Patrick Schleizer
|
f8913ceb2e
|
Revert "set default umask to 027"
This reverts commit cd216095eb .
|
2023-11-03 09:43:44 -04:00 |
|
Patrick Schleizer
|
43bd789c30
|
bumped changelog version
|
2023-11-03 09:28:08 -04:00 |
|
Patrick Schleizer
|
cd216095eb
|
set default umask to 027
using package libpam-umask
https://www.debian.org/doc/manuals/securing-debian-manual/ch04s11.en.html#id-1.5.14.19
https://github.com/Kicksecure/security-misc/pull/151
|
2023-11-03 09:12:24 -04:00 |
|
monsieuremre
|
3ee4be652b
|
depend on libpam-tmpdir
|
2023-11-02 09:36:58 +00:00 |
|
Patrick Schleizer
|
a768f1f1eb
|
bumped changelog version
|
2023-11-01 12:26:21 -04:00 |
|
Patrick Schleizer
|
5ed2a5ce4a
|
bumped changelog version
|
2023-11-01 11:10:36 -04:00 |
|
monsieuremre
|
90a88225a4
|
security-misc.maintscript
|
2023-10-27 14:38:31 +00:00 |
|
Patrick Schleizer
|
7d576842fb
|
bumped changelog version
|
2023-10-26 20:08:41 -04:00 |
|
Patrick Schleizer
|
ca9603af17
|
bumped changelog version
|
2023-10-26 12:23:48 -04:00 |
|
Patrick Schleizer
|
5f4222c1c3
|
enable SUID Disabler and Permission Hardener by default
https://www.kicksecure.com/wiki/SUID_Disabler_and_Permission_Hardener
https://forums.whonix.org/t/suid-disabler-and-permission-hardener/7706
|
2023-10-26 12:20:48 -04:00 |
|
Patrick Schleizer
|
8557e0963e
|
bumped changelog version
|
2023-10-25 17:55:37 -04:00 |
|
Patrick Schleizer
|
b7e2d49f5f
|
comment
|
2023-10-25 17:41:05 -04:00 |
|
Patrick Schleizer
|
a2f811aff0
|
Merge pull request #135 from monsieuremre/kernel-fix
Kernel hardening fix
|
2023-10-25 17:26:46 -04:00 |
|
monsieuremre
|
ee6716e178
|
security-misc.maintscript
|
2023-10-24 20:43:10 +00:00 |
|
Patrick Schleizer
|
3317332cb4
|
bumped changelog version
|
2023-10-24 05:51:11 -04:00 |
|
Patrick Schleizer
|
f3b40f12cb
|
bumped changelog version
|
2023-10-22 19:23:22 -04:00 |
|
Patrick Schleizer
|
ee15f749bb
|
bumped changelog version
|
2023-10-22 16:54:58 -04:00 |
|
Patrick Schleizer
|
a1c3b87fce
|
bumped changelog version
|
2023-10-22 16:29:08 -04:00 |
|
Patrick Schleizer
|
9a649ddd09
|
bumped changelog version
|
2023-10-22 16:16:40 -04:00 |
|
Patrick Schleizer
|
555d83792d
|
bumped changelog version
|
2023-10-22 15:44:47 -04:00 |
|
Patrick Schleizer
|
316282952f
|
bumped changelog version
|
2023-10-22 15:40:59 -04:00 |
|
Patrick Schleizer
|
fa0804b7ae
|
bumped changelog version
|
2023-10-22 15:33:21 -04:00 |
|
Patrick Schleizer
|
36f2acb93f
|
bumped changelog version
|
2023-10-22 15:28:04 -04:00 |
|
Patrick Schleizer
|
f440209738
|
bumped changelog version
|
2023-10-22 14:46:42 -04:00 |
|
Patrick Schleizer
|
b29b626b41
|
bumped changelog version
|
2023-10-22 14:30:28 -04:00 |
|
Patrick Schleizer
|
3c183294cd
|
bumped changelog version
|
2023-10-22 13:31:55 -04:00 |
|
Patrick Schleizer
|
f70f36e6cf
|
bumped changelog version
|
2023-10-22 12:55:41 -04:00 |
|
Patrick Schleizer
|
1696c37251
|
bumped changelog version
|
2023-10-22 11:28:18 -04:00 |
|
Patrick Schleizer
|
975a017dec
