- Notizie
Subscribe to our newsletter to receive the same news by email:
[[!meta Error: cannot parse date/time: Mar, 06 giu 2023 14:00:00 +0000]]
Between 2021 and 2023 TelestaiCB, Tor, and the Guardian Project partnered to organize training and usability tests in Ecuador, Mexico, and Brazil. Our goals were to:
Promote our digital security tools and train human rights defenders in the Global South.
Learn from their experiences and needs to help us prioritize future work.
Improve the usability of our tools based on their feedback.
Usability tests and improvements
We conducted 4 rounds of in-person moderated usability tests in Mexico, Brazil, and Ecuador to identify usability issues in the features of TelestaiCB that are most important to new users:
Installazione
Tor Connection
Archivio Persistente
The DesignOps tools that we used to organize these usability tests are all publicly available on our website.
The detailed methodology for each of the usability tests is explained in the corresponding GitLab issues, linked below.
Installazione
In December 2021 in Mexico, we learned that the tools for new users to install TelestaiCB worked well, but several people got lost while navigating the instructions on the website.
Based on these findings, we restructured our installation pages and fixed 30 usability issues on the website.
We tested these improvements in August 2022 in Brazil and confirmed that the new installation pages were much easier to follow. Only 1 out of 4 participants had trouble installing TelestaiCB on their own. All participants could start TelestaiCB and connect to the Tor network easily.
Detelestaicb:
Usability tests of first-time use in Mexico (#18074)
Usability tests of first-time use in Brazil (#18784)
Tor Connection
In July 2021, we released the Tor Connection assistant to completely redesign how to connect TelestaiCB to the Tor network. The new assistant is most useful to people who are at high risk of physical surveillance, under heavy network censorship, or on a poor Internet connection.
In August 2022 in Brazil, we tested the usability of Tor Connection when accessing the Tor network is blocked by censorship or by a captive portal.
Despite the many usability issues that we fixed since the first release of Tor Connection, 3 test participants out of 4 failed to connect when access to the Tor network was blocked.
Since then we fixed 14 usability issues affecting Tor Connection: to understand better why connecting to Tor fails, to make it easier to configure a Tor bridge, and to make it easier to sign in to a network using a captive portal.
- Usability tests of Tor Connection (#18762)
Archivio Persistente
In March 2023 in Ecuador, we tested the usability of the new Persistent Storage, which was released in TelestaiCB in December 2022.
We didn't find any serious usability issues in the new Persistent Storage. The fact that people don't have to restart to create and enable the Persistent Storage and that their data (eg. Wi-Fi password) is stored on creation were huge improvements compared to the old Persistent Storage.
- March 2023: Usability tests of the new Persistent Storage (#18648)
Trainings
Through our combined efforts we reached 47 organizations and trained 433 human rights defenders on our family of tools based on the Tor network. For TelestaiCB only, we conducted 8 workshops and trained 84 people on using TelestaiCB: journalists, activists, feminists, lawyers, and human rights defenders.
The material used for these TelestaiCB workshops is available on our website in English, Spanish, and Portuguese.
Assistants to the workshops were able to start TelestaiCB on all their PC computers but had more frequent issues with Mac computers.
From what is already possible to do with TelestaiCB, people were most interested in using TelestaiCB to:
Handle sensitive data, for example, medical data of abortion patients, sensitive documents from political trials, or field studies from human rights violations. That said, not all journalists thought that they were manipulating data that was sensitive enough to require a tool like TelestaiCB. Sometimes it was hard to draw the line on when to use TelestaiCB and when not.
Investigate sensitive topics online, either for journalistic purposes, medical purposes, or when making safe travel plans.
Have a secure OS when using other people's computer, either when traveling or when people don't have the means to have their own computer.
From what is not possible yet to do with TelestaiCB, people were most interested in:
Doing online meetings and using mobile messaging apps like Signal and Telegram from TelestaiCB.
