe script is now translatable
377 - added gnome-keyboard-applet to the Gnome panel
380 - replaced Icedove with claws mail, in a bit rough way; see
381 https://amnesia.boum.org/todo/replace_icedove_with_claws/ for best
382 practices and configuration advices
383 - virtual keyboard: install onBoard instead of kvkbd
384 - Tor controller: install Vidalia instead of TorK
385 - install only chosen parts of Gnome, rather than gnome-desktop-environment
386 - do not install xdialog, which is unused and not in Squeeze
387 - stop installing grub as it breaks Squeeze builds (see Debian bug #467620)
388 - install live-helper from snapshots repository into the Live image
391 - do not install the NoScript extension anymore: it is not strictly
392 necessary but bloodily annoying
394 * Provide WhisperBack 1.2 for anonymous, GnuPG-encrypted bug reporting.
395 - added dependency on python-gnutls
396 - install the SMTP hidden relay's certificate
398 * amnesia-security-check: new program that tells users that the amnesia
399 version they are running is affected by security flaws, and which ones
400 they are; this program is run at Gnome session startup, after sleeping
401 2 minutes to let Tor a chance to initialize.
404 - uses the Desktop Notifications framework
405 - fetches the security atom feed from the wiki
406 - verifies the server certificate against its known CA
407 - tries fetching the localized feed; if it fails, fetch the default
410 * live-initramfs: new custom package built from our own live-initramfs
411 Git repository (commit 40e957c4b89099e06421)
412 - at shutdown time, ask the user to unplug the CD / USB stick, then run
413 smem, wait for it to finish, then attempt to immediately halt
416 - bumped dependency on live-helper to >= 2.0a6 and adapted our config
417 - generate hybrid ISO images by default, when installed syslinux is
419 - stop trying to support building several images in a row, it is still
420 broken and less needed now that we ship hybrid ISO images
421 - scripts/config: specify distribution when initializing defaults
422 - updated Debian Live APT repository's signing key
425 - disable virtualbox packages installing and module building on !i386
426 && !amd64, as PowerPC is not a supported guest architecture
427 - built and imported tor_0.2.1.20-1~~lenny+1_powerpc.deb
430 - rough beginnings of a scratch Squeeze branch, currently unsupported
431 - install gobby-infinote
434 - updated GnuPG key with up-to-date signatures
435 - more improvements on boot time from CD
436 - enhanced the wipe in Nautilus UI (now asks for confirmation and
437 reports success or failure)
438 - removed the "restart Tor" launcher from the Gnome panel
440 -- amnesia <amnesia@boum.org> Fri, 05 Feb 2010 22:28:04 +0100
442 amnesia (0.3) unstable; urgency=low
444 * software: removed openvpn, added
450 - lvm2 (with disabled initscript as it slows-down too much the boot in certain
452 - NetworkManager 0.7 (from backports.org) to support non-DHCP networking
454 - randomsound to enhance the kernel's random pool
456 - install the latest stable release from deb.torproject.org
457 - ifupdown script now uses SIGHUP signal rather than a whole tor
458 restart, so that in the middle of it vidalia won't start it's own
460 - configure Gnome proxy to use Tor
462 - adblockplus: upgraded to 1.0.2
463 - adblockplus: subscribe to US and DE EasyList extensions, updated patterns
464 - firegpg is now installed from Debian Squeeze rather than manually; current
465 version is then 0.7.10
466 - firegpg: use better keyserver ... namely pool.sks-keyservers.net
467 - added bookmark to Amnesia's own website
468 - use a custom "amnesiabranding" extension to localize the default search
469 engine and homepage depending on the current locale
470 - updated noscript whitelist
471 - disable overriden homepage redirect on iceweasel upgrade
473 - nicer default configuration with verified irc.indymedia.org's SSL cert
474 - do not parse incoming messages for formatting
475 - hide formatting toolbar
476 * hardware compatibility
478 - beginning of support for the ppc architecture
479 - load acpi-cpufreq, cpufreq_ondemand and cpufreq_powersave kernel
481 * live-initramfs: custom, updated package based on upstream's 1.157.4-1, built
482 from commit b0a4265f9f30bad945da of amnesia's custom live-initramfs Git
484 - securely erases RAM on shutdown using smem
485 - fixes the noprompt bug when running from USB
486 - disables local swap partitions usage, wrongly enabled by upstream
487 * fully support for running as a guest system in VirtualBox
