-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

Comment about https://tails.boum.org/todo/server_edition/

I think you can add to this page, that Tails's current implementation
with tails_htp is not sufficient. Servers are supposed to run over
longer periods without rebooting, days or weeks.

During that time and especially under load the system clock will shift.

My recommendation is to run htpdate periodically, perhaps every hour.
Time exact minute should be randomized to avoid creating a network
fingerprint.

Given what you already implemented with tails_htp, running tails_htp
frequently probable won't be hard. As I need it for aos, I am planing
to add a script to /etc/cron.daily, it will run another script in
background to avoid blocking anachron during the sleep delay. The
other script will simply pick a number between 0 and 3600 from
/dev/random, sleep for the delay and then restart the htpdate service.

Please comment on the implementation idea and if you are interested I
am going to link those small new scripts.

Cheers,
adrelanos
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJQKTxjAAoJEJwTGtNxOq7vqb8P/j+QrUfJIlWEmHwW0+nzhajL
f5nC4wGcS23dFtwMjRFcZkDtd7roYCfH6jVm/77joH9EVgOwFaNisiTTJiPvuohj
HL2hu9mdnlUvgJkSv9gEFvJOUNwRtnyIVx+2nD1eaey9jXazTzM7PgtJI+rvXUFr
UFRWJrUUWHIksyoUc0HWhDQTHaT8Wpf8MwlGQB/ZUverHBDpazGRBo87F+x6Zy9m
FKR+MEz2RHi5XZfjdK1/6v8qE5vrplSwFFevf5ejVXrZ06Uz4D8mRCcieDhYvoMi
+4tyx/tq1u3oL7Z2JJ41j8uiEvlfj4vU6h/50IFzxJYuelC1F/f+zmgFCBDpevuY
hUzNfLRO3FxQZU5eOVT77TXaqN2GSRahC44rWit0+nMyRx3b1y8ECq8zA+Ap7xT9
ad+eekowYisUhiYvGkCZvhnqcWaYytgO/1wfJcp0m0leL7pOkcUdH13RI/JGyTem
ptLUlboWijMBSJJ617tYNwqutxii87K5huMZEq1PXSt5rq0UDn/Qrh3nDqL1Uxmp
gNQa0wNxMUu/va08AKo2lr2AZSX4lusOXzii2g1xzTNC/sRG3YhrxVtytS5P0JNF
pM0X/HIWzzh/fURkjnOtbkbbjMhfN4rcWq025eaUWZKlt+ctDhJ40Dm30FhNp0EZ
WKH5ihkrHp0O9OPnXbDf
=eXk1
-----END PGP SIGNATURE-----
_______________________________________________
tails-dev mailing list
[email protected]
https://mailman.boum.org/listinfo/tails-dev

Reply via email to