This commit is contained in:
Patrick Schleizer 2019-10-05 09:39:05 +00:00
parent c87fc75f2a
commit aaebb32b66
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -68,6 +68,13 @@ flawed process.
a history of security concerns.
https://en.wikipedia.org/wiki/Bluetooth#History_of_security_concerns
* A systemd service restricts /proc/cpuinfo, /proc/bus, /proc/scsi and
/sys to the root user only. This hides a lot of hardware identifiers from
unprivileged users and increases security as /sys exposes a lot of information
that shouldn't be accessible to unprivileged users. As this will break many
things, it is disabled by default and can optionally be enabled by running
`systemctl enable hide-hardware-info.service` as root.
Uncommon network protocols are blacklisted:
These are rarely used and may have unknown vulnerabilities.
/etc/modprobe.d/uncommon-network-protocols.conf