Bug#928546: /etc/fstab.d

2019-05-06 Thread john.pseudonym1
Package: util-linux Version: 2.29.2-1 Severity: normal Hi, As part of the hardening of an anonymity focused operating system called Whonix, we need to add different mount options for different filesystems e.g. hidepid=2 on /proc or noexec on /home. To make sure that a user's own fstab configur

Bug#928362: Enable some kernel hardening by default

2019-05-02 Thread john.pseudonym1
Package: linux-image-amd64 Version: 4.19+104 Severity: important Hi, It would be great if Debian included some kernel hardening by default. These settings would offer great security benefits and no or very minimal performance decrease. Setting “kernel.kptr_restrict=1” with sysctl makes kernel