04 · Plebum Dominium
Two boots
After the files pass. Label the USBs. Networking off before the desktop.
You are here after the files are checked, and before any words are written. One computer. Two boots. Boot 1 is on the network and never holds a seed. Shut it down fully. Boot 2 is the Tails USB on that same computer, networking off. A second USB carries files only. Shutdown forgets the session.
Airgap does mean
- Networking disabled on the Tails welcome screen, before the desktop appears.
- The seed exists in RAM only. Shutdown wipes it.
- Data crosses the gap as files on a clean USB (PSBT, descriptor, verified binaries).
- The household computer stays watch-only: xpubs and the descriptor, never seeds.
- Stronger: Wi-Fi card physically removed; Ethernet never plugged. Still boot Tails.
Airgap does not mean
- “I turned Wi-Fi off after Sparrow opened.”
- Unplug Ethernet on a disk that was online yesterday.
- Photographing a seed “just to be safe.”
- A password manager, printer, or cloud note as backup.
Prepare Tails on a trusted online computer
- 01 · Download the Tails ISO only from the official Tails site. Fetch the signing key from more than one published source.
- 02 · Verify the ISO signature and checksum before you flash. If verification fails, stop.
- 03 · Flash Tails to its own USB with the official installer. Label it TAILS. Never mix it with the data USB.
- 04 · Do not create a Persistent Storage. Skip the passphrase. This stick stays amnesic.
- 05 · On the data USB, copy only files that already passed. The Sparrow file must be named sparrowwallet-2.5.5-x86_64.tar.gz. That is the Linux file. The Windows installer and the Mac installer do not go on this stick. Label the stick DATA.
Every offline session at home
- 01 · Insert Tails. Boot. Set Networking to Disabled. Do not unlock Persistent Storage. Start Tails.
- 02 · Plug in the data USB. Copy only what you need onto the live session.
- 03 · Convert entropy, restore one seed, sign one PSBT, or export the descriptor.
- 04 · Copy results back to the data USB. Shut Tails down fully. Wait for the screen to go dark before unplugging.
- 05 · Never load two seeds in one session. Never turn networking on while a seed is in memory.
Do not use Persistent Storage
- Tails will offer an encrypted area on the same USB. Do not create it, and do not unlock one if a stick already has it.
- It is not hidden. Anyone holding the USB can see that it exists, and you can be forced or tricked into giving up the passphrase.
- The Electrum feature writes the wallet onto the stick. That file contains the seed, protected only by the wallet password. That is a spending convenience, not this setup.
- Extra software and dotfiles can undo settings Tails already tested.
- Leave it off. The seed stays in RAM. Shutdown wipes the session. That is why this USB exists.
Stronger chassis (optional)
- Use an old laptop as a dedicated Tails chassis. Pull the Wi-Fi card (Bluetooth usually leaves with it). Do not leave it “disabled” in the slot.
- Ethernet is often still on the board. Never plug it. Disable it in BIOS if you can.
- Ignore or remove the previous owner’s disk. Tails does not use it. Do not boot that OS.
- Still verify the Tails ISO, still set Networking Disabled, still use a clean data USB. The remaining wire is that stick.
Two boots, one computer. Boot 1: watch-only Sparrow, builds the spend, broadcasts. Never holds a seed. Full shutdown. Boot 2: the Tails USB on that same hardware, networking off. It loads exactly one seed, signs, exports the PSBT, and shuts down. A second USB carries files only. The only secret that crosses is a signature file, not a seed. A networked machine with a seed loaded is a single point of failure. Treat that session as burned.
Next. Make the three keys. Do not write a word until Tails is up with networking off.