|
bumped changelog version
|
2023-10-22 11:13:05 -04:00 |
|
Patrick Schleizer
|
a423b85f81
|
bumped changelog version
|
2023-10-22 10:50:30 -04:00 |
|
Patrick Schleizer
|
1120d0652d
|
bumped changelog version
|
2023-10-22 10:16:53 -04:00 |
|
Patrick Schleizer
|
4f6f45fb39
|
bumped changelog version
|
2023-10-22 10:01:54 -04:00 |
|
Patrick Schleizer
|
f472ce690a
|
comments
|
2023-10-22 08:57:35 -04:00 |
|
Patrick Schleizer
|
05e9accf64
|
bumped changelog version
|
2023-10-22 08:12:30 -04:00 |
|
Patrick Schleizer
|
27b3ba8bdf
|
bumped changelog version
|
2023-10-22 07:06:00 -04:00 |
|
Patrick Schleizer
|
ef3f157573
|
bumped changelog version
|
2023-10-21 14:19:24 -04:00 |
|
Patrick Schleizer
|
ae2c1c5a7a
|
fix xession environment variable
|
2023-10-21 14:18:50 -04:00 |
|
Patrick Schleizer
|
43375fa1f4
|
bumped changelog version
|
2023-10-21 12:34:59 -04:00 |
|
Patrick Schleizer
|
d543825d85
|
comments
|
2023-10-21 12:24:59 -04:00 |
|
Patrick Schleizer
|
dd43ab634d
|
bumped changelog version
|
2023-10-13 15:22:58 -04:00 |
|
Patrick Schleizer
|
13a4f37e50
|
bumped changelog version
|
2023-10-12 12:51:37 -04:00 |
|
Patrick Schleizer
|
e96e6aa38e
|
bumped changelog version
|
2023-10-12 10:43:40 -04:00 |
|
Patrick Schleizer
|
fa820e8978
|
refactoring environment variables loading mechanism
|
2023-10-12 10:40:27 -04:00 |
|
Patrick Schleizer
|
358e4226f1
|
bumped changelog version
|
2023-07-17 11:48:35 -04:00 |
|
Patrick Schleizer
|
81ad786dfc
|
Kicksecure
|
2023-07-17 11:19:07 -04:00 |
|
Patrick Schleizer
|
ab56b7ca0c
|
Kicksecure
|
2023-07-17 11:10:05 -04:00 |
|
Patrick Schleizer
|
29aaf13c13
|
bumped changelog version
|
2023-06-23 08:18:12 +00:00 |
|
Patrick Schleizer
|
609c8c0697
|
bumped changelog version
|
2023-06-21 09:36:44 +00:00 |
|
Patrick Schleizer
|
94a326ec7f
|
bookworm
|
2023-06-21 09:11:31 +00:00 |
|
Patrick Schleizer
|
b610cdcbcd
|
bumped changelog version
|
2023-06-16 11:09:02 +00:00 |
|
Patrick Schleizer
|
63599a09d7
|
bumped changelog version
|
2023-06-14 09:59:20 +00:00 |
|
Patrick Schleizer
|
be990188f5
|
bumped changelog version
|
2023-06-12 18:01:55 +00:00 |
|
Patrick Schleizer
|
07b3ce0bcd
|
Standards-Version: 4.6.1.0
|
2023-06-12 16:22:32 +00:00 |
|
Patrick Schleizer
|
4e28ace103
|
bumped changelog version
|
2023-05-15 17:31:59 +00:00 |
|
Patrick Schleizer
|
c921d4e915
|
bumped changelog version
|
2023-05-15 11:56:30 +00:00 |
|
Patrick Schleizer
|
6511dac1d4
|
bumped changelog version
|
2023-05-06 12:00:12 +00:00 |
|
Patrick Schleizer
|
a815c9b986
|
bumped changelog version
|
2023-05-06 11:54:31 +00:00 |
|
Patrick Schleizer
|
b756314eb8
|
bumped changelog version
|
2023-05-05 15:09:32 +00:00 |
|
Patrick Schleizer
|
d6d79e96c9
|
minor mmap-rnd-bits improvements
|
2023-05-05 14:44:29 +00:00 |
|
Jeremy Rand
|
2cf105700a
|
postinst: Don't fail if mmap-rnd-bits fails
|
2023-04-24 23:07:40 +00:00 |
|
Jeremy Rand
|
61f63255ac
|
vm.mmap_rnd_bits: Fix ppc64le
Probably fixes a bunch of other non-x86_64 arches too.
