Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Blacklist more modules (based on OpenSCAP for RHEL 8) #75

Merged
merged 1 commit into from Sep 28, 2020
Merged

Blacklist more modules (based on OpenSCAP for RHEL 8) #75

merged 1 commit into from Sep 28, 2020

Conversation

flawedworld
Copy link
Contributor

The modules blacklisted may be debatable, but they aren't very commonly used so I think this shouldn't impact the average user. Open to feedback.

Sourced from: https://static.open-scap.org/ssg-guides/ssg-rhel8-guide-index.html

@adrelanos
Copy link
Member

@madaidan
Copy link
Contributor

There was discussion on blacklisting filesystem modules before https://forums.whonix.org/t/blacklist-more-kernel-modules-to-reduce-attack-surface/7989

Isn't vfat quite common?

@flawedworld
Copy link
Contributor Author

vfat is used for FAT12, FAT16 and FAT32. I would say that it's mostly an issue on a UEFI system, as it has to be used for the EFI partition. For that reason it would probably be best to omit it on second thoughts.

@adrelanos adrelanos merged commit 3684ab5 into Kicksecure:master Sep 28, 2020
adrelanos pushed a commit that referenced this pull request Sep 28, 2020
@adrelanos
Copy link
Member

Merged and unblacklisted vfat. Will also remove squashfsas this would likely break Whonix-Host ISO.

adrelanos pushed a commit to adrelanos/security-misc that referenced this pull request Sep 28, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants