raja-grewal
|
9f7480e20a
|
Make terminology consistent
|
2025-10-19 01:41:58 +00:00 |
|
raja-grewal
|
f2c3eba4f0
|
Merge branch 'Kicksecure:master' into docs
|
2025-10-19 12:23:13 +11:00 |
|
Aaron Rainbolt
|
29639fe69e
|
Merge remote-tracking branch 'raja/bad_ipv6_ra' into arraybolt3/trixie
|
2025-10-15 19:01:08 -05:00 |
|
Aaron Rainbolt
|
026d55ac41
|
Typo fixes
|
2025-10-15 18:30:52 -05:00 |
|
Aaron Rainbolt
|
35fce26476
|
Merge remote-tracking branch 'raja/stop_ptrace' into arraybolt3/trixie
|
2025-10-15 18:18:33 -05:00 |
|
raja-grewal
|
f690b58870
|
Add docs relating to panic on OOM
|
2025-10-13 02:08:44 +00:00 |
|
raja-grewal
|
2304174171
|
Insert empty new line
|
2025-10-12 02:32:45 +00:00 |
|
raja-grewal
|
7161430a60
|
Seperate ptrace() disabling into own file
|
2025-10-12 02:27:48 +00:00 |
|
Patrick Schleizer
|
968de33c65
|
Force immediate kernel panic on OOM.
This is to avoid security features such as the screen locker, kloak, emerg-shutdown
from being arbitrarily terminated when the system starts running out of memory.
https://forums.whonix.org/t/screen-locker-in-security-can-we-disable-these-at-least-4-backdoors/8128/14
https://github.com/Kicksecure/security-misc/issues/324
`vm.panic_on_oom=2`
implements https://github.com/Kicksecure/security-misc/issues/324
|
2025-10-10 08:03:03 -04:00 |
|
raja-grewal
|
0c8f2f1b44
|
Add docs about the risks associated with IPv6 RAs
|
2025-10-02 07:05:00 +00:00 |
|
raja-grewal
|
194b8fce4e
|
Disable the usage of ptrace() by all processes
|
2025-09-28 03:20:24 +00:00 |
|
Aaron Rainbolt
|
2a39d5997c
|
security-misc split string changes
|
2025-09-21 16:06:11 -05:00 |
|
Patrick Schleizer
|
f70550d015
|
Split the security-misc into security-misc-shared, security-misc-desktop and security-misc-server: rename files
https://github.com/Kicksecure/security-misc/issues/187
|
2025-09-17 14:49:28 -04:00 |
|
raja-grewal
|
e48897cc44
|
Merge branch 'master' into panic_limits
|
2025-08-21 10:27:44 +10:00 |
|
raja-grewal
|
add054933b
|
Update docs on instant reboot when kernel panic
|
2025-08-21 00:24:28 +00:00 |
|
raja-grewal
|
a471069378
|
Remove link
|
2025-08-19 11:03:05 +10:00 |
|
Aaron Rainbolt
|
b5a36e02f1
|
Merge remote-tracking branch 'raja/panic_limits' into arraybolt3/trixie
|
2025-08-17 13:52:01 -05:00 |
|
raja-grewal
|
247015bcc6
|
Set sysctl kernel.panic=-1
|
2025-08-17 06:27:44 +00:00 |
|
raja-grewal
|
c33f7d04e2
|
Remove duplicate comment
|
2025-08-16 03:32:48 +00:00 |
|
raja-grewal
|
498551536c
|
Update docs
|
2025-08-06 03:12:06 +00:00 |
|
raja-grewal
|
45d20dd972
|
Upgrade sysctls and docs on kernel panics
|
2025-08-06 02:35:15 +00:00 |
|
raja-grewal
|
4314b1e85b
|
Add comment
|
2025-07-01 13:36:39 +10:00 |
|
raja-grewal
|
dd0b55cc45
|
Add reference
|
2025-06-03 12:32:17 +10:00 |
|
raja-grewal
|
ce4b57d1cb
|
Update docs on kernel panics
|
2025-02-03 00:31:45 +00:00 |
|
Patrick Schleizer
|
1b33e83529
|
Merge pull request #291 from raja-grewal/drop_gratuitous_arp