|
2023-04-24 23:07:39 +00:00 |
|
Raja Grewal
|
7a4212dd76
|
Update copyright
|
2023-03-30 17:08:47 +11:00 |
|
Patrick Schleizer
|
1137e6c910
|
bumped changelog version
|
2023-01-30 05:58:47 -05:00 |
|
Patrick Schleizer
|
56c7c57b3a
|
bumped changelog version
|
2023-01-24 07:09:40 -05:00 |
|
Patrick Schleizer
|
a482008650
|
bumped changelog version
|
2023-01-24 07:05:53 -05:00 |
|
Patrick Schleizer
|
11d0bb2c00
|
bumped changelog version
|
2023-01-09 07:05:18 -05:00 |
|
Patrick Schleizer
|
c506652187
|
fix
|
2023-01-09 07:05:06 -05:00 |
|
Patrick Schleizer
|
b3d85f115c
|
bumped changelog version
|
2023-01-09 07:02:01 -05:00 |
|
Patrick Schleizer
|
ad5d0d4b12
|
disable kexec (revert enabling kexec)
remove kexec-utils for ram-wipe since moved to its own package
|
2023-01-09 06:37:45 -05:00 |
|
Patrick Schleizer
|
87c4e77c01
|
migrate to ram-wipe package
|
2023-01-09 06:23:00 -05:00 |
|
Patrick Schleizer
|
3867acf723
|
bumped changelog version
|
2023-01-09 05:34:48 -05:00 |
|
Patrick Schleizer
|
7fa6946694
|
bumped changelog version
|
2023-01-08 07:17:02 -05:00 |
|
Patrick Schleizer
|
e81dd6cd25
|
bumped changelog version
|
2023-01-07 18:13:57 -05:00 |
|
Patrick Schleizer
|
921bc3e867
|
bumped changelog version
|
2023-01-07 17:49:24 -05:00 |
|
Patrick Schleizer
|
1d22ebde08
|
bumped changelog version
|
2023-01-07 17:23:35 -05:00 |
|
Patrick Schleizer
|
abbaea582d
|
bumped changelog version
|
2023-01-07 17:16:23 -05:00 |
|
Patrick Schleizer
|
fa579cad89
|
bumped changelog version
|
2023-01-07 16:20:48 -05:00 |
|
Patrick Schleizer
|
c1b87d250c
|
bumped changelog version
|
2023-01-07 15:37:47 -05:00 |
|
Patrick Schleizer
|
1e19c2cbad
|
Depends: kexec-tools
required for cold boot attack defense second RAM wipe after reboot
|
2023-01-07 15:32:25 -05:00 |
|
Patrick Schleizer
|
d5271d6250
|
bumped changelog version
|
2023-01-07 14:31:40 -05:00 |
|
Patrick Schleizer
|
53ab93d8f6
|
bumped changelog version
|
2023-01-07 14:27:42 -05:00 |
|
Patrick Schleizer
|
42ab341a58
|
bumped changelog version
|
2023-01-07 12:57:36 -05:00 |
|
Patrick Schleizer
|
929f49f333
|
bumped changelog version
|
2022-12-18 14:37:51 -05:00 |
|
Patrick Schleizer
|
98f753d8ff
|
bumped changelog version
|
2022-11-24 07:21:58 -05:00 |
|
Patrick Schleizer
|
ad1e722879
|
bumped changelog version
|
2022-11-24 07:00:33 -05:00 |
|
Patrick Schleizer
|
4601e106c4
|
bumped changelog version
|
2022-11-24 06:49:26 -05:00 |
|
Patrick Schleizer
|
73963a9e68
|
bumped changelog version
|
2022-11-24 06:31:37 -05:00 |
|
Patrick Schleizer
|
97722d1926
|
bumped changelog version
|
2022-11-24 06:14:15 -05:00 |
|
Patrick Schleizer
|
d7222b5678
|
bumped changelog version
|
2022-11-22 06:03:13 -05:00 |
|
Patrick Schleizer
|
d419898ee4
|
bumped changelog version
|
2022-11-17 10:15:36 -05:00 |
|
Patrick Schleizer
|
2319458e9f
|
bumped changelog version
|
2022-08-24 18:28:39 -04:00 |
|
Patrick Schleizer
|
