-
Notifications
You must be signed in to change notification settings - Fork 688
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #4838 from freedomofpress/docs-backport-4657
[1.0.0] [docs] Overhaul Transfer Device and export recommendations
- Loading branch information
Showing
32 changed files
with
1,970 additions
and
1,741 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
2,587 changes: 1,236 additions & 1,351 deletions
2,587
docs/diagrams/SecureDrop.svg → docs/diagrams/SecureDrop-en.svg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file not shown.
Large diffs are not rendered by default.
Oops, something went wrong.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Large diffs are not rendered by default.
Oops, something went wrong.
Binary file not shown.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,9 @@ | ||
.. important:: | ||
|
||
Like all storage media associated with SecureDrop, this drive should be | ||
encrypted and protected with a secure passphrase. We recommend using the | ||
tools built into Tails to `encrypt the drive using LUKS <https://tails.boum.org/doc/encryption_and_privacy/encrypted_volumes/index.en.html>`__. | ||
|
||
If you are planning to use hardware RAID and/or hardware-based encryption, | ||
we recommend that you research Tails compatibility before a procurement | ||
decision. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
* a printer without wireless network support, to use in combination with the | ||
*Secure Viewing Station*. | ||
* an external hard drive to expand the storage capacity of the | ||
*Secure Viewing Station*. | ||
* an external hard drive for server backups. | ||
* a USB drive to store :ref:`backups of your Tails workstation drives <backup_workstations>`. | ||
* a network switch, if you use a firewall with fewer than four ports. | ||
* a hardware token for HOTP authentication, such as a YubiKey, if you want to | ||
use hardware-based two-factor authentication instead of a mobile app. | ||
* a USB drive with a physical write protection switch, or a USB write blocker, | ||
if you want to mitigate the risk of introducing malware from your network to | ||
your *Secure Viewing Station* during repeated use of an *Export Device*. | ||
* CD-R/DVD-R writers, if you want to use CD-Rs/DVD-Rs as transfer or export | ||
media, and a CD shredder that can destroy media consistent with your threat | ||
model. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,13 @@ | ||
* 2 computers with memory and hard drives to use as the SecureDrop servers. | ||
* Mouse, keyboard, monitor (and necessary dongle or adapter) for | ||
installing the servers. | ||
* At least 2 dedicated physical computers that can boot to Tails: one | ||
computer for the *Secure Viewing Station*, and one or more computers for the | ||
*Admin Workstation(s)/Journalist Workstation(s)*. | ||
* Dedicated airgapped hardware for the mouse, keyboard, and monitor (only if you | ||
are using a desktop for the *Secure Viewing Station*). | ||
* Network firewall. | ||
* At least 3 ethernet cables. | ||
* Plenty of USB sticks: 1 drive for the master Tails stick, 1 drive for each | ||
Secure Viewing Station, 1 drive for each *Transfer Device*, 1 drive for each | ||
*Export Device*, and 1 drive for each admin and journalist. |
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.