Kicksecure/security-misc
Kernel Hardening; Protect Linux User Accounts against Brute Force Attacks; Improve Entropy Collection; Strong Linux User Account Separation; Enhances Misc Security Settings - https://www.kicksecure.com/wiki/Security-misc
ShellNOASSERTION
Issues
- 26
Restrict umask to 027 except for sudo/root broken
#185 opened by adrelanos - 1
review secureblue sysctl
#283 opened by adrelanos - 2
default SUID for umount (un-mount) may be incorrect
#284 opened by the-moog - 22
Split the `security-misc` into `security-misc-shared`, `security-misc-desktop` and `security-misc-server`
#187 opened by monsieuremre - 1
- 1
review Brace to see if there are security settings which aren't part of security-misc (or Kicksecure yet)
#278 opened by adrelanos - 3
Protecting /sys and /proc
#277 opened by monsieuremre - 3
slightly confusing KSPP header, introduce `KSPP=undocumented` comment in case KSPP does not mention it
#275 opened by adrelanos - 0
- 0
kernel module blacklist breaks VirtualBox audio devices ICH AC97 and maybe Intel HD
#271 opened by adrelanos - 11
criteria for kernel module blacklisting / disabling / Suggestions for kernel modules blacklisted in /etc/modprobe.d/30_security-misc.conf
#224 opened by MikeHorn-git - 12
Redundant kernel args
#199 opened by TommyTran732 - 7
- 1
file/folder permissions issue `d????????? ? ? ? ? ? .` | Firefox no longer starting (probably not not a Firefox issue) | caused by disallow registering interpreters for miscellaneous binary formats `sysctl fs.binfmt_misc.status=0`
#267 opened by adrelanos - 73
Kicksecure Default Browser Discussion
#192 opened by monsieuremre - 6
Use `slub_debug=FZ`?
#253 opened by cynicsketch - 10
no longer disable Intel ME related kernel modules
#239 opened by adrelanos - 10
Harden all system services by default
#213 opened by monsieuremre - 4
- 16
MAC randomization breaks root server and VirtualBox DHCP / IPv6PrivacyExtensions might be problematic
#184 opened by adrelanos - 32
Wayland Default DE for Real Security
#168 opened by monsieuremre - 2
add `/etc/gitconfig` for better git security
#225 opened by adrelanos - 8
- 2
/lib/sysctl.d/990-security-misc.conf - log_martians
#214 opened by the-moog - 0
allow MSR kernel module being load / move from security-misc to vm-config-dist
#215 opened by adrelanos - 3
test remount-secure script and systemd unit
#203 opened by adrelanos - 7
- 0
- 5
`remount-secure`: use `procfs` mount option `subset` (`hide-hardware-info.service`)
#205 opened by adrelanos - 20
- 0
- 1
`hide-hardware-info.service`: hide `/sys/kernel/notes` due to accidental pointer leaks on xen systems. Leak defeats KASLR
#209 opened by wryMitts - 10
- 1
- 1
`hide-hardware-info.service`: hide `/proc/kallsyms`
#206 opened by adrelanos - 2
sgid (set-group-ID) pkexec to fix hidepid
#201 opened by adrelanos - 4
pam-tmpdir-helper breaks certain initramfs-update actions on systems with noexec on the /tmp mount
#198 opened by wryMitts - 16
use SRSO spec_rstack_overflow kernel setting?
#177 opened by adrelanos - 0
automatic trigger of permission-hardener after APT package installation broken
#196 opened by adrelanos - 1
`flatpak remote-add` TOFU and TLS security issue / use stronger authentication than TLS
#191 opened by adrelanos - 1
Harden Network
#186 opened by monsieuremre - 0
- 1
- 4
fix Bluetooth readme
#180 opened by adrelanos - 0
- 6
Force IOMMU
#175 opened by TommyTran732 - 8
`Depends:` vs `Recommends:` vs none
#169 opened by adrelanos - 2
systemd-coredump
#174 opened by adrelanos - 13
Hide Proc | New Approach
#173 opened by monsieuremre - 4
Backport Firmware and Kernel | Protect against spectre/meltdown and various hardware vulnurabilities
#164 opened by monsieuremre