@kravietz The main goal of using a grub password is preventing someone from booting, pressing e setting /bin/bash as init and use vi to write nasty little scripts around your boot partition. It rasies the bar to "I have to open the device" which that again can be made visible using nail polish:
https://mullvad.net/en/blog/2016/12/14/how-tamper-protect-laptop-nail-polish/
At least when you are paranoid enough.
Also of course you should use secureboot as you mentioned.
@kravietz Set a grub password!
Use OpenSCAP Workbench with the proper profile for Ubuntu, Fedora or CentOS to check compliance.
Full set of instructions (one might want to select just a few, but still):
I guess that should already help a lot :)
3) When there's choice between .deb and Snap/Flatpak version available (there is for Firefox, Brave and many other popular programs) always go for Snap/Flatpak version as it runs in a much more effective sandbox.
This doesn't come completely free either because with Snaps your profile file move to the sandbox but it's quite a simple operation.
2) Always run the latest available Linux distro - so in case of Ubuntu go for 19.10 - and always have all updates installed.
My answers in random order:
1) Make sure you have Secure Boot enabled in BIOS, and BIOS password set.
That's pretty much all you can do to prevent backdooring & keysniffing of your bootloader today when someone covertly gets physical acces to your laptop.
If this is a viable threat, go for QubesOS, but be aware of its limitations (e.g. inability to access GPU by the operating system, so no games or 3D graphics)
Just had an interesting question from a colleague who has a #linux notebook and works remotely from random places:
> I've got full-disk #encryption (FDE), what else I can do for #security ?
One reason why #CloudFlare's 1.1.1.1 resolver is so fast is that it seems to be making a tradeoff between speed and freshness of responses. Specifically it seems to cache RRs for as long as allowed, while other public resolvers will recheck much earlier. #dns
LOL a nice list of names preferred by weirdos from different countries, for example "1000-jaehriges-reich", whose registration is blocked in .eu https://eurid.eu/en/register-a-eu-domain/rules-for-eu-domains/list-blocked-names/
#Ansible role to install, configure and manage zones using #Yadifa, a #DNSSEC enabled authoritative-only #DNS nameserver https://bitbucket.org/kravietz/ansible-yadifa/src/master/
" EU unveils โฌ3bn research fund to develop batteries
Seven member states to invest in the project which is set to run until 2031" #renewable
https://amp.ft.com/content/53a92e68-1a6b-11ea-9186-7348c2f183af
Avast, a cybersecurity company, sells its customers' browsing data
https://www.reddit.com/r/privacy/comments/e8bopk/avast_a_cybersecurity_company_sells_its_customers/
After months of work, we have a new stable release series.
Tor 0.4.2.5 is the first stable in the 0.4.2.x series. This series improves reliability and stability and includes several stability and correctness improvements for onion services. https://blog.torproject.org/new-release-0425-also-0417-0406-and-0359
Medicare chief asked taxpayers to cover stolen jewelry.
Seema Verma requested $47,000 for items taken from an SUV that took her to a speech. https://www.politico.com/news/2019/12/07/medicare-chief-asked-taxpayers-to-cover-stolen-jewelry-077761
Wireguard will be included in the newest Linux-kernel! -> https://lists.zx2c4.com/pipermail/wireguard/2019-December/004704.html @NGIZero is proud to have funded this effort which will provide Linux-users worldwide with an open source VPN utility that is exceedingly simple, yet thoroughly modern and secure. Want to know more? -> https://nlnet.nl/project/wireguard-scaleup/
RT @zkat__@twitter.com
The NPM registry is going to disappear overnight one of these days and there's millions of people without an actual backup plan. https://twitter.com/mykola/status/1198719315589160960
๐ฆ๐: https://twitter.com/zkat__/status/1203945036762640385
Protocols: Duty, Despair and Decentralisation transcript
Thoroughly enjoyed reading this piece by @matdryhurst@twitter.com on possibilities for co-operatively run, decentralised music industry
https://medium.com/@matdryhurst/protocols-duty-despair-and-decentralisation-transcript-69acac62c8ea
#Briar โ Next Step of The #Crypto #Messenger Evolution | Torsten's Thoughtcrimes
https://blog.grobox.de/2016/briar-next-step-of-the-crypto-messenger-evolution/
Polish expat into UK. Information security engineer. Caver & cave rescuer (thus the bat). NHS volunteer & blood donor.