Skip to content

04 · Plebum Dominium

Tails airgap sheet

Two-machine rule. Tails with networking off. Optional: radio-less laptop.

Download PDF

A computer that has never seen your seed while a network interface was live. Software off is required. Hardware gone is stronger. You can build that on a closed-door table.

Airgap does mean

  • Networking disabled on the Tails welcome screen, before the desktop appears.
  • The seed exists in RAM only. Shutdown wipes it.
  • Data crosses the gap as files on a clean USB (PSBT, descriptor, verified binaries).
  • The household computer stays watch-only: xpubs and the descriptor, never seeds.
  • Stronger: Wi-Fi card physically removed; Ethernet never plugged. Still boot Tails.

Airgap does not mean

  • “I turned Wi-Fi off after Sparrow opened.”
  • Unplug Ethernet on a disk that was online yesterday.
  • Photographing a seed “just to be safe.”
  • A password manager, printer, or cloud note as backup.

Prepare Tails on a trusted online computer

  1. 01 · Download the Tails ISO only from the official Tails site. Fetch the signing key from more than one published source.
  2. 02 · Verify the ISO signature and checksum before you flash. If verification fails, stop.
  3. 03 · Flash Tails to its own USB with the official installer. Label it TAILS. Never mix it with the data USB.
  4. 04 · Do not create a Persistent Storage. Skip the passphrase. This stick stays amnesic.
  5. 05 · On a separate clean USB, copy only already-verified files: Sparrow .tar.gz, optional Electrum, local Ian Coleman HTML.

Every offline session at home

  1. 01 · Insert Tails. Boot. Set Networking to Disabled. Do not unlock Persistent Storage. Start Tails.
  2. 02 · Plug in the data USB. Copy only what you need onto the live session.
  3. 03 · Convert entropy, restore one seed, sign one PSBT, or export the descriptor.
  4. 04 · Copy results back to the data USB. Shut Tails down fully. Wait for the screen to go dark before unplugging.
  5. 05 · Never load two seeds in one session. Never turn networking on while a seed is in memory.

Do not use Persistent Storage

  • Tails will offer an encrypted area on the same USB. Do not create it, and do not unlock one if a stick already has it.
  • It is not hidden. Anyone holding the USB can see that it exists, and you can be forced or tricked into giving up the passphrase.
  • The Electrum feature writes the wallet onto the stick. That file contains the seed, protected only by the wallet password. That is a spending convenience, not this setup.
  • Extra software and dotfiles can undo settings Tails already tested.
  • Leave it off. The seed stays in RAM. Shutdown wipes the session. That is why this USB exists.

Stronger chassis (optional)

  • Use an old laptop as a dedicated Tails chassis. Pull the Wi-Fi card (Bluetooth usually leaves with it). Do not leave it “disabled” in the slot.
  • Ethernet is often still on the board. Never plug it. Disable it in BIOS if you can.
  • Ignore or remove the previous owner’s disk. Tails does not use it. Do not boot that OS.
  • Still verify the Tails ISO, still set Networking Disabled, still use a clean data USB. The remaining wire is that stick.

Two-machine rule. Online computer: watch-only Sparrow, builds the spend, broadcasts. Offline Tails: loads exactly one seed, signs, exports the PSBT, shuts down. The only secret that crosses a USB is a signature file — not a seed. A networked machine with a seed loaded is a single point of failure. Treat that session as burned.