Patrick Schleizer
|
73f6523e09
|
bumped changelog version
|
2022-07-23 08:07:37 -04:00 |
|
Patrick Schleizer
|
465775c9dc
|
bumped changelog version
|
2022-07-16 08:00:16 -04:00 |
|
Patrick Schleizer
|
24d6a93eac
|
bumped changelog version
|
2022-07-13 08:28:34 -04:00 |
|
Patrick Schleizer
|
6aa9a9472f
|
bumped changelog version
|
2022-07-09 11:42:24 -04:00 |
|
Patrick Schleizer
|
1b8500cc22
|
bumped changelog version
|
2022-07-07 17:41:13 -04:00 |
|
Patrick Schleizer
|
277749f27b
|
genmkfile debinstfile
|
2022-07-07 15:49:08 -04:00 |
|
Patrick Schleizer
|
1b287a6430
|
bumped changelog version
|
2022-07-05 11:16:33 -04:00 |
|
Patrick Schleizer
|
01b82bf0f0
|
bumped changelog version
|
2022-07-02 18:30:06 -04:00 |
|
Patrick Schleizer
|
e783ddc71e
|
bumped changelog version
|
2022-07-02 17:37:16 -04:00 |
|
Patrick Schleizer
|
3bd87d019f
|
bumped changelog version
|
2022-07-02 16:03:52 -04:00 |
|
Patrick Schleizer
|
aebca1b3dc
|
bumped changelog version
|
2022-07-02 15:52:08 -04:00 |
|
Patrick Schleizer
|
ed8ce9a7d0
|
bumped changelog version
|
2022-07-02 15:32:51 -04:00 |
|
Patrick Schleizer
|
7a448e01a1
|
bumped changelog version
|
2022-07-02 14:27:04 -04:00 |
|
Patrick Schleizer
|
26be74bfe5
|
bumped changelog version
|
2022-06-29 16:25:07 -04:00 |
|
Patrick Schleizer
|
aae4fdcffd
|
bumped changelog version
|
2022-06-29 16:06:33 -04:00 |
|
Patrick Schleizer
|
a1f752ad00
|
bumped changelog version
|
2022-06-29 16:03:58 -04:00 |
|
Patrick Schleizer
|
0b0cda8f8f
|
bumped changelog version
|
2022-06-29 15:24:40 -04:00 |
|
Patrick Schleizer
|
4b0cd53fee
|
bumped changelog version
|
2022-06-29 15:22:41 -04:00 |
|
Patrick Schleizer
|
87e5f49f8d
|
bumped changelog version
|
2022-06-29 14:18:02 -04:00 |
|
Patrick Schleizer
|
81c15e88af
|
bumped changelog version
|
2022-06-29 14:15:48 -04:00 |
|
Patrick Schleizer
|
4d937f551f
|
bumped changelog version
|
2022-06-29 13:03:35 -04:00 |
|
Patrick Schleizer
|
43ea4dbb83
|
bumped changelog version
|
2022-06-29 11:18:59 -04:00 |
|
Patrick Schleizer
|
e5d85d69ef
|
bumped changelog version
|
2022-06-29 10:02:18 -04:00 |
|
Patrick Schleizer
|
af8ff65f84
|
comment
|
2022-06-29 10:01:51 -04:00 |
|
Patrick Schleizer
|
83519a58c7
|
bumped changelog version
|
2022-06-29 09:54:27 -04:00 |
|
Patrick Schleizer
|
38cdf2722b
|
- Wipe LUKS Disk Encryption Key for Root Disk from RAM during Shutdown to defeat Cold Boot Attacks
- Confirm in console output if encrypted mounts (root disk) is unmounted. (Because that is a pre-condition for wiping the LUKS full disk encryption key from RAM.)
Thanks to @friedy10!