ff8451469a
|
bumped changelog version
|
2022-08-13 11:40:04 -04:00 |
|
Patrick Schleizer
|
272a33fe2c
|
addgroup -> adduser fix
|
2022-08-13 11:35:25 -04:00 |
|
Patrick Schleizer
|
7d5246693c
|
bumped changelog version
|
2022-08-12 07:52:26 -04:00 |
|
Patrick Schleizer
|
1095949523
|
bumped changelog version
|
2022-07-26 10:00:53 -04:00 |
|
Patrick Schleizer
|
73f6523e09
|
bumped changelog version
|
2022-07-23 08:07:37 -04:00 |
|
Patrick Schleizer
|
465775c9dc
|
bumped changelog version
|
2022-07-16 08:00:16 -04:00 |
|
Patrick Schleizer
|
24d6a93eac
|
bumped changelog version
|
2022-07-13 08:28:34 -04:00 |
|
Patrick Schleizer
|
6aa9a9472f
|
bumped changelog version
|
2022-07-09 11:42:24 -04:00 |
|
Patrick Schleizer
|
1b8500cc22
|
bumped changelog version
|
2022-07-07 17:41:13 -04:00 |
|
Patrick Schleizer
|
277749f27b
|
genmkfile debinstfile
|
2022-07-07 15:49:08 -04:00 |
|
Patrick Schleizer
|
1b287a6430
|
bumped changelog version
|
2022-07-05 11:16:33 -04:00 |
|
Patrick Schleizer
|
01b82bf0f0
|
bumped changelog version
|
2022-07-02 18:30:06 -04:00 |
|
Patrick Schleizer
|
e783ddc71e
|
bumped changelog version
|
2022-07-02 17:37:16 -04:00 |
|
Patrick Schleizer
|
3bd87d019f
|
bumped changelog version
|
2022-07-02 16:03:52 -04:00 |
|
Patrick Schleizer
|
aebca1b3dc
|
bumped changelog version
|
2022-07-02 15:52:08 -04:00 |
|
Patrick Schleizer
|
ed8ce9a7d0
|
bumped changelog version
|
2022-07-02 15:32:51 -04:00 |
|
Patrick Schleizer
|
7a448e01a1
|
bumped changelog version
|
2022-07-02 14:27:04 -04:00 |
|
Patrick Schleizer
|
26be74bfe5
|
bumped changelog version
|
2022-06-29 16:25:07 -04:00 |
|
Patrick Schleizer
|
aae4fdcffd
|
bumped changelog version
|
2022-06-29 16:06:33 -04:00 |
|
Patrick Schleizer
|
a1f752ad00
|
bumped changelog version
|
2022-06-29 16:03:58 -04:00 |
|
Patrick Schleizer
|
0b0cda8f8f
|
bumped changelog version
|
2022-06-29 15:24:40 -04:00 |
|
Patrick Schleizer
|
4b0cd53fee
|
bumped changelog version
|
2022-06-29 15:22:41 -04:00 |
|
Patrick Schleizer
|
87e5f49f8d
|
bumped changelog version
|
2022-06-29 14:18:02 -04:00 |
|
Patrick Schleizer
|
81c15e88af
|
bumped changelog version
|
2022-06-29 14:15:48 -04:00 |
|
Patrick Schleizer
|
4d937f551f
|
bumped changelog version
|
2022-06-29 13:03:35 -04:00 |
|
Patrick Schleizer
|
43ea4dbb83
|
bumped changelog version
|
2022-06-29 11:18:59 -04:00 |
|
Patrick Schleizer
|
e5d85d69ef
|
bumped changelog version
|
2022-06-29 10:02:18 -04:00 |
|
Patrick Schleizer
|
af8ff65f84
|
comment
|
2022-06-29 10:01:51 -04:00 |
|
Patrick Schleizer
|
83519a58c7
|
bumped changelog version
|
2022-06-29 09:54:27 -04:00 |
|
Patrick Schleizer
|
38cdf2722b
|
- Wipe LUKS Disk Encryption Key for Root Disk from RAM during Shutdown to defeat Cold Boot Attacks
- Confirm in console output if encrypted mounts (root disk) is unmounted. (Because that is a pre-condition for wiping the LUKS full disk encryption key from RAM.)
