3 ms·
> Kernel/userland hardening is a thing [forgive me if I misunderstood the topic] If you're running a server, then you really should keep the Web side of things
by insoluble 11y ago
> Kernel/userland hardening is a thing
[forgive me if I misunderstood the topic] If you're running a server, then you really should keep the Web side of things in an even more restricted zone than normal Users. I create extremely limited accounts for each domain or large App being hosted. Each such account can access only those resources it's supposed to be able to.
- archimedespi 11y ago> [forgive me if I misunderstood the topic] You didn't misunderstand at all! When I stated that, I mean two different things: - Kernel hardening Kernel hardening is when you take the kernel and add patches/configure it to be more secure, like grsecurity. - Userland hardening This is when you do exactly what you're talking about: you restrict what the userland can do and configure userland programs to be more secure (ie turning off insecure Apache options). This could also mean jailing or containerizing them.