Tails 7.12 Kicks Off a New Two-Week Release Cycle

Tails 7.12 Kicks Off a New Two-Week Release Cycle

Tails 7.12 is out, and it marks the start of a two-week release cycle. For a distribution whose entire purpose is security, that cadence change matters more than anything in the release notes.

Why the cadence matters here

Tails is an amnesic live system: it boots from removable media, routes everything through Tor, and forgets everything on shutdown unless you have configured persistent storage. It is used by journalists, activists, and people whose threat model involves adversaries with real capability.

The distinguishing problem is that Tails users cannot patch in place the way a normal installation can. There is an in-system updater, but the model is fundamentally that you are running a fixed image. A vulnerability in the shipped Tor Browser or the shipped kernel is a vulnerability in the image until a new image exists.

Moving from a roughly monthly cycle to a fortnightly one halves the worst-case window between an upstream fix and an image containing it. When the upstream in question is Tor Browser, which inherits Firefox’s security releases, that is a direct reduction in exposure for the component most likely to be attacked.

The tradeoff

Faster releases mean more releases to verify and install. Tails users are told, correctly, to verify the signature on every download:

# verify before writing, every time
gpg --verify tails-amd64-7.12.img.sig tails-amd64-7.12.img

Doing that fortnightly rather than monthly is more friction for people who are already following a demanding operational routine. The automatic upgrade path handles most cases, but not all upgrades can be done automatically, and a full reinstall is occasionally required.

There is also a testing question. Shorter cycles mean less soak time per release, and a regression in a distribution like this has consequences beyond inconvenience. We covered the 7.11 persistent storage fix recently, which is the category of bug that fortnightly releases will catch faster and also produce more often.

The project has evidently judged that the exposure reduction outweighs the testing cost. For a security distribution downstream of a browser that ships fixes on a fast cycle, that seems like the right call.

Practical notes

If you use Tails, upgrade. The in-system updater will handle it in most cases, and the installation documentation covers the cases where it will not.

If you are considering Tails, be clear about what it is for. It is a tool for a specific threat model, not a general-purpose privacy upgrade. Booting it and then signing into accounts tied to your real identity defeats most of what it provides, because Tor protects the transport and not the fact that you just authenticated as yourself.

Background reading

Explainers for the concepts behind this story.