Thanks to @friedy10!
https://github.com/friedy10/dracut/tree/master/modules.d/40sdmem
https://forums.whonix.org/t/is-ram-wipe-possible-inside-whonix-cold-boot-attack-defense/5596
|
2022-06-29 09:32:55 -04:00 |
|
Patrick Schleizer
|
adca1ebdf6
|
bumped changelog version
|
2022-06-08 11:05:07 -04:00 |
|
Patrick Schleizer
|
616fe857f7
|
bumped changelog version
|
2022-05-25 06:07:17 -04:00 |
|
Patrick Schleizer
|
2d37e3a1af
|
copyright
|
2022-05-20 14:46:38 -04:00 |
|
Patrick Schleizer
|
0051a6935a
|
bumped changelog version
|
2022-02-10 14:06:54 -05:00 |
|
Patrick Schleizer
|
96026a5e90
|
bumped changelog version
|
2021-09-14 14:18:52 -04:00 |
|
Patrick Schleizer
|
03276fbec5
|
bumped changelog version
|
2021-09-12 11:57:20 -04:00 |
|
Patrick Schleizer
|
64e9f0016a
|
bumped changelog version
|
2021-09-09 12:35:37 -04:00 |
|
Patrick Schleizer
|
d16d9a5455
|
bumped changelog version
|
2021-09-06 09:46:20 -04:00 |
|
Patrick Schleizer
|
bb3a3178f1
|
bumped changelog version
|
2021-09-06 04:55:23 -04:00 |
|
Patrick Schleizer
|
a67d1754d4
|
bumped changelog version
|
2021-09-05 16:04:28 -04:00 |
|
Patrick Schleizer
|
1b09d56718
|
bumped changelog version
|
2021-09-04 18:29:00 -04:00 |
|
Patrick Schleizer
|
1a10293b04
|
bumped changelog version
|
2021-09-04 12:00:55 -04:00 |
|
Patrick Schleizer
|
e2810f348b
|
Depends: libpam-modules-bin
|
2021-09-04 11:50:31 -04:00 |
|
Patrick Schleizer
|
3c64ec8f91
|
bumped changelog version
|
2021-09-02 14:36:53 -04:00 |
|
Patrick Schleizer
|
224ae730c1
|
bumped changelog version
|
2021-08-22 05:32:18 -04:00 |
|
Patrick Schleizer
|
ef2b067c03
|
bumped changelog version
|
2021-08-17 15:24:12 -04:00 |
|
Patrick Schleizer
|
8676beef90
|
bumped changelog version
|
2021-08-10 18:26:32 -04:00 |
|
Patrick Schleizer
|
582492d6d8
|
port from pam_tally2 to pam_faillock
since pam_tally2 was deprecated upstream
|
2021-08-10 17:13:00 -04:00 |
|
Patrick Schleizer
|
6376bbff80
|
bumped changelog version
|
2021-08-05 17:03:43 -04:00 |
|
Patrick Schleizer
|
3756016f42
|
lintian --suppress-tags obsolete-command-in-modprobe.d-file
https://forums.whonix.org/t/blacklist-more-kernel-modules-to-reduce-attack-surface/7989/24
|
2021-08-03 13:04:34 -04:00 |
|
Patrick Schleizer
|
50bdd097df
|
move /usr/lib/security-misc to /usr/libexec/security-misc as per lintian FHS
|
2021-08-03 12:56:31 -04:00 |
|
Patrick Schleizer
|
6607c1e4bd
|
move /usr/lib/helper-scripts and /usr/lib/curl-scripts to /usr/libexec/helper-scripts as per lintian FHS
|
2021-08-03 12:48:57 -04:00 |
|
Patrick Schleizer
|
5e3338f8d3
|
bullseye
|
2021-08-03 05:48:25 -04:00 |
|
Patrick Schleizer
|
82f3961a71
|
bumped changelog version
|
2021-08-01 13:12:08 -04:00 |
|
Patrick Schleizer
|
5a65c35479
|
port LKRG compatibility settings automation for VirtualBox hosts from systemd to dpkg trigger
|
2021-08-01 13:11:18 -04:00 |
|
Patrick Schleizer
|
f03c7978c7
|
bumped changelog version
|
2021-07-25 11:31:45 -04:00 |
|
Patrick Schleizer
|
3ebe9e7c53
|
bumped changelog version
|
2021-07-24 18:10:06 -04:00 |
|
Patrick Schleizer
|
0f86ffef04
|
bumped changelog version
|
2021-06-23 11:20:39 -04:00 |
|
Patrick Schleizer
|
0f3dbfc4a1
|
bumped changelog version
|
2021-06-20 10:16:57 -04:00 |
|