https://github.com/friedy10/dracut/tree/master/modules.d/40sdmem
https://forums.whonix.org/t/is-ram-wipe-possible-inside-whonix-cold-boot-attack-defense/5596
|
2022-06-29 09:32:55 -04:00 |
|
Patrick Schleizer
|
adca1ebdf6
|
bumped changelog version
|
2022-06-08 11:05:07 -04:00 |
|
Patrick Schleizer
|
616fe857f7
|
bumped changelog version
|
2022-05-25 06:07:17 -04:00 |
|
Patrick Schleizer
|
2d37e3a1af
|
copyright
|
2022-05-20 14:46:38 -04:00 |
|
Patrick Schleizer
|
0051a6935a
|
bumped changelog version
|
2022-02-10 14:06:54 -05:00 |
|
Patrick Schleizer
|
96026a5e90
|
bumped changelog version
|
2021-09-14 14:18:52 -04:00 |
|
Patrick Schleizer
|
03276fbec5
|
bumped changelog version
|
2021-09-12 11:57:20 -04:00 |
|
Patrick Schleizer
|
64e9f0016a
|
bumped changelog version
|
2021-09-09 12:35:37 -04:00 |
|
Patrick Schleizer
|
d16d9a5455
|
bumped changelog version
|
2021-09-06 09:46:20 -04:00 |
|
Patrick Schleizer
|
bb3a3178f1
|
bumped changelog version
|
2021-09-06 04:55:23 -04:00 |
|
Patrick Schleizer
|
a67d1754d4
|
bumped changelog version
|
2021-09-05 16:04:28 -04:00 |
|
Patrick Schleizer
|
1b09d56718
|
bumped changelog version
|
2021-09-04 18:29:00 -04:00 |
|
Patrick Schleizer
|
1a10293b04
|
bumped changelog version
|
2021-09-04 12:00:55 -04:00 |
|
Patrick Schleizer
|
e2810f348b
|
Depends: libpam-modules-bin
|
2021-09-04 11:50:31 -04:00 |
|
Patrick Schleizer
|
3c64ec8f91
|
bumped changelog version
|
2021-09-02 14:36:53 -04:00 |
|
Patrick Schleizer
|
224ae730c1
|
bumped changelog version
|
2021-08-22 05:32:18 -04:00 |
|
Patrick Schleizer
|
ef2b067c03
|
bumped changelog version
|
2021-08-17 15:24:12 -04:00 |
|
Patrick Schleizer
|
8676beef90
|
bumped changelog version
|
2021-08-10 18:26:32 -04:00 |
|
Patrick Schleizer
|
582492d6d8
|
port from pam_tally2 to pam_faillock
since pam_tally2 was deprecated upstream
|
2021-08-10 17:13:00 -04:00 |
|
Patrick Schleizer
|
6376bbff80
|
bumped changelog version
|
2021-08-05 17:03:43 -04:00 |
|
Patrick Schleizer
|
3756016f42
|
lintian --suppress-tags obsolete-command-in-modprobe.d-file
https://forums.whonix.org/t/blacklist-more-kernel-modules-to-reduce-attack-surface/7989/24
|
2021-08-03 13:04:34 -04:00 |
|
Patrick Schleizer
|
50bdd097df
|
move /usr/lib/security-misc to /usr/libexec/security-misc as per lintian FHS
|
2021-08-03 12:56:31 -04:00 |
|
Patrick Schleizer
|
6607c1e4bd
|
move /usr/lib/helper-scripts and /usr/lib/curl-scripts to /usr/libexec/helper-scripts as per lintian FHS
|
2021-08-03 12:48:57 -04:00 |
|
Patrick Schleizer
|
5e3338f8d3
|
bullseye
|
2021-08-03 05:48:25 -04:00 |
|
Patrick Schleizer
|
82f3961a71
|
bumped changelog version
|
2021-08-01 13:12:08 -04:00 |
|
Patrick Schleizer
|
5a65c35479
|
port LKRG compatibility settings automation for VirtualBox hosts from systemd to dpkg trigger
|
2021-08-01 13:11:18 -04:00 |
|
Patrick Schleizer
|
f03c7978c7
|
bumped changelog version
|
2021-07-25 11:31:45 -04:00 |
|
Patrick Schleizer
|
3ebe9e7c53
|
bumped changelog version
|
2021-07-24 18:10:06 -04:00 |
|
Patrick Schleizer
|
0f86ffef04
|
bumped changelog version
|
2021-06-23 11:20:39 -04:00 |
|
Patrick Schleizer
|
0f3dbfc4a1
|
bumped changelog version
