FYI:
I've learned of a "Linux kernel hardening checker":
https://github.com/a13xp0p0v/kernel-hardening-checker
It might be interesting to run & see if there are missing hardening measures that
should be applied in Tails. It'd be good to alert Debian if they should also be applied there,
but I'd be unsurprised if Tails had additional hardening settings to resist attack.
--- David A. Wheeler