Drop gratuitous ARP packets
|
2025-01-10 10:29:30 -05:00 |
|
Patrick Schleizer
|
486757bfae
|
Merge pull request #290 from raja-grewal/arp_ignore
Respond to ARP requests only if the target IP address is on-link
|
2025-01-10 10:29:12 -05:00 |
|
Patrick Schleizer
|
17ff249150
|
Merge pull request #289 from raja-grewal/arp_filter
Enable ARP filtering
|
2025-01-10 10:28:48 -05:00 |
|
Patrick Schleizer
|
27d19ba568
|
Merge pull request #288 from raja-grewal/shared_media
Deny sending and receiving shared media redirects
|
2025-01-10 10:28:05 -05:00 |
|
raja-grewal
|
1f8eee4720
|
Add missing sentence full stop
|
2025-01-08 18:36:00 +11:00 |
|
Patrick Schleizer
|
33114f771a
|
copyright
|
2024-12-31 13:26:21 -05:00 |
|
raja-grewal
|
2e6e1701a0
|
Set net.ipv4.conf.*.drop_gratuitous_arp=1
|
2024-12-19 10:35:08 +00:00 |
|
raja-grewal
|
c37f4efadf
|
Set net.ipv4.conf.*.arp_ignore=2
|
2024-12-19 10:33:49 +00:00 |
|
raja-grewal
|
af1d06973b
|
Set net.ipv4.conf.*.arp_filter=1
|
2024-12-19 10:31:43 +00:00 |
|
raja-grewal
|
750367a906
|
Set net.ipv4.conf.*.shared_media=0
|
2024-12-19 10:29:56 +00:00 |
|
Patrick Schleizer
|
c7f7196471
|
Merge pull request #287 from raja-grewal/patch
Refactor and add two CPU mitigations
|
2024-12-19 00:31:25 -05:00 |
|
raja-grewal
|
3749f8ff09
|
Update presentation on user namespaces
|
2024-12-18 03:36:09 +00:00 |
|
raja-grewal
|
ca3a73ac13
|
Typo
|
2024-12-17 11:37:10 +00:00 |
|
raja-grewal
|
c116796854
|
arp_ignore: Add reference to 2024-12-10 Mullvad VPN audit details
|
2024-12-12 06:36:47 +00:00 |
|
raja-grewal
|
141b84c40d
|
Provide option to deny sending and receiving shared media redirects
|
2024-11-13 05:42:56 +00:00 |
|
raja-grewal
|
18aec201bf
|
Provide option to harden response to ARP requests
|
2024-11-13 05:41:25 +00:00 |
|
raja-grewal
|
a25d4f8df8
|
Provide option to enable ARP filtering
|
2024-11-13 05:40:21 +00:00 |
|
raja-grewal
|
c2aae73ce1
|
Add reference and move text
|
2024-11-13 05:38:03 +00:00 |
|
raja-grewal
|
a1d1f97955
|
Provide option to drop gratuitous ARP packets
|
2024-11-08 03:58:23 +00:00 |
|
raja-grewal
|
09fe46adc9
|
Clarify KSPP compliance header for the undocumented case
|
2024-10-14 02:54:30 +00:00 |
|
raja-grewal
|
0c0774f6c0
|
Merge branch 'master' into text_2
|
2024-10-06 10:48:52 +00:00 |
|
Patrick Schleizer
|
0e3ffa3f11
|
no longer set kernel.unprivileged_userns_clone=0
because it breaks too much
fixes https://github.com/Kicksecure/security-misc/issues/274
|
2024-10-03 02:58:58 -04:00 |
|
Patrick Schleizer
|
f401d94d5e
|
expand documentation on kernel.unprivileged_userns_clone=0 sysctl
https://github.com/Kicksecure/security-misc/issues/274
|
2024-10-03 02:44:06 -04:00 |
|
raja-grewal
|
f3b50a23c9
|
Add reference on unprivileged_userns_restriction
|
2024-09-26 13:10:01 +00:00 |
|
raja-grewal
|
39d063d494
|
Add KSPP=no definition
|
2024-09-26 13:09:21 +00:00 |
|
raja-grewal
|
870ff88605
|
Comment on Flatpak requiring unprivileged user namespaces
|
2024-09-25 10:01:45 +10:00 |
|