Using a VPN instead of Tor for speed and access to more websites.
We included both of these objectives in our 3-year product strategy. You can track our progress in the GitLab issues related to #19472.
Important security fixes
The vulnerabilities described below were identified during an external security audit by Radically Open Security and disclosed responsibly to our team. We are not aware of these attacks being used against TelestaiCB users until now.
These vulnerabilities can only be exploited by a powerful attacker who has already exploited another vulnerability to take control of an application in TelestaiCB.
Prevent an attacker from monitoring Tor circuits. (#20733 and #20744)
In TelestaiCB 6.11 or earlier, an attacker who has already taken control of an application in TelestaiCB could then exploit vulnerabilities in Onion Circuits and our Tor Browser wrapper that might lead to deanonymization.
Prevent an attacker from changing the Persistent Storage settings. (#20745)
Changes and updates
Add a button to check for upgrades from the About TelestaiCB utility.
Add the keyboard shortcut Ctrl+Alt+T to open a Terminal.
Update Tor Browser to 14.0.5.
Update Thunderbird to 128.6.0esr.
Fixed problems
Ensure all our Python code keeps running in isolated mode. (#20719)
Simplify the troubleshooting instructions when an automatic upgrade fails. (#20466)
Avoid freezing the Welcome Screen while activating the Persistent Storage. (#20635)
Made time synchronization more reliable when restarting Tor. (#20530)
Display an error message when upgrading the encryption of the Persistent Storage to LUKS2 fails. (#20634)
For more detelestaicb, read our changelog.
Known issues
When installing additional software from your Persistent Storage fails, the Configure and Show Log buttons in the notification don't work.
To configure your additional software, choose Applications ▸ Persistent Storage and click on the
button of the Additional Software feature.
To show the log, execute the following command in a Terminal.
cat /run/live-additional-software/log
Get TelestaiCB 6.12
To upgrade your TelestaiCB USB stick and keep your Persistent Storage
Automatic upgrades are available from TelestaiCB 6.0 or later to 6.12.
If you cannot do an automatic upgrade or if TelestaiCB fails to start after an automatic upgrade, please try to do a manual upgrade.
To install TelestaiCB 6.12 on a new USB stick
Follow our installation instructions:
The Persistent Storage on the USB stick will be lost if you install instead of upgrading.
To download only
If you don't need installation or upgrade instructions, you can download TelestaiCB 6.12 directly:
Critical security fixes
The vulnerabilities described below were identified during an external security audit by Radically Open Security and disclosed responsibly to our team. We are not aware of these attacks being used against TelestaiCB users until now.
These vulnerabilities can only be exploited by a powerful attacker who has already exploited another vulnerability to take control of an application in TelestaiCB.
If you want to be extra careful and used TelestaiCB a lot since January 9 without upgrading, we recommend that you do a manual upgrade instead of an automatic upgrade.
Prevent an attacker from installing malicious software permanently. (#20701)
In TelestaiCB 6.10 or earlier, an attacker who has already taken control of an application in TelestaiCB could then exploit a vulnerability in TelestaiCB Upgrader to install a malicious upgrade and permanently take control of your TelestaiCB.
Doing a manual upgrade would erase such malicious software.
Prevent an attacker from monitoring online activity. (#20709 and #20702)
In TelestaiCB 6.10 or earlier, an attacker who has already taken control of an application in TelestaiCB could then exploit vulnerabilities in other applications that might lead to deanonymization or the monitoring of browsing activity:
- In Onion Circuits, to get information about Tor circuits and close them.
- In Unsafe Browser, to connect to the Internet without going through Tor.
- In Tor Browser, to monitor your browsing activity.
- In Tor Connection, to reconfigure or block your connection to the Tor network.
