<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=4972&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Devuan/Linux security: a novella]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=4972</link>
		<description><![CDATA[The most recent posts in Devuan/Linux security: a novella.]]></description>
		<lastBuildDate>Thu, 07 Apr 2022 21:31:29 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Devuan/Linux security: a novella]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=35544#p35544</link>
			<description><![CDATA[<p>Perhaps adding a patch to the init scripts that can use hardened malloc, so that they can read a config like from /etc/default/hardened_malloc.config to use hardened malloc in a local LD_PRELOAD</p>]]></description>
			<author><![CDATA[dummy@example.com (EDX-0)]]></author>
			<pubDate>Thu, 07 Apr 2022 21:31:29 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=35544#p35544</guid>
		</item>
		<item>
			<title><![CDATA[Re: Devuan/Linux security: a novella]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=35539#p35539</link>
			<description><![CDATA[<p>^ That would apply to all system scripts but not all will work with hardened malloc so the suggestion is to only load the hardened malloc for specific init scripts.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Thu, 07 Apr 2022 10:05:04 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=35539#p35539</guid>
		</item>
		<item>
			<title><![CDATA[Re: Devuan/Linux security: a novella]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=35538#p35538</link>
			<description><![CDATA[<p>to use the hardened malloc without systemd wouldn&#039;t it suffice to add something like <span class="bbc">hardened-malloc.conf</span> to <span class="bbc">/etc/ld.so.conf.d/</span> , you know like with the other ld configs?</p>]]></description>
			<author><![CDATA[dummy@example.com (EDX-0)]]></author>
			<pubDate>Thu, 07 Apr 2022 09:39:23 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=35538#p35538</guid>
		</item>
		<item>
			<title><![CDATA[Re: Devuan/Linux security: a novella]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=35521#p35521</link>
			<description><![CDATA[<p>Devuan should be able to make use of the hardened malloc implementation provided by Whonix/Kicksecure ™:</p><p><a href="https://www.kicksecure.com/wiki/Hardened_Malloc" rel="nofollow">https://www.kicksecure.com/wiki/Hardened_Malloc</a></p><p>I&#039;ve had it working for Debian, the only caveat is that sysvinit does not support <a href="https://wiki.archlinux.org/title/systemd#Drop-in_files" rel="nofollow">drop-in configuration snippets</a> so the relevant scripts under /etc/init.d/ would have to be edited manually to add the <span class="bbc">LD_PRELOAD</span> environmental variable. The changes would probably be over-written during package upgrades, or perhaps APT will ask if the file should be kept or replaced with the new version, not sure which.</p><p>EDIT: <a href="https://www.kicksecure.com/wiki/Debian" rel="nofollow">https://www.kicksecure.com/wiki/Debian</a> ← that shows how to add the Kicksecure repositories, use with care and backup beforehand.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Wed, 06 Apr 2022 09:44:17 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=35521#p35521</guid>
		</item>
		<item>
			<title><![CDATA[Re: Devuan/Linux security: a novella]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=35518#p35518</link>
			<description><![CDATA[<p>Archlinux wiki has a great section on Linux security.</p><p><a href="https://wiki.archlinux.org/title/security" rel="nofollow">https://wiki.archlinux.org/title/security</a></p><p>Ive never (touch wood) had security issues using Linux based distros. Windows years ago i did with all sorts of viruses when i visited certain websites out of curiosity.</p>]]></description>
			<author><![CDATA[dummy@example.com (hevidevi)]]></author>
			<pubDate>Wed, 06 Apr 2022 08:09:26 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=35518#p35518</guid>
		</item>
		<item>
			<title><![CDATA[Re: Devuan/Linux security: a novella]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=35511#p35511</link>
			<description><![CDATA[<p>Sup HoaS,</p><div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><p>... <a href="https://madaidans-insecurities.github.io/" rel="nofollow">https://madaidans-insecurities.github.io/</a> ...</p></div></blockquote></div><p>madaidan has some legit insights. Whonix is an interesting distro. Used it for research awhile back.</p><p><em>Further reading: <a href="https://www.reddit.com/r/linux/comments/pwi1l9/thoughts_about_an_article_talking_about_the/" rel="nofollow">https://www.reddit.com/r/linux/comments … about_the/</a></em></p><div class="quotebox"><blockquote><div><p>The sad truth is that Windows is probably the most secure desktop operating system at the moment and Chrome is the most secure browser. Both are exceptionally poor in respect of privacy so I suppose that&#039;s the price to be paid.</p></div></blockquote></div><p>It is upsetting that businesses treat privacy as a commodity, not a right in and of itself. The early web had so much promise...</p>]]></description>
			<author><![CDATA[dummy@example.com (siva)]]></author>
			<pubDate>Mon, 04 Apr 2022 17:06:03 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=35511#p35511</guid>
		</item>
		<item>
			<title><![CDATA[Re: Devuan/Linux security: a novella]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=35509#p35509</link>
			<description><![CDATA[<p>I&#039;m no expert in such matters but I like to use this site to troll the #nonemoresecure crowd:</p><p><a href="https://madaidans-insecurities.github.io/" rel="nofollow">https://madaidans-insecurities.github.io/</a></p><p>The author is a security researcher and a Whonix developer so I think they actually know what they&#039;re talking about. Some good advice there.</p><p>The sad truth is that Windows is probably the most secure desktop operating system at the moment and Chrome is the most secure browser. Both are exceptionally poor in respect of privacy so I suppose that&#039;s the price to be paid.</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Mon, 04 Apr 2022 16:29:48 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=35509#p35509</guid>
		</item>
		<item>
			<title><![CDATA[Devuan/Linux security: a novella]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=35508#p35508</link>
			<description><![CDATA[<p>Sup everyone,</p><p>The tl;dr is that I recently eavesdropped a <em>long</em> conversation/FUD about &quot;linux is the most secure OS blah blah...&quot; Their claims were without support. It makes me cringe when people peddle misinformation about Linux-based operating systems (and when they call Linux an operating system...). </p><p>Still, it got the gears turning, and I realized, it&#039;s been a hot minute since I did anything in Linux that wasn&#039;t for professional end.</p><p>So, I wanted to open a topic for people to share facts, thoughts, or other info about Linux or Devuan security. The topic is open-ended. My interest is more to have a conversation about things we would not expect from Linux security. I know for a fact that our &quot;frequent flyers&quot; here bring a wealth of experience from a variety of backgrounds. </p><p>P.S.: It&#039;s been a minute since I posted here. I write software now and am working in the CyS field. I&#039;ll actually be working with an IoT/mobile security research team over the summer. Life is good.</p>]]></description>
			<author><![CDATA[dummy@example.com (siva)]]></author>
			<pubDate>Mon, 04 Apr 2022 16:00:34 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=35508#p35508</guid>
		</item>
	</channel>
</rss>