488 - install guest utils and X11 drivers
489 - build virtualbox-ose kernel modules at image build time
491 - new (translatable) wiki, using ikiwiki, with integrated bugs and todo
492 tracking system a static version of the wiki is included in generated
493 images and linked from the Desktop
495 - adapt for live-helper 2.0, and depend on it
496 - get amnesia version from debian/changelog
497 - include the full version in ISO volume name
498 - save .list, .packages and .buildlog
499 - scripts/clean: cleanup any created dir in binary_local-includes
500 - updated Debian Live snapshot packages repository URL and signing key
501 - remove duplicated apt/preferences file, the live-helper bug has been
503 * l10n: beginning of support for --language=en
505 - improved boot time on CD by ordering files in the squashfs in the order they
507 - added a amnesia-version script to built images, that outputs the current
509 - added a amnesia-debug script that prepares a tarball with information that
510 could be useful for developpers
511 - updated Amnesia GnuPG key to a new 4096R one
512 - set time with NTP when a network interface is brought up
513 - import amnesia's GnuPG pubkey into the live session user's keyring
514 - do not ask DHCP for a specific hostname
515 - install localepurge, only keep en, fr, de and es locales, which reduces the
516 generated images' size by 100MB
517 - added a hook to replace /sbin/swapon with a script that only runs
519 - moved networking hooks responsibility from ifupdown to NetworkManager
521 -- amnesia <amnesia@boum.org> Thu, 26 Nov 2009 11:17:08 +0100
523 amnesia (0.2) unstable; urgency=low
525 * imported /home/amnesia, then:
526 - more user-friendly shell, umask 077
527 - updated panel, added launcher to restart Tor
528 - mv $HOME/bin/* /usr/local/bin/
529 - removed metacity sessions
530 - removed gstreamer's registry, better keep this dynamically updated
531 - rm .qt/qt_plugins_3.3rc, better keep this dynamically updated
532 - removed .gnome/gnome-vfs/.trash_entry_cache
533 - removed kconf_update log
534 - removed and excluded Epiphany configuration (not installed)
537 - enable caching in RAM
538 - explicitly disable ssl v2, and enable ssl v3 + tls
539 - removed prefs for the non-installed webdeveloper
540 - removed the SSL Blacklist extension (not so useful, licensing issues)
541 - deep profile directory cleanup
542 - extensions cleanup: prefer Debian-packaged ones, cleanly reinstalled
543 AddBlock Plus and CS Lite to allow upgrading them
544 - updated pluginreg.dat and localstore.rdf
545 - moved some settings to user.js
546 - made cookie/JavaScript whitelists more consistent
547 - force httpS on whitelisted sites
548 - NoScript: marked google and gmail as untrusted
549 - some user interface tweaks, mainly for NoScript
550 - FireGPG: disable the buggy auto-detection feature, the link to firegpg's
551 homepage in generated pgp messages and the GMail interface (which won't
552 work without JavaScript anyway)
553 - updated blocklist.xml
554 - removed and excluded a bunch of files in the profile directory
555 * icedove: clean the profile directory up just like we did for iceweasel
556 * software: install msmtp and mutt
558 - use rsync rather than tar
561 - reviewed pidgin-otr security (see TODO)
563 - stop calling home-refresh in lh_build
564 - include home-refresh in generated images
566 - fix permissions on local includes at build time
567 - updated scripts/{build,clean} wrt. new $HOME handling
568 - scripts/{build,config}: stop guessing BASEDIR, we must be run from
569 the root of the source directory anyway
570 - stop storing /etc/amnesia/version in Git, delete it at clean time
572 - converted Changelog to the Debian format and location, updated
573 build scripts accordingly
574 - added a README symlink at the root of the source directory
575 - basic debian/ directory (not working for building packages yet,
576 but at least we can now use git-dch)
577 - added debian/gbp.conf with our custom options for git-dch
578 - config/amnesia: introduce new $AMNESIA_DEV_* variables to be used
579 by developpers' scripts
580 - added ./release script: a wrapper around git-dch, git-commit and git-tag
582 -- amnesia <amnesia@boum.org> Tue, 23 Jun 2009 14:42:03 +0200
584 amnesia (0.1) UNRELEASED; urgency=low
586 * Forked Privatix 9.03.15, by Markus Mandalka:
587 http://mandalka.name/privatix/index.html.en
588 Everything has since been rewritten or so heavily changed that nothing
589 remains from the original code... apart of a bunch of Gnome settings.
