Now is the time for tinfoil autism. Secure your computers, router, modem, cellphone, videogame console, TV, printer, car, hvac, lights, doorlocks. They will be used against us and you.
Robert Cooper
bump
Nathan Lewis
/fucko/ in the title please
Anyone else notice a bug in recent cryptsetup that doesn't let you create a detached header file?
Anyone rocking a grsec kernel?
Chase Campbell
>Anyone else notice a bug in recent cryptsetup that doesn't let you create a detached header file? I don't have detached headers on my partitions. Do you keep them on USB flash? What version of cryptsetup are you using?
Caleb Stewart
The newest in arch repos. Im trying to setup a blind system that only boots from a USB key, and contains just seemingly random data otherwise, so naturally the luks header has to be detached. I think it's a recent regression. But maybe it's my syntax, I was throwing a few dozen parameters at it
>Linux """"""""""Hardening"""""""""" So a shitty version of OpenBSD?
Carter Kelly
Quick tip: install firejail, and use it to sandbox your default media programs. PDF readers, image viewers, music and video players especially should all be sandboxed. Usually adding firejail to each program's desktop file under /use/share/applications should do the trick. They should have --seccomp and --net=none to block network access. The more paranoid can have complicated setups where the only thing on the disk they can access is the PDF you just clicked.
On a related note, anyone have a good way of sandboxing the default gnome/Nautilus thumbnailers? I can't even find which binary is producing them. They have known attack vectors and I'd rather patch em.
Wyatt Green
>OpenBSD So a shitty version of FreeBSD?
Hudson Martin
>FreeBSD >literally OpenBSD with old packages and less security features turned on in the kernel
Charles Hughes
Openbsd is only """""""""""""""""""""""'secure"""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""" when you stay in their limited software repo,once you branch out of that, its hands up and the same as any other distro
Asher Edwards
BSD wannabes GET OUT! REEEEEEEE
Gavin Morgan
the hipsters have arrived
Carter Ortiz
Oh I forgot the actual papers good read if you just starting out ;
>limited software repo It's like you never wrote your own software using OpenBSD's style guide to make sure it's secure.
Andrew Cox
*cucked*
Chase Robinson
>donate to grsecurity >literal autists that rageban people when they point out bugs in their shitty software
Hudson Turner
put some red boxes in there i am not reading all of this trash give me a comprehensive list of os's/distros safer than openbsd
Daniel Hernandez
Why not write your own kernel then?
Jacob Johnson
why don't you build your own house or design your own car
Jonathan Brooks
Ah, nice fallacy. +1
Brody Sanchez
>the x86 designers collapsed the read and execute memory flags into one in order to save space. Since a page can either be writable or readable and executable it is not useful to set buffers as non-executable since they would no longer be readable. So on x86 PaX emulates this behavior at a software level, which introduces overhead but is very helpful for system security.
why you do this x86 designers, space is so cheap in 2016
Joshua Perez
nice argument, nice reply with literally 0 content what a great platform for discussion Sup Forums is, really attracts the smartest people
Jonathan Gomez
>space is so cheap in 2016 >meanwhile Intlel's processors are actually getting slower because they're dedicating more of that precious space to vidya hardware
Isaiah Hall
new thread
Isaac Roberts
>encrypted partition Enjoy losing all your data from random bit flip
>selinux Enjoy spending hours creating a profile for graphical applications
Colton Hughes
>>encrypted partition >Enjoy losing all your data from random bit flip That's why you have multiple HDD
Robert Perry
This has never happened to me. The only data that would be sensitive to a single bit flip would perhaps be the encrypted master key. But of course, you backed up your encryption headers, right?
Josiah Edwards
You expect a response to your fallacy? +1 There ya go kiddo.
William Carter
"i am so correct that i don't even need to argue. i can just say words and win because i am better." it's a rough life once you're out of high school, kid
Zachary Ward
+1 +1
Levi Nelson
...
Justin Rogers
Hardening doesn't do shit if you're logged in and get a drive by media attack thanks to the absolute shit security of Linux (((desktop))).
Good luck faggots.
Asher Ortiz
>drive by media Thank you Sup Forums. Fortunately some of us don't install Gstreamer bad plugins or Adobe software.
Nolan Martin
how do I encrypt and dual boot
Ian Myers
This look like a good thread to have around. Contribooting.
Privacy Tools - Encryption against global mass surveillance: privacytools.io/
PRISM Break - Opt out of global data surveillance programs like PRISM, XKeyscore, and Tempora: prism-break.org/en/
I suggest to use either Firefox-esr or Icecat, then here are addons and the reasons to use it:
Depends with grsecurity you have strong mprotect & RBAC if your policy is good even root can't do anything on the system.
Caleb Ward
encrypt with luks, then lvm, then make your regular partitions if you want windows (which of course, defeats the purpose of encryption if you will give your data over network while in ram)
Justin Young
How do I get good with policies? I am new to this.
Apparently grsecurity has much I could use, but some reviews on the internet say is good for beginners.
I wish there where an up to date MAC that uses inodes instead of SELinux labels thou.
Eli Flores
>But of course, you backed up your encryption headers, right?
No... How to senpai?
Jayden Campbell
Yea i don't like SELinux because it's way to complicated to setup a full strict policy, most distros have only enforced so only few applications are confined
Landon Sullivan
>car, hvac, lights, doorlocks.
Not securing your pens, pencils, crayons, markers...