Commit Graph

34 Commits

Author SHA1 Message Date
a72bbb1883 Corrected kerenl module disabling 2022-07-13 23:42:13 +10:00
48089e5ba4 More verbose kernel module blocking error logs 2022-07-12 17:02:12 +10:00
40ec791774 Updated comments 2022-07-12 16:58:16 +10:00
ef1ef9917d Blacklist automatic loading of CD-ROM modules 2022-07-10 04:53:25 +10:00
61ef9bd59f Incorporated Ubuntu’s kernel module blacklists 2022-07-10 04:52:00 +10:00
26b2c9727f not blacklist CD-ROM / DVD yet
https://forums.whonix.org/t/blacklist-more-kernel-modules-to-reduce-attack-surface/7989/31
2022-07-07 15:39:40 -04:00
ca19d78d48 shuffle 2022-07-07 15:27:15 -04:00
780dc8eec9 replace /bin/false -> /bin/disabled-by-security-misc 2022-07-08 04:11:25 +10:00
fa2e30f512 Updated descriptions of disabled modules 2022-07-08 03:04:37 +10:00
da389d6682 Revert "replace /bin/false -> /bin/true"
This reverts commit f0511635a9.
2022-07-08 02:12:04 +10:00
f0511635a9 replace /bin/false -> /bin/true 2022-07-07 09:27:53 +00:00
18d67dbc53 Blacklist more modules 2022-07-07 09:26:55 +00:00
2d37e3a1af copyright 2022-05-20 14:46:38 -04:00
a67007f4b7 copyright 2021-03-17 09:45:21 -04:00
da1ac48cde unblacklist squashfs as this would likely break Whonix-Host ISO
https://github.com/Whonix/security-misc/pull/75#issuecomment-700044182
2020-09-28 10:29:50 -04:00
4070133ed6 unblacklist vfat
https://github.com/Whonix/security-misc/pull/75#issuecomment-695201068
2020-09-28 10:25:57 -04:00
a813e7da07 Blacklist more modules 2020-09-19 20:46:19 +01:00
2ceea8d1fe update copyright year 2020-04-01 08:49:59 -04:00
e0aa67677d merge the many modprobe.d config files into 1
and use a name starting with double digits

to make it easier to disable settings using a lexically higher config file
2020-01-24 04:30:36 -05:00
a662a76a52 Blacklist vivid 2020-01-11 18:37:00 +00:00
dd93b11321 Blacklist CPU MSRs 2019-12-22 13:52:43 +00:00
a14a2854c6 Elaborate 2019-10-16 18:52:14 +00:00
7affddb3bb blacklist modules with /bin/false rather than /bin/true to fail with error
message rather than failing without notification
2019-09-07 05:47:34 +00:00
a8b6281119 Update uncommon-network-protocols.conf
Removing llc from blacklisted network protocols as it is needed by KVM for networking.
See https://hub.packtpub.com/kvm-networking-libvirt/ and https://forums.whonix.org/t/whonix-desktop-installer-with-calamares-field-report/7350/107
2019-08-19 11:30:57 +00:00
5a4ea39566 Create blacklist-bluetooth.conf 2019-07-31 18:30:57 +00:00
b63d4ccb41 Update uncommon-network-protocols.conf 2019-07-11 15:28:56 +00:00
4058e283a5 Blacklist more uncommon network protocols 2019-07-10 14:27:19 +00:00
d70440aaed Remove duplicate 2019-07-09 21:57:37 +00:00
2d27bdd808 Blacklist more uncommon network protocols 2019-07-09 21:55:37 +00:00
46409be8b6 Use install instead of blacklist 2019-07-04 14:25:28 +00:00
eb7eaffba1 Blacklist n-hdlc 2019-07-04 14:24:44 +00:00
07c6362f1a Blacklist thunderbolt and firewire 2019-06-23 18:34:45 +00:00
7177c6041a Create uncommon-network-protocols.conf 2019-05-16 20:30:49 +00:00
6cda8b1496 disable conntrack helper for better security
https://phabricator.whonix.org/T486
2016-10-10 16:10:30 +00:00