It may be silly to ask[1] but is there a similar list for Mac OS X? [1] Silly because, you know, closed source
[1] Yes, pretty ironic, isn't it?
11–20 of 165 posts
It may be silly to ask[1] but is there a similar list for Mac OS X? [1] Silly because, you know, closed source
[1] Yes, pretty ironic, isn't it?
SecureBoot!? Hahahah, Linux Foundation marks this as critical? I am sorry to laugh, but thank God the LF and others fought tooth and nail for some way to have someone other than Microsoft have the key. But seriously, did anyone else laugh?
https://wiki.archlinux.org/index.php/Unified_Extensible_Firm...
It may not provide 100% security (what does?), but using this still provides much more security than just booting whatever lies on disk without any sort of verification.
So yeah. Laughing at this advice is at best uninformed.
A nice bonus-effect from using secure boot is that most UEFI implementations secure-boot faster. Why? Because when in "insecure" mode it keeps up a splash-screen saying "Booting insecure" for a few seconds before moving on.
I always install fail2ban so to prevent brute force ssh attacks from getting in. It's popular enough that's it's probably available in your distro's package repositories. http://www.fail2ban.org/
Not the soundest security advice I've read recently: > We recommend that you use the same passphrase for your root password as you use for your LUKS encryption (unless you share your laptop with other trusted people who should be able to unlock the drives, but shouldn't be able to become root). If you are the sole user of the laptop, then having your root password be different from your LUKS password has no meaningfu…
That's only going to get you the user's password, not the root password.
I always install fail2ban so to prevent brute force ssh attacks from getting in. It's popular enough that's it's probably available in your distro's package repositories. http://www.fail2ban.org/
Not the soundest security advice I've read recently: > We recommend that you use the same passphrase for your root password as you use for your LUKS encryption (unless you share your laptop with other trusted people who should be able to unlock the drives, but shouldn't be able to become root). If you are the sole user of the laptop, then having your root password be different from your LUKS password has no meaningfu…
>Trick the user into running a program that does 'alias sudo=evil-sudo' >> ~/.bashrc That's only going to get you the user's password, not the root password.
An attacker might still bring an evil-su in addition to an evil-sudo, though. And even if you're logging into that root user only in an another tty, it seems like an unnecessary risk to share the password with LUKS.
SecureBoot!? Hahahah, Linux Foundation marks this as critical? I am sorry to laugh, but thank God the LF and others fought tooth and nail for some way to have someone other than Microsoft have the key. But seriously, did anyone else laugh?
Why laugh? On proper UEFI implementations you can enroll your own keys. Arch Wiki (as usual) has an article with more details: https://wiki.archlinux.org/index.php/Unified_Extensible_Firm... It may not provide 100% security (what does?), but using this still provides much more security than just booting whatever lies on disk without any sort of verification. So yeah. Laughing at this advice is at best uninformed. A n…
You're going to have to qualify that.
Nice list, until... install a closed source product that sends backups offsite (SpiderOak). wtf?