Re: timedatectl Should Not be Enabled by Default: Privacy/Anonymity risks

2015-07-28 Thread bancfc
about how a distro should work. On 07/27/2015 07:55 AM, intrigeri wrote: > Hi, > > bancfc wrote (26 Jul 2015 18:19:59 GMT) : >> The research comes from WhonixOS a privacy centric distro like TAILS. > > For the record, this does not imply any position from Tails regarding &g

timedatectl Should Not be Enabled by Default: Privacy/Anonymity risks

2015-07-26 Thread bancfc
Its not a good idea to enable timedatectl (or any NTP daemon) by default in Debian Stretch+ because it has negative consequences for privacy and anonymity. The NTP protocol is not secure and can be trivially manipulated by network observers to mount clock skew attacks. NTPS is no better because of