|
2021-06-20 10:16:57 -04:00 |
|
Patrick Schleizer
|
419f1d89c2
|
bumped changelog version
|
2021-06-07 12:13:37 -04:00 |
|
Patrick Schleizer
|
0305baf211
|
bumped changelog version
|
2021-06-01 07:36:59 -04:00 |
|
Patrick Schleizer
|
5bd59991cb
|
bumped changelog version
|
2021-05-05 08:37:56 -04:00 |
|
Patrick Schleizer
|
6e759f9196
|
config-package-dev displace /etc/dkms/framework.conf
https://forums.whonix.org/t/enforce-kernel-module-software-signature-verification-module-signing-disallow-kernel-module-loading-by-default/7880/58
|
2021-04-29 11:17:30 -04:00 |
|
Patrick Schleizer
|
1d35bdf291
|
bumped changelog version
|
2021-04-05 11:58:47 -04:00 |
|
Patrick Schleizer
|
e8ea94325b
|
bumped changelog version
|
2021-03-17 12:31:34 -04:00 |
|
Patrick Schleizer
|
a67007f4b7
|
copyright
|
2021-03-17 09:45:21 -04:00 |
|
Patrick Schleizer
|
0c4a7207e4
|
bumped changelog version
|
2021-03-04 07:09:01 -05:00 |
|
Patrick Schleizer
|
7f30d70295
|
bumped changelog version
|
2021-02-06 06:31:45 -05:00 |
|
Patrick Schleizer
|
3120ff3ec9
|
bumped changelog version
|
2021-01-29 23:37:03 -05:00 |
|
Patrick Schleizer
|
d9aaf59105
|
bumped changelog version
|
2021-01-28 02:15:46 -05:00 |
|
Patrick Schleizer
|
f2595cc254
|
bumped changelog version
|
2021-01-27 05:50:16 -05:00 |
|
Patrick Schleizer
|
480f74cab6
|
bumped changelog version
|
2021-01-24 05:10:36 -05:00 |
|
Patrick Schleizer
|
126c31c37d
|
bumped changelog version
|
2021-01-19 19:41:43 -05:00 |
|
Patrick Schleizer
|
611fbe2c61
|
description
|
2021-01-18 05:39:34 -05:00 |
|
Patrick Schleizer
|
0e8ea5eb72
|
bumped changelog version
|
2021-01-14 02:36:49 -05:00 |
|
Patrick Schleizer
|
353e74fb5f
|
bumped changelog version
|
2021-01-05 08:30:37 -05:00 |
|
Patrick Schleizer
|
a4d7e46141
|
bumped changelog version
|
2020-12-10 05:20:57 -05:00 |
|
Patrick Schleizer
|
261ef85c14
|
bumped changelog version
|
2020-12-01 05:53:06 -05:00 |
|
Patrick Schleizer
|
fe27483886
|
bumped changelog version
|
2020-11-28 06:08:10 -05:00 |
|
Patrick Schleizer
|
0ef35f8770
|
bumped changelog version
|
2020-11-06 10:18:09 -05:00 |
|
Patrick Schleizer
|
f4843b1deb
|
bumped changelog version
|
2020-10-31 06:29:25 -04:00 |
|
Patrick Schleizer
|
b06d4ca299
|
bumped changelog version
|
2020-10-31 06:09:22 -04:00 |
|
Patrick Schleizer
|
881d695bff
|
bumped changelog version
|
2020-10-05 07:03:37 -04:00 |
|
madaidan
|
06ffd5d220
|
Restrict access to debugfs
|
2020-09-28 19:21:20 +00:00 |
|
Patrick Schleizer
|
feb7cea4c5
|
bumped changelog version
|
2020-09-28 10:30:42 -04:00 |
|
Patrick Schleizer
|
5fc7b791db
|
bumped changelog version
|
2020-09-19 09:28:27 -04:00 |
|
Patrick Schleizer
|
98c0decaa4
|
bumped changelog version
|
2020-08-03 09:43:43 -04:00 |
|
Patrick Schleizer
|
b09f5ddc15
|
bumped changelog version
|
2020-07-29 08:33:07 -04:00 |
|
Patrick Schleizer
|
861f9d1022
|
bumped changelog version
|
2020-05-14 13:57:32 -04:00 |
|
Patrick Schleizer
|
81cb6ad246
|
bumped changelog version
|
2020-04-23 12:27:25 -04:00 |
|
Patrick Schleizer
|
aa5631b02b
|
bumped changelog version
|
2020-04-16 08:43:40 -04:00 |
|
Patrick Schleizer
|
df218ad658
|
bumped changelog version
|
