Commit Graph

187 Commits

Author SHA1 Message Date
38cdf2722b - Wipe LUKS Disk Encryption Key for Root Disk from RAM during Shutdown to defeat Cold Boot Attacks
- Confirm in console output if encrypted mounts (root disk) is unmounted. (Because that is a pre-condition for wiping the LUKS full disk encryption key from RAM.)

Thanks to @friedy10!

https://github.com/friedy10/dracut/tree/master/modules.d/40sdmem

https://forums.whonix.org/t/is-ram-wipe-possible-inside-whonix-cold-boot-attack-defense/5596
2022-06-29 09:32:55 -04:00
2d37e3a1af copyright 2022-05-20 14:46:38 -04:00
e2810f348b Depends: libpam-modules-bin 2021-09-04 11:50:31 -04:00
5e3338f8d3 bullseye 2021-08-03 05:48:25 -04:00
a67007f4b7 copyright 2021-03-17 09:45:21 -04:00
611fbe2c61 description 2021-01-18 05:39:34 -05:00
06ffd5d220 Restrict access to debugfs 2020-09-28 19:21:20 +00:00
72be31e870 disable proc-hidepid by default because incompatible with pkexec
and undo pkexec wrapper
2020-04-12 16:48:13 -04:00
565ff136e5 vm.swappiness=1
import from swappiness-lowest

https://forums.whonix.org/t/vm-swappiness-1-set-swapiness-to-lowest-setting-still-useful-swappiness-lowest/9278
2020-04-08 21:04:02 +00:00
a9d0baffe6 python -> python3 2020-04-08 16:57:32 +00:00
4153d8d088 apparmor-profile-anondist -> apparmor-profile-dist 2020-04-08 16:51:22 +00:00
663811a819 anon-base-files -> dist-base-files 2020-04-08 12:04:13 +00:00
5c81e1f23f import from anon-gpg-conf 2020-04-06 09:25:45 -04:00
d9f2a0e4a1 remove 'Build-Depends: ronn' since no longer required 2020-04-01 17:34:59 -04:00
eda9c57a62 remove genmkfile 2020-04-01 16:57:33 -04:00
2ceea8d1fe update copyright year 2020-04-01 08:49:59 -04:00
15dde15a36 typo 2020-03-03 09:42:24 -05:00
cd19c2da00 fix lintian warning 2020-03-03 09:18:24 -05:00
453aa8a4eb Merge pull request #65 from madaidan/userfaultfd
Restrict the userfaultfd() syscall to root
2020-02-29 12:28:32 +00:00
e3e39f2235 Merge remote-tracking branch 'origin/master' 2020-02-29 05:01:41 -05:00
b31caefdeb description 2020-02-29 04:59:02 -05:00
bd7678c574 Merge pull request #66 from madaidan/mce
Fix docs
2020-02-28 12:04:05 +00:00
42d3b986c4 Update control 2020-02-27 17:41:14 +00:00
4043d2af3f description 2020-02-25 02:06:48 -05:00
0e5187ff24 description 2020-02-25 02:00:27 -05:00
60fbf8b0de Update control 2020-02-24 18:24:07 +00:00
8ea4e50c8e Update control 2020-02-16 19:52:40 +00:00
1e5946c795 Merge branch 'master' into sysrq 2020-02-15 10:41:52 +00:00
0f49736957 Update control 2020-02-14 18:18:18 +00:00
ace6211176 Update control 2020-02-14 17:51:17 +00:00
ad6b766886 Merge pull request #57 from madaidan/sysctl
Prevent symlink/hardlink TOCTOU races
2020-02-13 18:40:58 +00:00
2796c2dd00 Update control 2020-02-12 18:43:19 +00:00
14f8458374 Update control 2020-02-12 18:05:32 +00:00
c1a0da60be set kernel boot parameter l1tf=full,force and nosmt=force
https://forums.whonix.org/t/should-all-kernel-patches-for-cpu-bugs-be-unconditionally-enabled-vs-performance-vs-applicability/7647/17
2020-01-30 00:46:48 -05:00
f4c54881ac description 2020-01-24 04:49:19 -05:00
a37da1c968 add digits to drop-in file names 2020-01-24 04:39:06 -05:00
3a4d283169 description 2020-01-24 04:33:30 -05:00
8616728ce0 remove duplicate 2020-01-24 03:35:15 -05:00
1df48a226d Update control 2020-01-15 20:30:17 +00:00
0618b53464 fix lintian warning 2020-01-15 11:35:07 -05:00
528c5fc4c4 Merge branch 'master' into sysctl-initramfs 2020-01-15 11:02:03 +00:00
0953bbe1d7 Update control 2020-01-13 21:05:35 +00:00
9dc43eae38 Description 2020-01-12 21:42:07 +00:00
61a2d390a7 lintian 2020-01-11 15:15:12 -05:00
6088444c37 Update control 2020-01-11 18:38:17 +00:00
9ec5b0ee82 description: lockdown not enabled yet 2019-12-23 03:38:49 -05:00
1ff51ee061 merge 2019-12-23 03:37:28 -05:00
3670fcf48b depend on libcap2-bin for setcap / getcap / capsh 2019-12-23 00:49:33 -05:00
8f11a520f4 Update control 2019-12-22 13:54:16 +00:00
b74e5ca972 comment 2019-12-21 07:47:00 -05:00