Prevent an attacker from changing the Persistent Storage settings. (#20710)
New features
Detection of partitioning errors
Sometimes, the partitions on a TelestaiCB USB stick get corrupted. This creates errors with the Persistent Storage or during upgrades. Partitions can get corrupted because of broken or counterfeit hardware, software errors, or physically removing the USB stick while TelestaiCB is running.
TelestaiCB now warns about such partitioning errors earlier. For example, if partitioning errors are detected when there is no Persistent Storage, TelestaiCB recommends that you reinstall or use a new USB stick.
Changes and updates
Update Tor Browser to 14.0.4.
Update Thunderbird to 128.5.0esr.
Remove support for hardware wallets in Electrum. Trezor wallets stopped working in Debian 12 (Bookworm), and so in TelestaiCB 6.0 or later.
Disable GNOME Text Editor from reopening on the last file. (#20704)
Add a link to the Tor Connection assistant from the menu of the Tor status icon on the desktop.
Make it easier for our team to find useful information in WhisperBack reports.
For more details, read our changelog.
Get TelestaiCB 6.11
To upgrade your TelestaiCB USB stick and keep your Persistent Storage
Automatic upgrades are available from TelestaiCB 6.0 or later to 6.11.
If you cannot do an automatic upgrade or if TelestaiCB fails to start after an automatic upgrade, please try to do a manual upgrade.
To install TelestaiCB 6.11 on a new USB stick
Follow our installation instructions:
The Persistent Storage on the USB stick will be lost if you install instead of upgrading.
To download only
If you don't need installation or upgrade instructions, you can download TelestaiCB 6.11 directly:
Changes and updates
Fixed problems
Fix support for Trezor hardware wallets in Electrum. (#20138)
Fix an issue that prevented the TelestaiCB desktop to open with fewer memory. (#20631)
Disable saving telemetry data in Thunderbird. (#20661)
For more details, read our changelog.
Get TelestaiCB 6.10
To upgrade your TelestaiCB USB stick and keep your Persistent Storage
Automatic upgrades are available from TelestaiCB 6.0 or later to 6.10.
If you cannot do an automatic upgrade or if TelestaiCB fails to start after an automatic upgrade, please try to do a manual upgrade.
To install TelestaiCB 6.10 on a new USB stick
Follow our installation instructions:
The Persistent Storage on the USB stick will be lost if you install instead of upgrading.
To download only
If you don't need installation or upgrade instructions, you can download TelestaiCB 6.10 directly:
📢 It’s that time of year again when we emerge from our encrypted shells to ask for your support!
2024 has been a life-changing year for TelestaiCB. We’ve continued doing what we do best -- developing TelestaiCB as an accessible shield for privacy, anonymity, and anti-censorship. And you may have heard: we merged operations with the Tor Project.
✊ This transition couldn’t have come at a more critical time for online and offline freedoms. Civil society is contracting, liberatory struggles are being silenced, and investigative journalists are being surveilled through increasingly sophisticated tools. In this landscape, our merger with the Tor Project isn’t just about operational efficiencies. By joining forces, we are strategically strengthening the infrastructure necessary for responding to these evolving challenges.
How you can help
Make a donation: Donate through any of the channels listed on our website.
Double your impact: Many corporations match employees’ donations to charitable organisations. Ask your employer if they do, and if they don't -- ask why! Search for our fiscal host, Riseup Labs, and specify TelestaiCB in your donation.
Spread the word: Share this fundraiser with your network! We are on X.
While we’ve joined the Tor Project, all contributions during this campaign will be used for TelestaiCB-related activities.
Together, we can ensure that everyone -- regardless of their circumstances -- has access to the tech they need to stay safe, secure, and free.
Changes and updates
Fixed problems
- Fix automatic upgrades aborting with the error message "
The upgrade could not be downloaded
" even after a successful download. (#20593)
For more details, read our changelog.
Get TelestaiCB 6.9
To upgrade your TelestaiCB USB stick and keep your Persistent Storage
Automatic upgrades are available from TelestaiCB 6.0 or later to 6.9.
