Developers tell users not to launch this top Linux distro over security fears

Hologram of security padlock operating on the electronic circuit CPU.
(Image credit: Getty Images)

Developers of the popular Tails Linux distribution have warned users to abstain from the OS until the next version is released, if they use it for entering, or accessing, sensitive information.

"We recommend that you stop using Tails until the release of 5.1 (May 31) if you use Tor Browser for sensitive information (passwords, private messages, personal information, etc.)," the warning reads.

The announcement comes days after the Pwn2Own 2022 Vancouver event, where contestants successfully exploited two zero-days found in the Firefox JavaScrip engine. If the two vulnerabilities, tracked as CVE-2022-1802 and CVE-2022-1529, are abused successfully, they could allow threat actors to access information submitted to legitimate sites via the Tor browser on targeted endpoints.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Exceptions to the rule

"For example, after you visit a malicious website, an attacker controlling this website might access the password or other sensitive information that you send to other websites afterwards during the same Tails session," the warning explains.

Mozilla, which said some threat actors were already exploiting this vulnerability in the wild, has addressed the issue, BleepingComputer has found, but given that Tails is a live Linux distro, the devs cannot deliver patches for any of the included apps until the next release, which is due on May 31.

There are a few exceptions as well, including using Tor Browser on the Safest security level, which disables JavaScript by default. Email client Thunderbird also comes with JavaScript disabled by default, making it safe to use.

It was also said that if users refrain from accessing, or submitting, sensitive information via Tor, they can still safely use it, as these flows don’t break the encryption and anonymity provided by Tor.

Tails, short for The Amnesic Incognito Live System, is a Debian-based Linux distro, usually used by journalists, whistleblowers, civil rights activists, and other individuals looking to stay fully anonymous online, and bypass any censorship or government restrictions. 

"Mozilla is aware of websites exploiting this vulnerability already. This vulnerability will be fixed in Tails 5.1 (May 31), but our team doesn't have the capacity to publish an emergency release earlier," the Tails team warned.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
The best free firewall
Palo Alto warns another major firewall hack has been detected
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
Home internet connection. A wlan router on desk with notebook in background.
Cloudflare admits security tool is blocking some challenger browsers
An abstract image of digital security.
Tenable warns users to update now following possible plugin security issue
Latest in Software & Services
Windows 11 Start menu layout choices: Grid view
Windows 11 vs Linux for business: which operating system should you embrace?
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Gmail vs Outlook for business: which email system is right for your organization?
Windows 11 logo
Windows 11 Pro vs Windows 11 Home: which version is right for you?
Canva HubSpot
HubSpot and Canva team up to level the creative playing field
a laptop computer
Windows 11 vs ChromeOS for business: Is one better than the other for your needs?
a laptop computer
Windows 11 vs macOS for business: which side are you on?
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off