Commit Graph

129 Commits

Author SHA1 Message Date
8cf5ed990a comment 2019-12-05 15:52:24 -05:00
30289c68c2 Enable reverse path filtering 2019-12-05 20:13:10 +00:00
0c25a96b59 description / comments 2019-12-03 02:18:32 -05:00
5da2a27bf0 Distrust the CPU for initial entropy 2019-12-02 16:43:00 +00:00
d9d6d07714 /dev/pts/[0-9]* rw, 2019-11-26 17:12:12 +00:00
d32024a3da /usr/sbin/pam_tally2 mrix,
https://forums.whonix.org/t/apparmor-for-complete-system-including-init-pid1-systemd-everything-full-system-mac-policy/8339/152
2019-11-23 05:53:19 -05:00
81e4f580af etc/apparmor.d/usr.lib.security-misc.permission-lockdown: /usr/bin/chmod mrix, 2019-11-19 15:29:02 +00:00
477d476bb1 etc/apparmor.d/usr.lib.security-misc.pam_tally2-info: add '#include <abstractions/base>' 2019-11-10 08:29:44 -05:00
11dc23bf08 etc/apparmor.d/usr.lib.security-misc.permission-lockdown: add '#include <abstractions/base>' 2019-11-10 08:28:32 -05:00
9f2932faab /usr/bin/id rix, 2019-11-09 13:32:21 -05:00
94d40c68d4 do not set kernel boot parameter page_poison=1 in Qubes since does not work
https://github.com/QubesOS/qubes-issues/issues/5212#issuecomment-533873012
2019-11-05 10:02:55 -05:00
f57702c158 comments; copyright 2019-11-05 09:55:43 -05:00
b55c2fd62e Enables punycode (network.IDN_show_punycode) by default in Thunderbird
to make phising attacks more difficult. Fixing URL not showing real Domain
Name (Homograph attack).

https://forums.whonix.org/t/enable-network-idn-show-punycode-by-default-in-thunderbird-to-fix-url-not-showing-real-domain-name-homograph-attack-punycode/8415
2019-11-03 02:50:51 -05:00
e1375802eb apparmor fix
https://forums.whonix.org/t/apparmor-for-complete-system-including-init-pid1-systemd-everything-full-system-mac-policy/8339/67
2019-10-31 16:32:28 +00:00
203d5cfa68 copyright 2019-10-31 11:19:44 -04:00
0e49bdc45f Licensing 2019-10-28 14:26:14 +00:00
5d5ad92638 Licensing 2019-10-28 14:26:05 +00:00
1b8b3610b1 Create usr.lib.security-misc.pam_tally2-info 2019-10-28 14:20:59 +00:00
29b05546e4 Create usr.lib.security-misc.permission-lockdown 2019-10-28 14:20:08 +00:00
40707e70db Redirect calls for pkexec to lxqt-sudo because pkexec is incompatible with hidepid.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860040

https://forums.whonix.org/t/cannot-use-pkexec/8129

Thanks to AnonymousUser for the bug report!
2019-10-21 05:46:49 -04:00
0b8725306f renamed: etc/hide-hardware-info.d/30_whitelist.conf -> etc/hide-hardware-info.d/30_default.conf 2019-10-17 06:13:44 -04:00
8a42c5b023 Merge pull request #34 from madaidan/whitelist
Add a whitelist for /sys and /proc/cpuinfo
2019-10-17 09:59:12 +00:00
4f5b7816ec Elaborate 2019-10-16 19:01:49 +00:00
99a762d3dc KASLR is different from ASLR 2019-10-16 18:53:04 +00:00
a14a2854c6 Elaborate 2019-10-16 18:52:14 +00:00
a47a2fca8b Create 30_whitelist.conf 2019-10-15 20:58:58 +00:00
c22738be02 comments 2019-10-07 08:25:45 +00:00
75f36bc2c9 comments 2019-10-07 08:25:07 +00:00
e92a8a6966 comments 2019-10-07 08:24:02 +00:00
60c044a9d6 copyright / comments 2019-10-07 05:30:56 +00:00
cd2135ff82 comments 2019-10-06 10:18:24 +00:00
8b4f2befd4 comment out sack by default
https://forums.whonix.org/t/disabling-tcp-sack-dsack-fack/8109/8?u=patrick
2019-10-05 13:15:34 +00:00
02096f8d7c Revert "undo Disabling TCP SACK, DSACK, FACK"
This reverts commit 5fb4eb8e56.
2019-10-05 13:13:46 +00:00
5fb4eb8e56 undo Disabling TCP SACK, DSACK, FACK
https://forums.whonix.org/t/disabling-tcp-sack-dsack-fack/8109/5
2019-10-05 07:00:47 -04:00
d0c6bb1e90 Disable TCP DSACK and FACK 2019-10-04 17:35:54 +00:00
f13a73e569 undo SysRq restrictions
https://forums.whonix.org/t/sysrq-magic-sysrq-key/8079
2019-09-10 12:35:42 -04:00
60db7e6294 fix typo 2019-09-07 20:08:56 +00:00
7affddb3bb blacklist modules with /bin/false rather than /bin/true to fail with error
message rather than failing without notification
2019-09-07 05:47:34 +00:00
661bcd8603 allow loading unsigned modules due to issues
https://forums.whonix.org/t/allow-loading-signed-kernel-modules-by-default-disallow-kernel-module-loading-by-default/7880/23
2019-09-07 05:39:56 +00:00
cb8170fd80 comment 2019-09-06 11:44:56 +00:00
ccdbc52b82 comment 2019-09-06 11:43:55 +00:00
051856bc8e remove trailing space 2019-09-06 11:42:38 +00:00
0ae5c5ff14 remove umask changes since these are causing issues are are not needed anymore
thanks to home folder permission lockdown

https://forums.whonix.org/t/change-default-umask/7416/45
2019-08-24 12:14:22 -04:00
a8b6281119 Update uncommon-network-protocols.conf
Removing llc from blacklisted network protocols as it is needed by KVM for networking.
See https://hub.packtpub.com/kvm-networking-libvirt/ and https://forums.whonix.org/t/whonix-desktop-installer-with-calamares-field-report/7350/107
2019-08-19 11:30:57 +00:00
ed90d8b025 change default umask to 027
as per:

https://forums.whonix.org/t/change-default-umask/7416/47
2019-08-17 09:55:20 +00:00
224f95799c sudo default umask 006
https://forums.whonix.org/t/change-default-umask/7416/43
2019-08-16 11:15:25 -04:00
85502ad430 Merge branch 'master' into patch-21 2019-08-16 14:35:51 +00:00
dbea7d1511 add hook etc/kernel/postinst.d/30_remove-system-map to remove system.map
on kernel package upgrade;

self-document this package: during upgrade the following will be written
to stdout:

Setting up linux-image-4.19.0-5-amd64 (4.19.37-5+deb10u2) ...
/etc/kernel/postinst.d/30_remove-system-map:
removed '/boot/System.map-4.19.0-5-amd64
2019-08-14 07:22:14 +00:00
9a49b8ecbb Create 40_only_allow_signed_modules.cfg
Require all loaded kernel modules to be signed with a valid key.
2019-08-13 13:33:07 +00:00
5a4ea39566 Create blacklist-bluetooth.conf 2019-07-31 18:30:57 +00:00