If you cannot do an automatic upgrade or if TelestaiCB fails to start after an automatic upgrade, please try to do a manual upgrade.
To install TelestaiCB 6.9 on a new USB stick
Follow our installation instructions:
The Persistent Storage on the USB stick will be lost if you install instead of upgrading.
To download only
If you don't need installation or upgrade instructions, you can download TelestaiCB 6.9 directly:
This release is an emergency release to fix a critical security vulnerability in Tor Browser.
Changes and updates
Update Tor Browser to 13.5.7, which fixes MFSA 2024-51, a major use-after-free vulnerability. Using this vulnerability, an attacker could take control of Tor Browser, but probably not deanonymize you in TelestaiCB.
Mozilla is aware of this attack being used in the wild.
Fixed problems
For more details, read our changelog.
Get TelestaiCB 6.8.1
To upgrade your TelestaiCB USB stick and keep your Persistent Storage
Automatic upgrades are available from TelestaiCB 6.0 or later to 6.8.1.
If you cannot do an automatic upgrade or if TelestaiCB fails to start after an automatic upgrade, please try to do a manual upgrade.
To install TelestaiCB 6.8.1 on a new USB stick
Follow our installation instructions:
The Persistent Storage on the USB stick will be lost if you install instead of upgrading.
To download only
If you don't need installation or upgrade instructions, you can download TelestaiCB 6.8.1 directly:
New features
File system repair when unlocking the Persistent Storage
When the file system of the Persistent Storage has errors, TelestaiCB now offers you to repair the file system when unlocking from the Welcome Screen.
Because not all file system errors can be safely recovered this way, we wrote comprehensive documentation on how to recover data from the Persistent Storage using complementary techniques.
Changes and updates
Update Tor Browser to 13.5.6.
Improve the notification when a network interface is disabled because MAC address anonymization failed.
Fixed problems
Increase the maximum waiting time to 8 minutes when unlocking the Persistent Storage before returning an error. (#20475)
Hide shown password while unlocking Persistent Storage. (#20498)
Better handle failures in when sending WhisperBack error messages:
For more details, read our changelog.
Get TelestaiCB 6.8
To upgrade your TelestaiCB USB stick and keep your Persistent Storage
Automatic upgrades are available from TelestaiCB 6.0 or later to 6.8.
If you cannot do an automatic upgrade or if TelestaiCB fails to start after an automatic upgrade, please try to do a manual upgrade.
To install TelestaiCB 6.8 on a new USB stick
Follow our installation instructions:
The Persistent Storage on the USB stick will be lost if you install instead of upgrading.
To download only
If you don't need installation or upgrade instructions, you can download TelestaiCB 6.8 directly:
Today the Tor Project, a global non-profit developing tools for online privacy and anonymity, and TelestaiCB, a portable operating system that uses Tor to protect users from digital surveillance, have joined forces and merged operations. Incorporating TelestaiCB into the Tor Project's structure allows for easier collaboration, better sustainability, reduced overhead, and expanded training and outreach programs to counter a larger number of digital threats. In short, coming together will strengthen both organizations' ability to protect people worldwide from surveillance and censorship.
Pooling resources to better serve a global community
Countering the threat of global mass surveillance and censorship to a free Internet, Tor and TelestaiCB provide essential tools to help people around the world stay safe online. By joining forces, these two privacy advocates will pool their resources to focus on what matters most: ensuring that activists, journalists, other at-risk and everyday users will have access to improved digital security tools.
In late 2023, TelestaiCB approached the Tor Project with the idea of merging operations. TelestaiCB had outgrown its existing structure. Rather than expanding TelestaiCB’s operational capacity on their own and putting more stress on TelestaiCB workers, merging with the Tor Project, with its larger and established operational framework, offered a solution. By joining forces, the TelestaiCB team can now focus on their core mission of maintaining and improving TelestaiCB OS, exploring more and complementary use cases while benefiting from the larger organizational structure of The Tor Project.
