fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

8.7K
active users

#Kicksecure

0 posts0 participants0 posts today

#Debian splash!

Fig 1. Neofetch can’t get past hypervisor to profile hardware in #Qubes

Fig 2. But even with permission hardener and and hide hw info from security misc in #Kicksecure,
admin can still get to #baremetal

How to block self-consciousness?
There are known unknowns, the unknown unknowns,
and the not to know in order to know unknowns . . .

Tips for latest Qubes: security-misc applied to #Whonix GW and WS, firejail dvm captive portal, onionize Dom0 sources and Whonix, remove xscreensaver

Fig 3. TB thinks https is a onionsite down ; )

Defenses for Sensitive .state (R/W)

#Rust memory safety
doc.rust-lang.org/book/ch04-01
yewtu.be/watch?v=VFIOSWy93H0

#Kicksecure & #Whonix – compare live to SUID controls
Permission Hardener
kicksecure.com/wiki/SUID_Disab
/wiki/Security-misc#SUID_Disabler_and_Permission_Hardener
User-SysMaint-Split
kicksecure.com/wiki/Dev/user-s
github.com/adrelanos #PatrickSchleizer

Flaws in #Cloud / #Virtualization (lemmy.world/post/24009127)
Ultravisor – can’t trust hyper anymore… (24:45) “protected memory areas”
media.ccc.de/v/36c3-107-the-ch
kernel.org/doc/html/v5.9/virt/
RPC and IRQ - #IBM
forum.osdev.org/viewtopic.php?
good/bad memory
en.wikipedia.org/wiki/Page_%28

#Oracle Sovereign Cloud AI “Sentinel” – #LarryEllison tech profile and #technototalitarianism
youtube.com/watch?v=YHGztqtmlu
youtube.com/watch?v=5Hj-HtW-zR
jbs.org/audio/analysis/the-col #ElonMusk
whiterabbitneo.com/
whonix.org/wiki/KVM#Why_Use_KV?
VS. igniterefereeing.com.au/ 7GB for netinst!?

Mateusz Chrobok – #3mdeb #fightingforfreedom, State Considered Harmful, #OpenAI
3mdeb.com/why-fight-for-freedo
youtube.com/watch?v=gke8WF6_UE
blog.invisiblethings.org/paper

doc.rust-lang.orgWhat is Ownership? - The Rust Programming Language

On Mobile Phone Security
kicksecure.com/wiki/Mobile_Pho
#SS7 and #baseband #vulnerabilities

What about #mobian hardening on a #MechaComet with a cellular hat? Then there's only carrier protocol weaknesses...

If ISPs use microwave relays (the hated 'air' - remember Max Headroom) and NSA access points, is domestic broadband really secure either? But the cable or fiber doesn't have 'carrier' vulns.
kicksecure.com/wiki/Router_and

#kicksecure #whonix #docs #security-misc

Kicksecure · Mobile Devices Privacy and SecurityMobile devices security and data harvesting. Mobile security best practices and preventative measures against security breaches, data leaks, SIM Swapping Attacks, and more.

#ElSalvador #crypto #BTC #ETH #XMR
reuters.com/markets/currencies

Developing secure crypto systems
kicksecure.com/wiki/Live_Mode
#Debian #Kicksecure #Whonix #Monero
forums.kicksecure.com/t/live-k

Opt out of being robbed of sense to pay for your own oppression. No need to be complicit in the subjugation of yourself and others. Privacy and security for the people, transparency for the tyrrants! We need a confidential layer to enforce our Rights.

Encryption enforces Rights, the government violates them.

cryptopolitan.com/free-roger-v

@DukeDuke I use #QubesOS every day. Right now I am also trying #Kicksecure as a hardened template for QubesOS. You can run #whonix on top of QubesOS too.
You can read about the basic ideas here qubes-os.org/doc/how-to-organi.

Make sure that you use disposables whenever possible. But know limitations too. While QubesOS provides strongest isolation right now probably, the damage from compromising even one compartment can be significant sometimes (e.g., messaging apps).

Qubes OS · How to organize your qubesWhen people first learn about Qubes OS, their initial reaction is often, “Wow, this looks really cool! But… what can I actually do with it?” It’s not always obvious which qubes you should create, what you should do in each one, and whether your organizational ideas makes sense from a se...
Continued thread

if i go with proxmox, i'm gonna see if i can apply #kicksecure 's hardening to it (or at least as much as possible)

if xcp-ng, i'll probably just leave it mostly as-is tho i'd like to see if i could use a more recent base distro for dom0

does anyone here have any experience with the #rockpro64? im planning on building a small home NAS, with #jellyfin for streaming.

the setup would be:
3x1tb drives in raid5
a rockpro64 with an IOcrest 4 port sata card
running #debian :debian: minimal install, with #kicksecure
all placed inside a pelican case (or any case like that)

would love you guys' input or any tips/advice:)