balenaEtcher shares sensitive information to the Balena company

The wiki instructs to use balenaEtcher to write the ISO to USB, however the folks over at Tails found that balenaEtcher shares sensitive information to the Balena company.

I don’t feel confident enough to edit the wiki nor do I have the knowhow to suggest a more secure method.

(apparently I can’t include links in my post? You can find the link if you navigate to the Tails OS Windows install instructions)

We’re aware of the issues with Etcher. So far though I don’t think we know of another ISO image writer that would work for us (in particular Rufus is not very user-friendly and can easily be used “wrong”), and Kicksecure is not an anonymity-focused OS so the privacy concerns that apply to Tails don’t apply as much here. (They would apply to Whonix, but Whonix is run in VMs, so Etcher never needs to work with it.)

If you know of any USB image writer for Windows that:

  • Is very user friendly,
  • Is Freedom Software,
  • Has binaries for Windows available without charge,
  • Isn’t affected by issues that would make it prohibitively difficult to start the application (such as codesigning issues),
  • Doesn’t have privacy concerns,
  • Writes ISO images directly to disk (as opposed to unpacking them onto a file system), and
  • Comes from a trustworthy source,

we might be able to recommend using it instead. Rufus I believe matches all of the criteria except the first one, but that’s a very important one.

(At some point, I’d like to just write an ISO image writer for Kicksecure that matches all of the above criteria. We have a bunch of higher-priority things to work on though, so there’s no telling when or if that will happen.)

2 Likes

See:

1 Like