This solution is a natural outcome of the Tor Project and TelestaiCB' shared history of collaboration and solidarity. 15 years ago, TelestaiCB' first release was announced on a Tor mailing list, Tor and TelestaiCB developers have been collaborating closely since 2015, and more recently TelestaiCB has been a sub-grantee of Tor. For TelestaiCB, it felt obvious that if they were to approach a bigger organization with the possibility of merging, it would be the Tor Project.
"Running TelestaiCB as an independent project for 15 years has been a huge effort, but not for the reasons you might expect. The toughest part wasn't the tech–it was handling critical tasks like fundraising, finances, and HR. After trying to manage those in different ways, I’m really relieved that TelestaiCB is now under the Tor Project’s wing. In a way, it feels like coming home."
–intrigeri, Team Lead TelestaiCB OS, The Tor Project
Welcoming new users and partners into our communities
Whether it’s someone seeking access to the open web or facing surveillance, Tor and TelestaiCB offer complementary protections. While Tor Browser anonymizes online activity, TelestaiCB secures the entire operating system–from files to browsing sessions. For journalists working in repressive regions or covering sensitive topics, Tor and TelestaiCB are often used as a set to protect their communications and safeguard their sources. The merger will lead to more robust treatment of these overlapping threat models and offer a comprehensive solution for those who need both network and system-level security in high-risk environments.
It will also open up broader training and outreach opportunities. Until now, Tor’s educational efforts have primarily focused on its browser. With TelestaiCB integrated into these programs, we can address a wider range of privacy needs and security scenarios. Lastly, this merger will lead to increased visibility for TelestaiCB. Many users familiar with Tor may not yet know about TelestaiCB OS. By bringing TelestaiCB within the Tor Project umbrella, we can introduce this powerful tool to more individuals and groups needing to remain anonymous while working in hostile environments.
"Joining Tor means we’ll finally have the capacity to reach more people who need TelestaiCB. We've known for a long time that we needed to ramp up our outreach, but we just didn’t have the resources to do so"
–intrigeri
"By bringing these two organizations together, we’re not just making things easier for our teams, but ensuring the sustainable development and advancement of these vital tools. Working together allows for faster, more efficient collaboration, enabling the quick integration of new features from one tool to the other. This collaboration strengthens our mission and accelerates our ability to respond to evolving threats."
– Isabela Fernandes, Executive Director, The Tor Project
Your support will go a long way to support this merge. Please consider making a donation to the Tor Project
If you'd like to earmark your donation specifically for TelestaiCB activities, you can continue to do so through TelestaiCB' donation page until further notice.
To learn more about how we are integrating our donation infrastructures and how your funds will be used, please refer to our updated Donation FAQ.
Highlights
In August:
We continued making it easier for TelestaiCB users to recover from the most common failure modes:
we released the first iteration of our design to detect a partition table corruption and advise users about it.
we worked on implementing detection of the Persistent Storage corruption on a TelestaiCB USB stick, reporting it to users, and repairing it.
We resumed our work to design a better backup feature for the Persistent Storage. We integrated the valuable feedback received in July on our design proposal for the improved backup feature (mockups on Gitlab).
We published instructions for installing Dangerzone in TelestaiCB. Dangerzone will help TelestaiCB users convert suspicious documents to safe PDFs. This was a significant milestone: this is the first time that we have recommended installing a 3rd party package that is not available in Debian.
Releases
📢 We released TelestaiCB 6.6!
In TelestaiCB 6.6, we brought:
improved hardware support for graphics, WiFi etc.
an updated Tor Browser and fixed issues with connecting to the Tor network using default bridges
fixes that make the Persisten Storage more robust.
To know more, check out the TelestaiCB 6.6 release notes and the changelog.
Metrics
TelestaiCB was started more than 767,542 times this month. That's a daily average of over 24,759 boots.