This project offers a production-grade security baseline and hardening guide for Ubuntu 24.04/26.04 LTS. It covers kernel isolation, custom AppArmor/Firejail configurations, Rootless Docker setups, and integrity checks via AIDE. Designed for diverse users, it supports 17 languages, ensuring accessibility for journalists, human rights defenders, and infosec professionals.
The security-baseline-ubuntu project serves as a comprehensive, production-grade security baseline and hardening guide tailored for Ubuntu versions 24.04 and 26.04 LTS. This initiative focuses on transforming a standard Linux distribution into a highly secure workstation capable of addressing advanced physical, supply-chain, and network-level threats. It integrates an array of open-source solutions and emphasizes security measures such as kernel isolation, custom AppArmor configurations, Firejail setup, Rootless Docker deployment, integrity checks using AIDE, and audits via Lynis.
Key Features
This meticulously crafted guide provides detailed instructions on critical security vectors, including:
- Hardware & Boot Hardening: Techniques to secure the boot process against threats like Evil Maid attacks through stringent bootloader password policies and secure configuration setups.
- DMA & Memory Protection: Kernel-level programming to mitigate risks associated with Direct Memory Access and enhance data retention practices.
- Telemetry & Component Purging: Automated scripts for comprehensive sanitation of system telemetry data, enhancing privacy by disabling unwanted services.
- System Integrity & Security Auditing: Advanced strategies employing File Integrity Monitoring via AIDE, rootkit detection with Rkhunter, and compliance verification through Lynis audits.
- Sandboxing & Mandatory Access Control (MAC): Implementation of detailed AppArmor policies and Firejail frameworks for application containment and secure interactions with development tools.
- Network Perimeter Isolation: Establishment of robust MAC address spoofing, firewall configurations with strict access controls, and VPN integration to prevent data leaks.
- Browser Hardening: Modifications to browser settings that mitigate various privacy risks, ensuring a safer browsing experience.
- Hardware Token Integration: Enhanced physical access security through the use of cryptographic hardware tokens like YubiKey, fortifying system access controls.
- Secure Virtualization & Crypto-Asset Protection: Best practices for managing isolated guest operating systems and securing cryptocurrency workflows.
- Data Sanitization & Anti-Forensics: Advanced methods for ensuring data destruction and maintaining operational security through expert handling of metadata.
- Censorship Circumvention: Solutions designed to bypass restrictive internet environments for unhindered access to essential updates and information.
This project is accessible in 17 languages, catering to a diverse range of users including journalists, human rights advocates, and infosec professionals who require enhanced operational security and digital self-defense methodologies.
Contributions to improve the guide's content, translations, and technical accuracy are highly encouraged to foster a collaborative approach to bolstering security practices.
Comments
0Start the conversation
Share the first comment.