#kicksecure

nickbeardednickbearded
2025-04-30

is secure because it's based on , but don’t expect a fortress like , or ...
It’s a Swiss knife: light, flexible, powerful.

For those who like to play hard: is included, so you can test your setup and fix what you break. Have fun! 🤪

Einstein^Diogenes@UniverseLinkazuresaipan@defcon.social
2025-04-18

#Debian splash!

Fig 1. Neofetch can’t get past hypervisor to profile hardware in #Qubes

Fig 2. But even with permission hardener and and hide hw info from security misc in #Kicksecure,
admin can still get to #baremetal

How to block self-consciousness?
There are known unknowns, the unknown unknowns,
and the not to know in order to know unknowns . . .

Tips for latest Qubes: security-misc applied to #Whonix GW and WS, firejail dvm captive portal, onionize Dom0 sources and Whonix, remove xscreensaver

Fig 3. TB thinks https is a onionsite down ; )

Einstein^Diogenes@UniverseLinkazuresaipan@defcon.social
2025-01-26

Defenses for Sensitive .state (R/W)

#Rust memory safety
doc.rust-lang.org/book/ch04-01
yewtu.be/watch?v=VFIOSWy93H0

#Kicksecure & #Whonix – compare live to SUID controls
Permission Hardener
kicksecure.com/wiki/SUID_Disab
/wiki/Security-misc#SUID_Disabler_and_Permission_Hardener
User-SysMaint-Split
kicksecure.com/wiki/Dev/user-s
github.com/adrelanos #PatrickSchleizer

Flaws in #Cloud / #Virtualization (lemmy.world/post/24009127)
Ultravisor – can’t trust hyper anymore… (24:45) “protected memory areas”
media.ccc.de/v/36c3-107-the-ch
kernel.org/doc/html/v5.9/virt/
RPC and IRQ - #IBM
forum.osdev.org/viewtopic.php?
good/bad memory
en.wikipedia.org/wiki/Page_%28

#Oracle Sovereign Cloud AI “Sentinel” – #LarryEllison tech profile and #technototalitarianism
youtube.com/watch?v=YHGztqtmlu
youtube.com/watch?v=5Hj-HtW-zR
jbs.org/audio/analysis/the-col #ElonMusk
whiterabbitneo.com/
whonix.org/wiki/KVM#Why_Use_KV?
VS. igniterefereeing.com.au/ 7GB for netinst!?

Mateusz Chrobok – #3mdeb #fightingforfreedom, State Considered Harmful, #OpenAI
3mdeb.com/why-fight-for-freedo
youtube.com/watch?v=gke8WF6_UE
blog.invisiblethings.org/paper

Einstein^Diogenes@UniverseLinkazuresaipan@defcon.social
2025-01-06

On Mobile Phone Security
kicksecure.com/wiki/Mobile_Pho
#SS7 and #baseband #vulnerabilities

What about #mobian hardening on a #MechaComet with a cellular hat? Then there's only carrier protocol weaknesses...

If ISPs use microwave relays (the hated 'air' - remember Max Headroom) and NSA access points, is domestic broadband really secure either? But the cable or fiber doesn't have 'carrier' vulns.
kicksecure.com/wiki/Router_and

#kicksecure #whonix #docs #security-misc

Einstein^Diogenes@UniverseLinkazuresaipan@defcon.social
2024-12-20

#ElSalvador #crypto #BTC #ETH #XMR
reuters.com/markets/currencies

Developing secure crypto systems
kicksecure.com/wiki/Live_Mode
#Debian #Kicksecure #Whonix #Monero
forums.kicksecure.com/t/live-k

Opt out of being robbed of sense to pay for your own oppression. No need to be complicit in the subjugation of yourself and others. Privacy and security for the people, transparency for the tyrrants! We need a confidential layer to enforce our Rights.