2020-04-14 12:40:31 -04:00 |
|
Patrick Schleizer
|
b6dde34bfb
|
bumped changelog version
|
2020-04-13 06:56:34 -04:00 |
|
Patrick Schleizer
|
72be31e870
|
disable proc-hidepid by default because incompatible with pkexec
and undo pkexec wrapper
|
2020-04-12 16:48:13 -04:00 |
|
Patrick Schleizer
|
695ad5b83d
|
bumped changelog version
|
2020-04-09 09:45:30 +00:00 |
|
Patrick Schleizer
|
565ff136e5
|
vm.swappiness=1
import from swappiness-lowest
https://forums.whonix.org/t/vm-swappiness-1-set-swapiness-to-lowest-setting-still-useful-swappiness-lowest/9278
|
2020-04-08 21:04:02 +00:00 |
|
Patrick Schleizer
|
642d4d8d93
|
bumped changelog version
|
2020-04-08 17:13:21 +00:00 |
|
Patrick Schleizer
|
a9d0baffe6
|
python -> python3
|
2020-04-08 16:57:32 +00:00 |
|
Patrick Schleizer
|
4153d8d088
|
apparmor-profile-anondist -> apparmor-profile-dist
|
2020-04-08 16:51:22 +00:00 |
|
Patrick Schleizer
|
bfd6018d8d
|
bumped changelog version
|
2020-04-08 12:51:11 +00:00 |
|
Patrick Schleizer
|
663811a819
|
anon-base-files -> dist-base-files
|
2020-04-08 12:04:13 +00:00 |
|
Patrick Schleizer
|
cc8489df2f
|
bumped changelog version
|
2020-04-06 13:29:23 -04:00 |
|
Patrick Schleizer
|
5c81e1f23f
|
import from anon-gpg-conf
|
2020-04-06 09:25:45 -04:00 |
|
Patrick Schleizer
|
1b2a34ea80
|
bumped changelog version
|
2020-04-04 16:51:42 -04:00 |
|
Patrick Schleizer
|
a2c932aa5a
|
bumped changelog version
|
2020-04-02 07:58:51 -04:00 |
|
Patrick Schleizer
|
d9f2a0e4a1
|
remove 'Build-Depends: ronn' since no longer required
|
2020-04-01 17:34:59 -04:00 |
|
Patrick Schleizer
|
eda9c57a62
|
remove genmkfile
|
2020-04-01 16:57:33 -04:00 |
|
Patrick Schleizer
|
2609fe9c3e
|
add debian install file
|
2020-04-01 16:33:29 -04:00 |
|
Patrick Schleizer
|
d4b2baa9b6
|
bumped changelog version
|
2020-04-01 10:58:16 -04:00 |
|
Patrick Schleizer
|
2ceea8d1fe
|
update copyright year
|
2020-04-01 08:49:59 -04:00 |
|
Patrick Schleizer
|
b6de867dec
|
bumped changelog version
|
2020-04-01 08:26:44 -04:00 |
|
Patrick Schleizer
|
ad022fc0b7
|
fix
|
2020-04-01 08:21:06 -04:00 |
|
Patrick Schleizer
|
354af7085b
|
bumped changelog version
|
2020-03-31 07:41:45 -04:00 |
|
Patrick Schleizer
|
a369a0a94d
|
bumped changelog version
|
2020-03-30 18:42:02 -04:00 |
|
Patrick Schleizer
|
c22adbd92f
|
notify if security-misc installation is forced
|
2020-03-30 18:39:23 -04:00 |
|
Patrick Schleizer
|
7ee5fc1b76
|
bumped changelog version
|
2020-03-30 17:16:46 -04:00 |
|
Patrick Schleizer
|
f663b5eff8
|
skip check if any non-root user is a member of group sudo and console if
environment variable `SECURITY_MISC_INSTALL` is set to `force`
|
2020-03-30 17:15:02 -04:00 |
|
Patrick Schleizer
|
bc22fc9fdb
|
skip check if any non-root user is a member of group sudo and console if file
/var/lib/security-misc/skip_install_check exists
|
2020-03-30 17:12:43 -04:00 |
|
Patrick Schleizer
|
d7a69628b1
|
bumped changelog version
|
2020-03-21 14:56:48 -04:00 |
|
Patrick Schleizer
|
e4118cb21e
|
bumped changelog version
|
2020-03-12 04:43:08 -04:00 |
|
Patrick Schleizer
|
04a87f7029
|
bumped changelog version
|
2020-03-08 09:43:24 -04:00 |
|
Patrick Schleizer
|
44351ec9b7
|
remove no longer needed code for installation of apparmor profiles
|
2020-03-07 21:44:19 -05:00 |
|
Patrick Schleizer
|
71ae623916
|
bumped changelog version
|
2020-03-05 08:36:27 -05:00 |
|
Patrick Schleizer
|
15dde15a36
|
typo
|
2020-03-03 09:42:24 -05:00 |
|
Patrick Schleizer
|
8887af26d6
|
bumped changelog version
|
2020-03-03 09:19:49 -05:00 |
|
Patrick Schleizer
|
cd19c2da00
|
fix lintian warning
|
2020-03-03 09:18:24 -05:00 |
|
Patrick Schleizer
|
7e3fedefb2
|
bumped changelog version
|
2020-03-03 09:12:50 -05:00 |
|
Patrick Schleizer
|
453aa8a4eb
|
Merge pull request #65 from madaidan/userfaultfd
Restrict the userfaultfd() syscall to root
|
2020-02-29 12:28:32 +00:00 |
|
Patrick Schleizer
|
e3e39f2235
|
Merge remote-tracking branch 'origin/master'
|
2020-02-29 05:01:41 -05:00 |
|
Patrick Schleizer
|
b31caefdeb
|
description
|
2020-02-29 04:59:02 -05:00 |
|
Patrick Schleizer
|
bd7678c574
|
Merge pull request #66 from madaidan/mce
Fix docs
|
2020-02-28 12:04:05 +00:00 |
|
madaidan
|
42d3b986c4
|
Update control
|
2020-02-27 17:41:14 +00:00 |
|
Patrick Schleizer
|
4043d2af3f
|
description
|
2020-02-25 02:06:48 -05:00 |
|
Patrick Schleizer
|
0e5187ff24
|
description
|
2020-02-25 02:00:27 -05:00 |
|
madaidan
|
60fbf8b0de
|
Update control
|
2020-02-24 18:24:07 +00:00 |
|
madaidan
|
8ea4e50c8e
|
Update control
|
2020-02-16 19:52:40 +00:00 |
|
Patrick Schleizer
|
01eaee997e
|
bumped changelog version
|
2020-02-15 15:35:44 -05:00 |
|
Patrick Schleizer
|
dce54d5d0f
|
bumped changelog version
|
2020-02-15 15:29:38 -05:00 |
|
Patrick Schleizer
|
1e5946c795
|
Merge branch 'master' into sysrq
|
2020-02-15 10:41:52 +00:00 |
|
madaidan
|
0f49736957
|
Update control
|
2020-02-14 18:18:18 +00:00 |
|
madaidan
|
ace6211176
|
Update control
|
2020-02-14 17:51:17 +00:00 |
|
Patrick Schleizer
|
ad6b766886
|
Merge pull request #57 from madaidan/sysctl
Prevent symlink/hardlink TOCTOU races
|
2020-02-13 18:40:58 +00:00 |
|
Patrick Schleizer
|
14140ad41b
|
bumped changelog version
|
2020-02-13 13:39:45 -05:00 |
|
madaidan
|
2796c2dd00
|
Update control
|
2020-02-12 18:43:19 +00:00 |
|
madaidan
|
14f8458374
|
Update control
|
2020-02-12 18:05:32 +00:00 |
|
Patrick Schleizer
|
163e20b886
|
bumped changelog version
|
2020-02-05 06:31:48 -05:00 |
|
Patrick Schleizer
|
8c5cd865f4
|
bumped changelog version
|
2020-02-03 09:23:13 -05:00 |
|
Patrick Schleizer
|
2291b7f787
|
bumped changelog version
|
2020-02-03 08:43:31 -05:00 |
|
Patrick Schleizer
|
0bd0a4a647
|
bumped changelog version
|
2020-01-30 06:14:34 -05:00 |
|
Patrick Schleizer
|
d69c1839cd
|
bumped changelog version
|
2020-01-30 06:02:26 -05:00 |
|
Patrick Schleizer
|
2711d0f7f0
|
bumped changelog version
|
2020-01-30 01:22:32 -05:00 |
|
Patrick Schleizer
|
c1a0da60be
|
set kernel boot parameter l1tf=full,force and nosmt=force
https://forums.whonix.org/t/should-all-kernel-patches-for-cpu-bugs-be-unconditionally-enabled-vs-performance-vs-applicability/7647/17
|
2020-01-30 00:46:48 -05:00 |
|
Patrick Schleizer
|
efc40da4fb
|
bumped changelog version
|
2020-01-24 12:02:27 -05:00 |
|
Patrick Schleizer
|
f4c54881ac
|
description
|
2020-01-24 04:49:19 -05:00 |
|