You are not logged in.

#1 2020-01-07 12:37:21

dev0x00
Member
Registered: 2019-12-21
Posts: 3

Paranoid Workstation Hardening Project

Hello everyone.

I've chosen an ambitious project for myself for these vacations: A paranoid Arch Linux workstation hardening WITH usability!

I got inspired while reading The paranoid #! Security Guide, and since it goes well with my other learning objectives, here I am.

This project is aimed for control freaks. By that I mean to control every aspect possible of my workstation at the lowest level possible. As a cybersecurity student, I think OPSEC/COMSEC is extremely important, but not always portable and usable. This whole set up will completely change the modus operandi of its user. Convenience will be sacrificed in order to achieve the maximum security possible. But one of the objectives is to make this whole set up the most usable and portable as possible. 

For its first stage, I'm writing a checklist based on some resources. I'm literally just centralizing the information of those guides into a new and "updated" one. All and any credits are for the authors of those guides.

Besides all that, I want to create something useful for the Arch Linux community with this project. So any help given here, will return for other users as well.

Some objectives of the project:

  • Create a detailed instruction guide for each element on the checklist.

  • Create a bash script that will install each element as a "selectable module", for portability’ sake.

  • Create a "master bash script" that will control and centralize the actions of all monitoring tools used on this checklist.

  • Create a Conky script that will display the information of all or the most critical information of all monitoring tools of this guide.

PS: As I've written before, this is an ambitious project. I'm not a sysadmin myself nor have I done a hardening before, so I can and I will be missing a lot of things, and that's the gap that I'm expecting the Arch community will help fulfill.
PS²: This won't be a "one time" project. I will definitely use this set up on my daily basis. Because of that, I'll try to keep the project the most updated as possible for everyone and for myself.
PS³: Since the project is on its early stages, the objectives can be modified over time.

-------------------------------------------------

Ok, now that I've introduced the project, here's what I've done so far: https://pastebin.com/raw/sTs83Mvr

I want to advance on the project in steps, so I won't be stuck in gathering all information before and then start applying it. The first step now would be the hardened installation of Arch Linux, and later I would work on the user and kernel space hardening.

What I need for this first stage from the community is some suggestions for the 1st and 2nd layers, which would be the Physical and Installation options hardening. I've tried to cover everything, but it's probably missing something.

PS⁴: I accept any constructive criticism, additional resources, tips and help. All help provided will be acknowledged on the project repository.

Thanks for reading!

Offline

#2 2020-01-07 13:55:43

WorMzy
Administrator
From: Scotland
Registered: 2010-06-16
Posts: 13,674
Website

Re: Paranoid Workstation Hardening Project

I advise that you take a look at https://wiki.archlinux.org/index.php/Security and its talk page. As you probably expect, you are not the first person to pursue hardening on Arch, and some of those who have come before you have already compiled a list of things to do (both documented on the page, and listed for future "fleshing out" on the talk page). Maybe by cross-checking these lists with the tasks listed on the #! tutorial, and the CentOS one linked on the talk page, you will come up with a pretty comprehensive list without needing any new community input. Participating on the talk page to help flesh out some of the less developed steps could help you get a better understanding of what you require from a hardened system.


Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD

Making lemonade from lemons since 2015.

Offline

#3 2020-01-07 14:10:56

dev0x00
Member
Registered: 2019-12-21
Posts: 3

Re: Paranoid Workstation Hardening Project

Thanks for the suggestion WorMzy!

The Security wiki page was the base for my checklist, but I didn't look its talk page. I'll check it out.

Offline

#4 2020-01-07 14:55:36

xerxes_
Member
Registered: 2018-04-29
Posts: 1,073

Re: Paranoid Workstation Hardening Project

If you are paranoid and don't want firmware in that system, you also shouldn't use nvidia binary drivers (or any binary drivers), and nouveau driver has too little support with new hardware. That practically excludes nvidia gpu in paranoid system.

Offline

#5 2020-01-07 15:33:18

dev0x00
Member
Registered: 2019-12-21
Posts: 3

Re: Paranoid Workstation Hardening Project

Thanks for replying xerxes_!

I'm aware of security issues regarding binary blobs and I agree with you. The comment regarding "DKMS" package was just an observation, but I think I will remove it from the checklist.

Offline

Board footer

Powered by FluxBB