Encryption enforces Rights, the government violates them.

cryptopolitan.com/free-roger-v

Einstein^Diogenes@UniverseLinkazuresaipan@defcon.social
2024-12-01

Tor subtleties:
stable Entry Guards makes it harder to detect using #TAILS

...but then taking additional steps like removing oniongrater from Whonix GW or adding Vanguards usually decreases the range of function for applications but also hardens and protects guards from deanonymization.

gitlab.tails.boum.org/tails/bl

whonix.org/wiki/Tor_Entry_Guar

blog.torproject.org/improving-

whonix.org/wiki/Dev/onion-grat

#TorProject #Whonix #Kicksecure #Debian #tor

Network is reliablenetwork_is_reliable
2024-11-08

@DukeDuke I use every day. Right now I am also trying as a hardened template for QubesOS. You can run on top of QubesOS too.
You can read about the basic ideas here qubes-os.org/doc/how-to-organi.

Make sure that you use disposables whenever possible. But know limitations too. While QubesOS provides strongest isolation right now probably, the damage from compromising even one compartment can be significant sometimes (e.g., messaging apps).

xyhhx 🔻 (plz hire me)xyhhx@nso.group
2024-06-25

@SoLSec i noticed the debian hashtag in your profile - have you checked out #kicksecure tho?

kicksecure.com

xyhhx 🔻 (plz hire me)xyhhx@nso.group
2024-05-23

has anybody tried applying kicksecure's security-misc to proxmox?

github.com/Kicksecure/security

#proxmox #kicksecure #security #homelab

xyhhx 🔻 (plz hire me)xyhhx@nso.group
2024-04-30

i shouldnt have any problems setting up ivpn on a kicksecure-based qube on qubes os, right?

@ivpn

#IVPN #qubes #qubesOS #kicksecure

Einstein^Diogenes@UniverseLinkazuresaipan@defcon.social
2024-04-25

#PAM (Password Authentication Module) has a big problem, at least in Debian derived OSes. #bugbounty

Must be PAM because there is no way people can read minds and change your log10=23+ passphrases to a different one unknown to you, right? I've seen this happen multiple times now. Not easy to do.

W^X (#Kicksecure) and "stateless" computing solutions to controlling R/W are necessary unless you want to start over everytime someone wants to F a persist / LUKS remotely.

Maybe clues toward a solution here here:
blog.verbum.org/2020/08/22/imm

But I think #Spectrum is approaching a point where matter is just a matter of energy, so really, how can you control information and memory from being altered with just the right energy?

#TheIllusionOfReadOnly

xyhhx 🔻 (plz hire me)xyhhx@nso.group
2024-03-22

if i go with proxmox, i'm gonna see if i can apply #kicksecure 's hardening to it (or at least as much as possible)

if xcp-ng, i'll probably just leave it mostly as-is tho i'd like to see if i could use a more recent base distro for dom0

(RTP) Privacy & Tech Tipsrtp_tips@tube.tchncs.de
2023-06-17

Follow Along: Convert Debian To Hardened Kicksecure Linux + Whonix

tube.tchncs.de/videos/watch/4d

(RTP) Privacy & Tech Tipsrtp_tips@tube.tchncs.de
2023-06-01

Kicksecure: Install Debian To Disk Of Choice (VIDEO 1)

tube.tchncs.de/videos/watch/70

2023-06-01

Kicksecure: Install Debian To Disk Of Choice (VIDEO 1)

tilvids.com/videos/watch/5d527

📡 RightToPrivacy & Tech TipsRTP@fosstodon.org
2023-05-25

Intro: Kicksecure Hardened Debian Linux Distribution With Kernel Changes / Upgrades Over Tor & Live Boot (Run On RAM / Forget) Options

(Whonix is based on Kicksecure)

#Linux #FOSS #Kicksecure #whonix #Debian #kernel #Tor #operatingsystems #infosec #Cybersecurity #privacy

tilvids.com/w/sNvENiPH2gRW7uA4

(RTP) Privacy & Tech Tipsrtp_tips@tube.tchncs.de
2023-05-25

INTRO: Kicksecure Hardened Debian Linux Distribution (VIDEO 1)

tube.tchncs.de/videos/watch/44

2023-05-25

INTRO: Kicksecure Hardened Debian Linux Distribution (VIDEO 1)

tilvids.com/videos/watch/d90c1

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst