On 7/18/19 3:53 PM, Chris Laprise wrote:
Description:
------------

Qubes-VM-hardening

Leverage Qubes template non-persistence to fend off malware at VM startup: Lock-down, quarantine and check contents of /rw private storage that affect the execution environment.

    * Acts at VM startup before private volume /rw mounts
    * User: Protect /home desktop & shell startup executables
    * Root: Quarantine all /rw configs & scripts, with whitelisting
    * Re-deploy custom or default files to /rw on each boot
    * SHA256 hash checking against unwanted changes
    * Provides rescue shell on error or request
    * Works with template-based AppVMs, sys-net and sys-vpn

Version 0.8.4 expands protection to the /home/user systemd directory, and now hides its vms config directory on all VM startups (not just when its enabled). Upgrading is recommended.

Github link - https://github.com/tasket/Qubes-VM-hardening


pardon my  non-sysadmin  query :


any chance of some real world  examples?  quite a few new terms  there .

so install into Debian-9

but step 2  am already lost

eg how and where amd I "activating" vm-boot-protect   in the templatevm ?

or during install there is going to appear a choice of which service to start , then when one opens a TBAVM based on the specified Deb-9 template the protection work at that point ?


Can I install it in a fresh Deb-9 , and if its breaking things, just delete the fresh Deb-9 template, or is it touching dom0 ?



I guess once installed there is no un-installing ?


--
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/33117978-ed56-0e09-53fa-76331a057623%40riseup.net.

Reply via email to