1 |
On Sun, 11 Dec 2011 10:18:51 +0000 |
2 |
Sven Vermeulen wrote: |
3 |
|
4 |
> Also consider hardening your system settings-wise. I would appreciate if you |
5 |
> take a look at |
6 |
> http://dev.gentoo.org/~swift/docs/previews/oval/gentoo-xccdf-guide.html. |
7 |
> With the instructions given, you can even have your system validated (as far |
8 |
> as possible) automatically. |
9 |
|
10 |
I was expecting to find here what one distro uses which is binary |
11 |
signature checking upon execution. |
12 |
|
13 |
Another thing that I try to do as a better method of TPE which is a |
14 |
breeze on OpenBSD and sometimes I find myself working against Linux |
15 |
developers¹ is to make it so that any writeable area of the filesystem |
16 |
is mounted noexec and mounts have the least priviledges required. |
17 |
|
18 |
|
19 |
¹ "https://bugs.launchpad.net/ubuntu/+source/udisks/+bug/880965" |
20 |
set as won't fix and also e.g. apt-get expecting /tmp exec. |