3 ms·
I doubt a 5 year old hardening is any relevant today. I would stick to a well researched article like Privsec[0] where they explain the reasoning for each step.
by ementally 2y ago
I doubt a 5 year old hardening is any relevant today. I would stick to a well researched article like Privsec[0] where they explain the reasoning for each step.
[0] https://privsec.dev/posts/linux/desktop-linux-hardening/ https://privsec.dev/posts/linux/desktop-linux-hardening/
- udev4096 2y agoAgreed. A more recent one which is quite extensive, yet a bit old, is https://madaidans-insecurities.github.io/guides/linux-hardening.html https://madaidans-insecurities.github.io/guides/linux-harden...
- velcrovan 2y agoWhat I want is an accompanying example Ansible playbook for at least one distribution so I can understand the reasoning behind each step and still do it all with a single command.
- josephcsible 2y agoThat one is no good because it tries to normalize DRM and tivoization by pretending they're for "security". E.g., it says to set kernel.kexec_load_disabled=1, debugfs=off, module.sig_enforce=1, and lockdown=confidentiality, all of which only restrict the root user. It's also terrible for other reasons, e.g.: > net.ipv6.conf.all.accept_ra=0 > net.ipv6.conf.default.accept_ra=0 > Malicious IPv6 router advertisements can result in a man-in-the-middle attack, so they should be disabled. But that's the main way to configure IPv6. The IPv4 equivalent of that advice would be to disable your DHCP client, since malicious DHCP servers can result in a man-in-the-middle attack. And it also has the same horrendous advice for PAM to require the kinds of passwords that we now know reduce security.
- fbdab103 2y agoFrom the link, suggestion to set hostname to `localhost` That is probably fine, but it makes me feel uneasy. Something has to break if you do that, right?