591 - install a bunch of non-free wifi firmwares
592 - install xsane and add the live user to the scanner group
593 - install aircrack-ng
594 - install xserver-xorg-video-geode on i386 (eCafe support)
595 - install xserver-xorg-video-all
596 - install firmware-linux from backports.org
597 - install system-config-printer
598 - added instructions in README.eCAFE to support the Hercules eCAFE EC-800
601 - configure pinning to support installing chosen packages from
602 squeeze; the APT source for testing is hardcoded in chroot_sources/,
603 since there is no way to use $LH_CHROOT_MIRROR in chroot_local-hooks
604 - give backports.org priority 200, so that we track upgrades of packages
606 * release: include the Changelog and TODO in the generated images,
607 in the /usr/share/doc/amnesia/ directory
608 * software: install gnomebaker when building Gnome-based live OS, to
609 easily clone myself when running from CD
611 - build i386 images when the build host is amd64
612 - added a version file: /etc/amnesia/version
613 - use snapshot live-* packages inside the images
614 - setup timezone depending on the chosen build locale
615 - rely on standard live-initramfs adduser to do our user setup
616 (including sudo vs. Gnome/KDE, etc.)
617 - stop "supporting" KDE
618 - allow building several images at once
619 - migrated most of lh_config invocations to scripts/config
620 - append "noprompt" so that halting/rebooting work with splashy
621 - moved our own variables to config/amnesia, using the namespace
624 - default search engine is now Scroogle SSL, configured to search pages
625 in French language; the English one is also installed
626 - never ask to save passwords or forms content
627 - configured the torbutton extension to use polipo
628 - installed the CACert root certificate
629 - installed the SSL Blacklist extension and the blacklist data
630 - installed the FireGPG extension
631 - installed the CS Lite extension
632 - installed the NoScript extension
633 - NoScript, CS Lite: replaced the default whitelists with a list of
634 trusted, non-commercial Internet Service Providers
635 - configure extensions (add to prefs.js):
636 user_pref("extensions.torbutton.startup", true);
637 user_pref("extensions.torbutton.startup_state", 1);
638 user_pref("extensions.torbutton.tor_enabled", true);
639 user_pref("noscript.notify.hide", true);
640 user_pref("capability.policy.maonoscript.sites", "about:
641 about:blank about:certerror about:config about:credits
642 about:neterror about:plugins about:privatebrowsing
643 about:sessionrestore chrome: resource:");
644 user_pref("extensions.firegpg.no_updates", true);
645 - install the NoScript plugin from Debian squeeze
646 - delete urlclassifier3.sqlite on $HOME refresh: as we disabled
647 "safebrowsing", this huge file is of no use
648 - torbutton: install newer version from Squeeze
649 * linux: removed non-686 kernel flavours when building i386 images
650 * compatibility: append "live-media=removable live-media-timeout=15", to
651 prevent blindly booting another debian-live installed on the hard disk
655 - cryptkeeper: Gnome system tray applet to encrypt files with EncFS
656 - kvkbd: virtual keyboard (installed from backports.org)
657 - sshfs (and added live user to the fuse group)
658 - less, secure-delete, wipe, seahorse, sshfs, ntfs-3g
661 - enable the transparent proxy, the DNS resolver, and the control port
662 - save authentication cookie to /tmp/control_auth_cookie, so that the
663 live user can use Tork and co.
664 - autostart Tork with Gnome
665 - Tork: installed, disabled most notifications and startup tips
666 - added a restart tor hook to if-up.d (used by Network Manager as well),
667 so that Tor does work immediately even if the network cable was
668 plugged late in/after the boot process
670 - added a nautilus-script to wipe files and directories
671 - bash with working completion for the live user
672 * polipo: install and configure this HTTP proxy to forward requests
674 * DNS: install and configure pdnsd to forward any DNS request through
676 * firewall: force every outgoing TCP connection through the Tor
677 transparent proxy, discard any outgoing UDP connection
679 - set syslinux timeout to 4 seconds
680 - use splashy for more user-friendly boot/halt sequences
682 -- amnesia <amnesia@boum.org> Sat, 20 Jun 2009 21:09:15 +0200